Vulnerability Disclosure Policy

Careberry Software LtdVersion 1.0Last updated 27 September 2026

1. Our commitment

Careberry is a care management platform used by home care agencies and care homes in the UK. The information in our platform includes health and care records of the people our customers support. Keeping that information safe is part of keeping people safe.

We welcome reports from anyone who believes they have found a security weakness in Careberry. We will treat every report seriously, respond within the timescales below, and work with you to fix confirmed problems before they are made public.

2. How to report

Email security@careberry.com.

Please include, as far as you can:

  • what is affected (web address, app name and version, or feature);
  • what the weakness is and what an attacker could do with it;
  • the steps to reproduce it, using a harmless proof of concept;
  • the date and time you found it, and any IP addresses you tested from;
  • how you would like to be named if we thank you publicly, or that you prefer not to be named.

Please do not include any personal data about service users, staff or customers in your report. If your finding involves personal data, describe it (for example "the response contains another care provider's client names") rather than copying it.

If you believe a weakness is being actively exploited right now, put URGENT at the start of the email subject line.

3. What is in scope

This policy covers every part of:

  • the Careberry web portal, including the APIs it uses;
  • the Careberry Family App;
  • the Careberry Admin App;
  • the careberry.com website.

If you are not sure whether something is covered, email us before testing.

4. What is out of scope

  • Systems run by our customers (care providers) themselves, including their own devices, email and networks.
  • Services run by our suppliers, such as Microsoft Azure and Microsoft Entra. Please report those to the supplier directly, for example through the Microsoft Security Response Center.
  • Denial of service, load testing or anything that degrades the service.
  • Social engineering, phishing or physical attempts against Careberry staff, customers or offices.
  • Reports from automated scanners without a demonstrated, realistic impact.
  • Findings with no realistic security impact, for example missing security headers on pages with no sensitive content, version banners, or TLS configuration preferences.

5. Rules for testing

Our platform supports the delivery of care. A careless test could stop a carer seeing a medication instruction. Please follow these rules:

  • Only use accounts and credentials that belong to you. We do not provide test accounts through this policy. If you need one, ask us first at security@careberry.com.
  • Do not access, change, delete or download data that is not yours. If you reach anyone else's data, stop immediately, do not keep a copy, and tell us straight away.
  • Do not use a weakness further than needed to show it exists. One record is enough to prove access; do not collect more.
  • Do not disrupt the service, use destructive tools, or run high-volume automated scans.
  • Do not install anything on our systems or leave anything behind (such as a backdoor or web shell).
  • Do not share details of the weakness with anyone else until we have fixed it and agreed a disclosure date with you (see section 7).
  • Do not ask for payment as a condition of telling us about a weakness.

6. What you can expect from us

StepOur target
Acknowledge your reportWithin 3 working days
Tell you whether we have confirmed the weakness and how serious we think it isWithin 10 working days
Progress updates while we fix itAt least every 14 days
Tell you when it is fixed, and invite you to check the fixWhen the fix is released

Working days are Monday to Friday, excluding bank holidays in England. We will handle your report in confidence and will not share your personal details outside Careberry without your permission, unless the law requires it.

7. Public disclosure

We ask that you give us reasonable time to fix a confirmed weakness before you publish anything about it. Our aim is to agree a disclosure date with you, normally within 90 days of your report. If a fix will take longer, we will explain why. We will not publish details that would put care providers or the people they support at risk.

9. Recognition

Careberry does not run a paid bug bounty. With your permission, we are happy to thank you by name on our website once the issue is fixed.

10. Changes to this policy

We review this policy at least once a year. The current version is always the one published at https://www.careberry.com/security/vulnerability-disclosure.