Symposed

Security and Vulnerability Reporting

Last updated 6 July 2026

1. Reporting a security concern

If you believe you have found a security vulnerability affecting Symposed, report it privately via our contact form. Please include the affected URL or feature, a clear description, steps to reproduce where safe, and the potential impact.

If the issue involves exposed personal information, account compromise or a patient-data disclosure, make that clear in the subject line so we can triage the incident appropriately.

2. Rules for security research

This policy does not provide blanket legal authorisation to test Symposed. You must not:

  • access, download, alter or disclose another user's data beyond the minimum accidental exposure necessary to identify and report a vulnerability;

  • use social engineering, phishing, credential stuffing or stolen credentials;

  • deploy malware, carry out denial-of-service testing or materially degrade the Service;

  • perform destructive testing against production data;

  • exfiltrate message content, contact information or research-related information;

  • demand payment or threaten public disclosure as a condition of reporting; or

  • publicly disclose an unresolved vulnerability before we have had a reasonable opportunity to investigate and mitigate it.

If you encounter user data accidentally, stop, do not retain or share it, tell us what was accessed and follow our instructions for secure deletion where lawful.

3. Our response

We will triage genuine reports and may contact you for further information. We do not currently promise a bug bounty or payment. We may recognise good-faith reporters at our discretion where appropriate. We may refer malicious activity to relevant providers or authorities.

4. Account-security reports

If you are a user and believe your account has been compromised, contact our contact form and use any password-reset or account-security tools available in the Service. Do not send your password to Symposed.