Vulnerability Disclosure Policy
1. Our commitment
Careberry is a care management platform used by home care agencies and care homes in the UK. The information in our platform includes health and care records of the people our customers support. Keeping that information safe is part of keeping people safe.
We welcome reports from anyone who believes they have found a security weakness in Careberry. We will treat every report seriously, respond within the timescales below, and work with you to fix confirmed problems before they are made public.
2. How to report
Email security@careberry.com.
Please include, as far as you can:
- what is affected (web address, app name and version, or feature);
- what the weakness is and what an attacker could do with it;
- the steps to reproduce it, using a harmless proof of concept;
- the date and time you found it, and any IP addresses you tested from;
- how you would like to be named if we thank you publicly, or that you prefer not to be named.
Please do not include any personal data about service users, staff or customers in your report. If your finding involves personal data, describe it (for example "the response contains another care provider's client names") rather than copying it.
If you believe a weakness is being actively exploited right now, put URGENT at the start of the email subject line.
3. What is in scope
This policy covers every part of:
- the Careberry web portal, including the APIs it uses;
- the Careberry Family App;
- the Careberry Admin App;
- the careberry.com website.
If you are not sure whether something is covered, email us before testing.
4. What is out of scope
- Systems run by our customers (care providers) themselves, including their own devices, email and networks.
- Services run by our suppliers, such as Microsoft Azure and Microsoft Entra. Please report those to the supplier directly, for example through the Microsoft Security Response Center.
- Denial of service, load testing or anything that degrades the service.
- Social engineering, phishing or physical attempts against Careberry staff, customers or offices.
- Reports from automated scanners without a demonstrated, realistic impact.
- Findings with no realistic security impact, for example missing security headers on pages with no sensitive content, version banners, or TLS configuration preferences.
5. Rules for testing
Our platform supports the delivery of care. A careless test could stop a carer seeing a medication instruction. Please follow these rules:
- Only use accounts and credentials that belong to you. We do not provide test accounts through this policy. If you need one, ask us first at security@careberry.com.
- Do not access, change, delete or download data that is not yours. If you reach anyone else's data, stop immediately, do not keep a copy, and tell us straight away.
- Do not use a weakness further than needed to show it exists. One record is enough to prove access; do not collect more.
- Do not disrupt the service, use destructive tools, or run high-volume automated scans.
- Do not install anything on our systems or leave anything behind (such as a backdoor or web shell).
- Do not share details of the weakness with anyone else until we have fixed it and agreed a disclosure date with you (see section 7).
- Do not ask for payment as a condition of telling us about a weakness.
6. What you can expect from us
| Step | Our target |
|---|---|
| Acknowledge your report | Within 3 working days |
| Tell you whether we have confirmed the weakness and how serious we think it is | Within 10 working days |
| Progress updates while we fix it | At least every 14 days |
| Tell you when it is fixed, and invite you to check the fix | When the fix is released |
Working days are Monday to Friday, excluding bank holidays in England. We will handle your report in confidence and will not share your personal details outside Careberry without your permission, unless the law requires it.
7. Public disclosure
We ask that you give us reasonable time to fix a confirmed weakness before you publish anything about it. Our aim is to agree a disclosure date with you, normally within 90 days of your report. If a fix will take longer, we will explain why. We will not publish details that would put care providers or the people they support at risk.
8. Legal position
If you act in good faith and follow this policy, Careberry will not take legal action against you, and will not ask the police to do so, in relation to your research. For the purposes of the Computer Misuse Act 1990, Careberry Software Ltd authorises testing of its own systems that stays within the scope in section 3 and the rules in section 5.
Please understand the limits of this. Careberry can only give permission for systems it owns. We cannot give permission on behalf of our customers or suppliers, and we cannot give immunity from the law or bind anyone else, including the police or the Information Commissioner. If a third party takes action against you and you have followed this policy, we will make it known that you acted in line with it.
9. Recognition
Careberry does not run a paid bug bounty. With your permission, we are happy to thank you by name on our website once the issue is fixed.
10. Changes to this policy
We review this policy at least once a year. The current version is always the one published at https://www.careberry.com/security/vulnerability-disclosure.