Report a vulnerability
TimeGrid processes protected health information on behalf of home-care agencies. If you have found a security flaw, we want to hear about it privately so we can fix it before anyone is harmed.
How to reach us
Email security@gomydev.com.
Please do not open a public issue, post, or social-media thread about a suspected vulnerability before we have had a chance to fix it. Public disclosure ahead of a fix puts patient data at risk.
What to include
A description of the issue, the affected URL, endpoint, or screen, the steps to reproduce it, and the impact you believe it has.
Do not include real patient data in your report. Redact it, or use synthetic values. If demonstrating the issue seems to require real records, describe what you were able to reach rather than sending it to us.
What happens next
- Acknowledgement within 2 business days. A human will confirm we have your report.
- Serious issues are worked immediately. Anything that exposes patient data, bypasses authentication, or lets one agency reach another agency's records is treated as critical, with a fix or mitigation targeted within 7 days.
- Lower-severity issues are scheduled on a risk-ranked basis, and we will tell you where yours landed.
- Credit where you want it. Tell us how you would like to be named, or if you would rather stay anonymous.
Safe harbor
We will not pursue legal action for good-faith security research that:
- stays within your own tenant or test data;
- does not access, modify, or take other agencies' data;
- does not degrade the service (no denial-of-service, no bulk automated scanning of production);
- and gives us a reasonable chance to remediate before you disclose publicly.
If you are unsure whether something crosses a line, ask us first at security@gomydev.com.
Out of scope
Reports from automated scanners with no demonstrated impact, missing best-practice headers with no exploit path, and issues that require an already-compromised device or account are generally not treated as vulnerabilities. Tell us anyway if you believe there is a real path to harm.
Not a bug bounty
We do not currently operate a paid bounty programme. We are grateful for reports regardless, and we will respond to every one.
Privacy and legal contacts
This page is for security vulnerabilities only. For privacy requests, data access, or deletion, see our Privacy Policy. For how we handle PHI as a Business Associate, see the BAA.