Skip to content

Security: drmaroc/.github

Security

.github/SECURITY.md

Security Policy

Dr Maroc is a healthcare platform that processes personal and medical data. We take the security of that data seriously and appreciate responsible disclosure.

Reporting a vulnerability

Do not report security vulnerabilities through GitHub issues, discussions, or pull requests, even in private repositories. Issues are visible to every member with access to the repository.

Report vulnerabilities privately by email to ismail.zahir@drmaroc.com with the subject line [SECURITY].

What to include

  • A description of the vulnerability and its potential impact
  • Affected application, component, endpoint, and version or commit, if known
  • Steps to reproduce or a proof of concept
  • Whether the issue could expose patient, practitioner, or medical data, or allow a user to access data belonging to another account or practice

Do not access, modify, or retain data that does not belong to you while investigating an issue. Never include real patient data in your report; use anonymized examples or test accounts.

What to expect

  • We will acknowledge your report and keep you informed as we investigate.
  • We will coordinate a fix and disclosure timeline with you.
  • Please give us reasonable time to address the issue before any public disclosure.

Repositories may extend this policy with their own SECURITY.md describing component-specific scope.

There aren't any published security advisories