Trust Home / Contact
Contact & Responsible Disclosure
How to reach our security team and how to report vulnerabilities responsibly.
Support
For general product questions, account help, and customer support, contact our team:
Security contact
For security questions, compliance evidence requests, and urgent security issues, contact:
PGP key available on request. Response SLA: 1 business day for non-critical, 4 hours for critical vulnerabilities.
General security
security@cerniahealth.comPrivacy / GDPR
privacy@cerniahealth.comLegal / BAA
legal@cerniahealth.comResponsible disclosure policy
We welcome security researchers who discover vulnerabilities in Cernia FHIR. We ask that you follow this responsible disclosure policy to protect our customers and give us time to remediate.
What we ask of you
- —Report the vulnerability to security@cerniahealth.com before publishing.
- —Provide enough detail for us to reproduce and verify the issue.
- —Do not access, modify, or exfiltrate customer data.
- —Do not perform automated scanning without prior written permission.
- —Give us a reasonable time to remediate before public disclosure (90 days).
What we commit to you
- —Acknowledge your report within 1 business day.
- —Provide a triage assessment within 5 business days.
- —Keep you informed of remediation progress.
- —Credit you in our security acknowledgements (if desired).
- —Not pursue legal action against researchers who follow this policy.
Out of scope
- —Denial of service attacks.
- —Physical security attacks on our infrastructure.
- —Social engineering of Cernia employees.
- —Issues in third-party services we do not control.
- —Vulnerabilities requiring unlikely user interaction (clickjacking on non-sensitive pages).