This page describes, at a general level, how we protect the data entrusted to us, and how a security researcher can report a vulnerability to us safely and in good faith.
1. Our Security Approach
- Encryption of personal and health data in transit and at rest.
- Authenticated access — reaching your data requires signing in through a managed identity service.
- Isolation by owner — records are read and written against their owner, so one account cannot load another's data.
- Least privilege — systems and staff can reach only the data they genuinely need.
- Separated environments — production, staging and development are isolated from each other.
- Backups and recovery — point-in-time recovery and versioned storage protect against accidental loss.
- Infrastructure as code — the running system matches its reviewed definition rather than ad-hoc manual changes.
We deliberately do not publish detailed technical specifics where disclosure would itself weaken security.
2. Reporting a Vulnerability
If you believe you have found a security vulnerability in our website, apps, firmware or cloud services, please tell us before telling anyone else. Email contact@adarna.us with the subject line "Security — vulnerability report" and include:
- A description of the issue and why you believe it is a security problem.
- Steps to reproduce it, and the affected URL, app version or endpoint.
- Any proof-of-concept material, kept to the minimum needed to demonstrate the issue.
3. What We Ask of Researchers
- Give us a reasonable opportunity to fix the issue before public disclosure. We suggest 90 days, and will work with you if more time is genuinely needed.
- Do not access, modify, download or delete data that is not your own. If you encounter someone else's personal data, stop and tell us.
- Do not degrade our services — no denial of service, no spam, no social engineering of our staff or users, no physical attacks.
- Act in good faith and within the law.
4. What You Can Expect From Us
- Acknowledgement of your report within 48 hours.
- An assessment and an indicative timeline within 10 business days.
- Updates as we work, and notification when the issue is resolved.
- Credit for your finding if you would like it, and no credit if you would not.
We do not currently operate a paid bug bounty. We will not pursue legal action against a researcher who follows this Policy in good faith.
5. Out of Scope
The following are generally not treated as vulnerabilities: reports generated solely by automated scanners without a demonstrated impact, missing security headers with no exploitable consequence, weaknesses in third-party services we do not control, social engineering, and issues requiring physical access to an unlocked device.
6. If a Breach Occurs
No system is perfectly secure and we will not claim otherwise. If a breach affecting personal data occurred, we would investigate and contain it, notify affected users and the appropriate United States regulators as applicable United States federal and state breach-notification laws require, and publish a plain account of what happened and what to do.
7. Protecting Your Own Account
Use a unique password, keep your credentials private, keep your apps updated, and tell us at contact@adarna.us if you think your account has been accessed by someone else.