Skip to content

Legal

Responsible Disclosure

If you have found a security issue on this site, we want to hear about it, and we will not take legal action against you for telling us in good faith.

Reporting a vulnerability

Email the address at the bottom of this page with “Security” in the subject line. Please include enough detail for us to reproduce the issue: the URL or endpoint, the steps you took, and what you observed.

We will acknowledge your report within five business days, keep you updated as we investigate, and tell you when it is resolved. We are a small practice, not a security team, so please be patient with our timelines, but we will not ignore you.

What is in scope

The wildlyprimal.com domain, its subdomains, and the API endpoints under /api.

What is out of scope

These are either not ours to fix or not things we consider vulnerabilities:

  • Findings from automated scanners without a demonstrated, exploitable impact
  • Missing security headers with no accompanying exploit
  • Reports about the absence of rate limiting on the contact form, which we already know about and document
  • Social engineering of our practitioners, our email provider or our hosting provider
  • Physical attacks, or anything targeting our staff rather than our systems
  • Denial-of-service or volumetric testing of any kind
  • Vulnerabilities in third-party services we use, which should be reported to those services directly
  • Issues requiring a rooted or jailbroken device, or a browser that is no longer supported

What we ask of you

While you are testing, please:

  • Stay within the scope above
  • Do not access, modify or delete data that is not yours; if you can reach someone else’s data, stop and tell us rather than confirming how much you can reach
  • Do not degrade the service for others; no denial-of-service or load testing
  • Do not use social engineering, phishing or physical intrusion
  • Give us a reasonable opportunity to fix the issue before disclosing it publicly
  • Do not extort us: a report conditioned on payment is not a disclosure

Safe harbor

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will not pursue or support any legal action against you in relation to your research, and we will consider your activity authorized under the Computer Fraud and Abuse Act and equivalent state law.

If a third party brings legal action against you for research you conducted in accordance with this policy, we will make it known that your actions were authorized.

This safe harbor reaches as far as our own authority reaches. It cannot bind our hosting provider, our email provider, or anyone else, so please stay inside our scope.

Rewards

We do not run a paid bug bounty. We are a two-practitioner health practice and we would rather be straightforward about that than imply a reward that is not coming.

What we will do is fix the issue, credit you by name if you would like to be credited, and thank you sincerely.

Contact

Security reports go to the address below. A machine-readable version of this policy is published at /.well-known/security.txt.

Wildly Primal

Jacksonville Beach, Florida

wildlyprimal@gmail.com

This page is provided for transparency about how we operate. It is not legal advice, and it does not create rights or obligations beyond those the law already gives you.