generated: '2026-09-02' method: searched source: >- https://github.com/ehrbase/ehrbase/blob/develop/SECURITY.md, https://github.com/ehrbase/ehrbase/security/policy, probes of /.well-known/security.txt on every EHRbase host published: true policy_url: https://github.com/ehrbase/ehrbase/security/policy policy_source: https://raw.githubusercontent.com/ehrbase/ehrbase/develop/SECURITY.md contact: mailto:ehrbase-security@vitagroup.ag note: >- EHRbase publishes a genuine responsible-disclosure policy - as SECURITY.md in the server repository, which GitHub surfaces at /security/policy. It names a dedicated security mailbox operated by vitagroup rather than routing reports through public issues, and it explains WHY: "Given that EHRbase is used to handle sensitive, medical data, we would like to ask you to submit the vulnerability to ehrbase-security@vitagroup.ag, to allow triaging and handling of the vulnerability with standardized processes and response times." policy: model: coordinated / responsible disclosure channel: private email to a dedicated security mailbox acknowledgement: >- "Each report is acknowledged, analyzed and responded to by the team as soon as possible." No numeric SLA is published. disclosure_timing: >- "We will notify you as soon as the issue is triaged and we identify a fix and a release date, and create a full disclosure after a patch is released." in_scope: - A potential security vulnerability in EHRbase - Uncertainty about whether a vulnerability affects EHRbase out_of_scope: - Support in securely deploying/operating EHRbase - Support for additional environment-dependent security measures - Support with security-related updates - Non-security issues security_txt: published: false probes: - {url: 'https://www.ehrbase.org/.well-known/security.txt', status: 404} - {url: 'https://ehrbase.org/.well-known/security.txt', status: 404} - {url: 'https://docs.ehrbase.org/.well-known/security.txt', status: 404} - {url: 'https://sandkiste.ehrbase.org/.well-known/security.txt', status: 200, note: 'Vaadin SPA HTML shell served for every /.well-known/* path - not a document'} gap: >- The policy exists but is only discoverable from the GitHub repository. An RFC 9116 security.txt on ehrbase.org pointing at SECURITY.md and ehrbase-security@vitagroup.ag would make it machine-discoverable at no cost. bug_bounty: program: false platform: null detail: >- No HackerOne / Bugcrowd / Intigriti program. SECURITY.md cites Bugcrowd only as a reference definition of responsible disclosure, not as a program EHRbase runs. advisories: github_security_advisories: https://github.com/ehrbase/ehrbase/security/advisories supply_chain: license: Apache-2.0 code_of_conduct: https://github.com/ehrbase/ehrbase/blob/develop/CODE_OF_CONDUCT.md contributing: https://github.com/ehrbase/ehrbase/blob/develop/CONTRIBUTING.md notice: https://github.com/ehrbase/ehrbase/blob/develop/NOTICE