AverCare takes the security and privacy of our users, systems and information seriously.
We welcome responsible reports from security researchers, users and other third parties who believe they have identified a potential security vulnerability affecting an AverCare-controlled system or service.
We ask that security research is conducted responsibly, in good faith and in a manner that protects our users, their information and the availability of our services.
This Responsible Vulnerability Disclosure programme provides a channel through which potential security vulnerabilities affecting AverCare-controlled systems and services may be responsibly reported to AverCare.
If you believe you have identified a security vulnerability affecting AverCare, please report it privately to:
Security Contact: security@avercare.global
Website: www.avercare.global
Please provide as much relevant information as reasonably possible, including:
Please do not include unnecessary personal, health or other sensitive information in your report.
Responsible vulnerability reports may relate to AverCare-controlled:
Third-party products, platforms or infrastructure that AverCare does not control may fall outside the scope of this programme.
Testing of third-party systems is not authorised under this programme unless AverCare has the authority to permit such testing.
We ask researchers to:
Researchers should stop testing once sufficient information has been obtained to reasonably demonstrate the existence and potential impact of a vulnerability.
This disclosure programme does not authorise:
Conduct falling outside these requirements is not authorised under this Responsible Vulnerability Disclosure programme.
If you unintentionally encounter personal information, health information or other sensitive information during good-faith security research:
Please provide sufficient technical information for us to investigate without sending unnecessary sensitive information.
AverCare will make reasonable efforts to:
We may limit information provided about an investigation where necessary to protect security, privacy, confidentiality or ongoing investigations.
The nature and timing of remediation or other risk-treatment activities may vary depending on the severity, complexity, affected systems and potential impact of the reported vulnerability.
Please provide AverCare with reasonable time to investigate and remediate a reported vulnerability before publishing technical information that could place users or systems at risk.
Where public disclosure is appropriate, we encourage coordinated disclosure so that remediation can be made available before detailed vulnerability information is released.
Where reasonably possible, AverCare may coordinate with the reporter regarding:
AverCare may request that disclosure be delayed where remediation is actively underway and premature disclosure could materially increase risk to users, information or systems.
Nothing in this process is intended to prevent lawful reporting to an appropriate regulatory or law-enforcement authority.
Where security research is conducted in good faith and in accordance with this Responsible Vulnerability Disclosure guidance, AverCare's intention is to treat that activity as authorised security research within the scope described here and not to pursue action solely because a researcher identified and responsibly reported a vulnerability.
This does not apply to:
This safe-harbour statement does not authorise testing of systems or information controlled by third parties where AverCare does not have authority to grant such permission.
AverCare does not currently represent this disclosure programme as a bug-bounty programme.
Submitting a vulnerability report does not create an entitlement to payment, compensation, reward or other benefit unless AverCare has expressly agreed otherwise in writing.
Any future bug-bounty or reward programme established by AverCare will be governed by its own applicable terms and conditions.
Security vulnerabilities should be reported privately to:
Email: security@avercare.global
Website: www.avercare.global
Please do not send unnecessary personal information, health information, credentials or other sensitive information when submitting a vulnerability report.
This is the published version of AC-COM-RVDP-383, version 1.0. The signed original is retained on record.