![A stone watchtower with a lantern glowing over a walled garden](https://viacara.com/img/content/security-feature-light.webp)

# Security and vulnerability disclosure

How to report a security vulnerability in ViaCara, what is in scope, what we ask of researchers and what you can expect from us.

## Our commitment

The people who use ViaCara trust us with information about their mental health and wellbeing. We take that seriously. If you believe you have found a security vulnerability in our service, we want to hear from you and we will work with you in good faith.

This page explains how to report a vulnerability, what is in scope and what you can expect from us. We do not operate a bug bounty programme and we do not offer financial rewards for reports.

## How to report

Email [security@viacara.com](mailto:security@viacara.com) with as much of the following as you can:

- What you found and where you found it
- Steps to reproduce the issue
- What an attacker could do with it
- Any relevant evidence such as request and response details or screenshots

Please send your report as soon as possible after finding the issue and do not share it publicly before we have had a reasonable opportunity to fix it. A machine-readable summary of this policy is published at [/.well-known/security.txt](https://viacara.com/.well-known/security.txt).

If your report contains sensitive detail, you can encrypt it with our [OpenPGP key](https://viacara.com/.well-known/pgp-key.txt) (fingerprint `36D3 4A42 0F0D 88C3 363A 14FD 10AD B6FD D292 FE56`).

## What we ask of you

Because our service handles sensitive personal data, these rules protect the people who use it:

- **Never access, modify or store real user data.** If you encounter someone else's data, stop immediately, do not save or share it and tell us in your report.
- **Test only with accounts you created yourself.**
- **No automated scanning** of our production service.
- **No denial of service testing** or anything that degrades the service for others.
- **No social engineering** of our team or the professionals on our platform, and no physical attacks.

## What you can expect from us

- We will acknowledge your report within 5 working days.
- We will keep you informed as we investigate and fix the issue.
- We will not pursue legal action against research carried out in good faith within the rules on this page.
- With your permission, we are happy to credit you once the issue is resolved.

## Scope

In scope: `viacara.com` and the subdomains we operate.

Out of scope:

- Services run by our third-party infrastructure providers and sub-processors. Report issues in those services to the provider directly.
- Findings from automated tools without a demonstrated security impact.
- Reports about email configuration records, missing security headers or software version disclosure without a working exploit.
- Denial of service, social engineering and physical attacks, which this policy does not authorise.

## How we look after the service

Security checks run on every change we ship, our dependencies are monitored for known vulnerabilities and our infrastructure is hosted in the EU. Details of how we handle personal data, including your rights and how to exercise them, are in our [privacy policy](https://viacara.com/privacy/).

**Last updated: June 2026**

**This policy is written in plain language and is periodically reviewed for accuracy.**
