Nerida Health Take Part

Report a security vulnerability

Coordinated disclosure policy · Last updated 10 August 2026

If you have found a weakness in something we run, send it to us. We acknowledge reports within 2 business days and keep you informed through closure.

How to report

Email [email protected]. Tell us what you found, where, and how to reproduce it. If you would like to encrypt your report, say so and we will arrange it.

This address is published in machine-readable form at /.well-known/security.txt, following RFC 9116.

What we promise

  • We acknowledge your report within 2 business days.
  • We give you an assessment within 10 business days: whether we can reproduce it, how serious we judge it, and what we intend to do.
  • We keep you informed until it is closed, and we tell you when the fix ships.
  • We will credit you publicly if you want that, and stay quiet about you if you do not.
  • We will not pursue or support legal action against anyone who reports in good faith under this policy, and we will not ask your employer to.

What is in scope

  • neridahealth.com and its subdomains, which today serve this website only.
  • Our public code, brand assets and email configuration.

When the Nerida Health platform has public addresses, this page will name them. No real patient data is on the platform until clinical, legal and security review is complete.

What we ask of you

  • Give us a reasonable chance to fix the problem before you tell anyone else. We suggest 90 days, and we will usually be much faster.
  • Do not access, change or keep data that is not yours. If you come across personal data, stop, and tell us in your report.
  • Do not degrade the service for anyone else: no denial-of-service testing, no automated scanning heavy enough to disrupt, no social engineering of our people or suppliers, and no physical attempts.
  • Stay within the scope above.

What reporters receive

We do not run a paid bug bounty. The response times, updates and credit choices above apply to every good-faith report. If a bounty is added later, this page will say so.

Not a security problem?

General questions, service issues and complaints go to [email protected], or see the complaints page.