Skip to content
Security · Disclosure policy

How to report a vulnerability.

We rely on independent researchers to help us keep healthcare professional and facility data safe. This policy explains what we ask of you, and what we commit to in return.

Where to send reports

Email security@btlocum.com with:

  • A clear description of the issue and impact
  • Steps to reproduce (cURL or HTTP request preferred)
  • The endpoint, page URL, or system component affected
  • Your name and how you would like to be credited (or "anonymous")

PGP key available at /security/pgp.asc for sensitive submissions.

What we commit to

  • Acknowledgement within 24 hours. A person responds, not an autoresponder.
  • Triage within 5 business days. We confirm whether we can reproduce, classify severity, and tell you our remediation plan.
  • No legal action against researchers acting in good faith under this policy. We will not contact your employer, file complaints, or pursue criminal proceedings.
  • Credit on our security thanks page once the fix ships, unless you ask otherwise.
  • Coordinated disclosure. We work with you on a public disclosure timeline, typically 90 days from confirmed receipt.

What we ask of you

  • Do not access, modify, or delete data belonging to other users. Use test accounts only.
  • Do not exfiltrate, store, or share user data discovered through your research.
  • Do not run automated scans against production at high rates without notifying us first.
  • Do not perform denial-of-service attacks or social engineering.
  • Wait until we have shipped a fix before publicly disclosing.

Scope

In scope:

  • app.locumplatform.com
  • api.locumplatform.com
  • locumplatform.com (marketing site)
  • Locum mobile apps (iOS, Android) — when launched

Out of scope:

  • Third-party services (PayFast, our hosting provider, SendGrid) — please report directly to them
  • Findings dependent on outdated browser versions or missing security headers without demonstrated impact
  • Self-XSS, clickjacking on pages without authenticated state changes
  • Social engineering of staff or users

Rewards

We do not yet run a paid bug bounty. Researchers receive public credit (with consent) and our enthusiastic thanks. We plan to launch a formal bounty programme in Q4 2026; sign up at security@btlocum.com to be notified.