Vulnerability Disclosure Policy

    Last Updated: May 9, 2025

    Report a Vulnerability

    If you believe you've found a security vulnerability in our services, please report it to us immediately:

    For security reasons, please encrypt sensitive vulnerability details using our PGP key.

    Our Commitment

    At Elderwise, we take security seriously. We value the contributions of security researchers who help us maintain high security standards. We are committed to:

    • Acknowledging receipt of vulnerability reports
    • Working with security researchers to understand and validate reported issues
    • Addressing confirmed vulnerabilities in a timely manner
    • Recognizing the contributions of security researchers when appropriate

    Scope

    This policy applies to all Elderwise-owned web applications, APIs, and infrastructure. This includes:

    • *.elderwise.ai domains
    • Elderwise web applications
    • Elderwise APIs
    • Elderwise mobile applications
    • Elderwise IoT devices and gateways

    Security Testing Authorization

    If you plan to conduct security research on our systems, please contact us first at security-research@elderwise.ai to request explicit authorization before beginning any testing.

    Testing without prior authorization may violate our terms of service and applicable laws.

    Guidelines

    When reporting vulnerabilities, please:

    • Provide detailed information about the vulnerability
    • Include steps to reproduce the issue
    • Respect the privacy of our users and do not access, modify, or delete user data
    • Do not disrupt our services or degrade the quality of our services
    • Do not disclose the vulnerability publicly until we have had a reasonable time to address it

    Process

    Response Timeline

    We will acknowledge receipt of vulnerability reports within 48 hours and strive to provide regular updates about our progress in addressing confirmed vulnerabilities.

    Resolution

    The time needed to resolve a vulnerability will vary depending on its severity and complexity. We're committed to resolving critical issues as quickly as possible.

    Responsible Disclosure

    We request that you:

    • Make every effort to avoid privacy violations, degradation of user experience, and disruption to our services
    • Only interact with your own accounts or test accounts for security testing purposes
    • Do not modify or access data that does not belong to you

    Recognition

    We believe in recognizing the valuable contribution that security researchers make in helping us maintain the security of our systems. Unless you request otherwise, we will acknowledge your contribution in our security acknowledgments once the vulnerability has been addressed.

    Security Hall of Fame

    We maintain a security researcher hall of fame to publicly recognize those who have helped improve our security posture through responsible disclosure.

    View our Security Hall of Fame

    Legal Protection

    We will not pursue legal action against security researchers who report vulnerabilities in accordance with this policy, provided they act in good faith and in accordance with this policy.

    For questions about this policy, please contact legal@elderwise.ai.

    This policy is aligned with industry best practices and standards for responsible vulnerability disclosure.