Security

Report a vulnerability

Last updated 27 August 2026

TimeGrid processes protected health information on behalf of home-care agencies. If you have found a security flaw, we want to hear about it privately so we can fix it before anyone is harmed.

How to reach us

Email security@gomydev.com.

Please do not open a public issue, post, or social-media thread about a suspected vulnerability before we have had a chance to fix it. Public disclosure ahead of a fix puts patient data at risk.

What to include

A description of the issue, the affected URL, endpoint, or screen, the steps to reproduce it, and the impact you believe it has.

Do not include real patient data in your report. Redact it, or use synthetic values. If demonstrating the issue seems to require real records, describe what you were able to reach rather than sending it to us.

What happens next

Safe harbor

We will not pursue legal action for good-faith security research that:

If you are unsure whether something crosses a line, ask us first at security@gomydev.com.

Out of scope

Reports from automated scanners with no demonstrated impact, missing best-practice headers with no exploit path, and issues that require an already-compromised device or account are generally not treated as vulnerabilities. Tell us anyway if you believe there is a real path to harm.

Not a bug bounty

We do not currently operate a paid bounty programme. We are grateful for reports regardless, and we will respond to every one.

Privacy and legal contacts

This page is for security vulnerabilities only. For privacy requests, data access, or deletion, see our Privacy Policy. For how we handle PHI as a Business Associate, see the BAA.

Machine-readable version: /.well-known/security.txt