Trust
Vulnerability disclosure
We welcome reports from security researchers about any Vytivo product, including PracticeHQ and Vytivo Connect.
How to report
Email security@vytivo.com with the affected product, steps to reproduce, and the impact you observed. Encrypted reports are welcome; ask for our PGP key in your first message. We acknowledge every report within 3 business days.
What we ask
- Do not access, modify, or retain data that is not your own. Stop and report as soon as you can demonstrate an issue.
- Do not degrade the service. No denial-of-service, spam, or social engineering of staff or customers.
- Give us reasonable time to remediate before disclosing publicly.
What we commit to
- Safe harbor for good-faith research that follows this policy. We will not pursue legal action.
- Remediation targets: critical within 7 days, high within 14 days, medium within 30 days.
- A status update when the issue is fixed, and credit if you would like it.
We do not run a paid bug bounty at this time.