Security

Vulnerability disclosure

MedPhoto is a HIPAA-, LGPD-, and GDPR-compliant platform for storing patient medical photos. We take security reports seriously and work with researchers in good faith to investigate, fix, and disclose vulnerabilities responsibly.

How to report

Send vulnerability reports by email. Please do not file public GitHub issues, post on social media, or share details in support chat before we have had a chance to investigate.

PGP encryption is available on request. Email us and we will reply with a public key.

What to include

  • A clear description of the issue and its impact.
  • Steps to reproduce, with any required payloads or sample inputs.
  • The affected surface (API, web app, or mobile client) and version if known.
  • Your name or handle if you want credit in the advisory, or a note that you prefer to remain anonymous.

Our commitments

  • We will acknowledge your report within 3 business days.
  • We will complete an initial triage within 10 business days.
  • We will keep you updated on status throughout the investigation.
  • If you want credit, we will name you in the advisory once the fix ships.
  • We do not currently run a paid bug bounty program. Reports are handled on a good-faith basis only.

Disclosure & advisories

Confirmed vulnerabilities are published as advisories at /security/advisories once the fix has shipped and affected users have had a reasonable window to update. Reporters who want credit are named in the advisory.

Safe harbor

If you act in good faith and follow this policy, MedPhoto will not pursue legal action against you for your research, and we will work with you on coordinated disclosure. To stay within safe harbor:

  • Do not access, modify, or download patient data that is not yours. Use a test account you control.
  • Do not degrade service for other users. No denial-of-service, no high-volume scanning, no resource exhaustion.
  • Give us a 90-day disclosure window from the date of your initial report before going public. We will work with you in good faith to fix issues well within that window.
  • Stop testing and contact us immediately if you encounter patient data, credentials, or any other sensitive information.

In scope

The following MedPhoto-operated surfaces and features are in scope:

  • API: api.medphoto.com.br
  • Web app: app.medphoto.com.br
  • Marketing website: medphoto.com.br. Only vulnerabilities with demonstrable impact (e.g. stored or reflected XSS, open redirect, subdomain takeover). The out-of-scope exclusions below still apply.
  • Official iOS and Android mobile clients.
  • Authentication, including Better Auth, 2FA, and Apple / Google Sign-In.
  • Patient data handling, PII encryption at rest, and audit logging.
  • Shared link generation, presigned S3 URLs, and public sharing routes.
  • Webhook handlers (Stripe, RevenueCat).

Out of scope

  • Third-party infrastructure we do not control, including AWS, Stripe, RevenueCat, Resend, Firebase, Apple, and Google.
  • Social engineering of MedPhoto staff, customers, or vendors.
  • Physical attacks against MedPhoto offices, staff, or hardware.
  • Denial-of-service and volumetric attacks.
  • Findings on staging or local development environments that are not exposed to the public internet.
  • Self-XSS, missing security headers on unauthenticated marketing pages, clickjacking without demonstrable impact, and theoretical TLS misconfigurations.
  • Automated scanner output without a validated proof of concept.
  • Library version reports without a working proof of concept against MedPhoto.

Compliance note

MedPhoto handles protected health information under HIPAA, dados pessoais sensíveis under LGPD, and personal data under GDPR. Reports involving patient data exposure, audit log tampering, encryption-at-rest bypass, presigned URL leakage, or any authentication or authorization bypass are treated as critical and prioritized accordingly.

Last updated: 2026-06-05 · Policy expires: 2027-06-05