Legal
Security Policy
Feel August Health welcomes responsible disclosure of security vulnerabilities. If you believe you have found an issue in feelaugust.com or related infrastructure, here is how to report it, what we commit to in return, and what is in and out of scope.
How to report
Email [email protected] with:
- A clear description of the vulnerability
- Steps to reproduce, including URLs, payloads, and any required preconditions
- The potential impact
- Your contact information, which is optional but helpful for follow-up and credit
We monitor this mailbox during business hours, Monday through Friday, Pacific time. Acknowledgment typically arrives within two business days.
Scope
In scope:
- feelaugust.com and all subdomains we operate, excluding third-party-hosted services
- api.feelaugust.com, the booking API surface
- Booking flow, intake form, magic-link returning-patient path, cancellation path, and check-in path
- Insurance verification flow and any patient-data handling endpoints
Out of scope:
- Third-party services we use, such as Cloudflare, Google Cloud, PostHog, Resend, Spruce Health, and Workspace. Report those to the vendor directly.
- Denial of service attacks, volumetric testing, or anything that risks degrading service for patients
- Social engineering of clinicians, staff, or patients
- Physical security of personal workstations
- Reports generated solely from automated scanners without manual validation
What we commit to
- Acknowledge receipt within two business days
- Provide an initial triage assessment within five business days
- Keep you informed of remediation progress at reasonable intervals
- Credit you publicly if you wish, after the fix lands
- Not pursue legal action against researchers acting in good faith under this policy
Safe harbor
Research conducted under this policy and in good faith is authorized. We will not initiate legal action against researchers who report findings promptly, avoid exposing or destroying patient data, do not degrade service, and give us reasonable time to remediate before any public disclosure.
Patient data
If your testing surfaces protected health information, stop immediately and notify us. Do not download, share, or retain the data. We treat patient privacy as paramount and will work with you to confirm the gap is closed without further exposure.
Disclosure timing
We ask for 90 days from the date of acknowledgment before any public disclosure, extended by mutual agreement if the fix is structurally complex. We will work in good faith to remediate sooner.
Contact
Security reports [email protected]
General inquiries [email protected]