Trust center
Legal
Responsible disclosure
Effective: 2026-05-30
Security research helps keep our customers safe. We welcome good-faith reports of vulnerabilities and will not pursue legal action against researchers who follow this policy.
Scope
weconsultrx.com— marketing surfaceapp.weconsultrx.com— authenticated applicationstatus.weconsultrx.com— status portal
Out of scope
- Vulnerabilities in third-party SaaS we use (report to the vendor).
- Reports based on automated scanner output without reproduction steps.
- Spam, denial-of-service, social engineering of staff.
- Physical attacks against staff facilities.
- Best-practice notices without exploitability (e.g. missing security headers on static assets that contain no sensitive data).
Safe harbor
If you make a good-faith effort to comply with this policy, we will:
- Consider your research authorized.
- Not pursue or support any legal action related to it.
- Work with you to understand and resolve the issue quickly.
Rules of engagement
- Test only against accounts you own or have explicit permission to test.
- Do not access, modify, or exfiltrate data belonging to others.
- Do not perform attacks that degrade availability (rate-limit testing OK at low volume).
- Do not publish vulnerabilities prior to coordinated disclosure.
How to report
Email [email protected]. Include:
- A description of the vulnerability and its impact.
- Step-by-step reproduction.
- Affected URL(s).
- Your name / handle (optional, for credit).
We acknowledge within two business days and aim to remediate critical issues within 30 days.
Recognition
With your permission we will publicly credit you in our security acknowledgments page once the issue is resolved.
security.txt
Machine-readable contact: /.well-known/security.txt.