Security
Vulnerability Disclosure Policy
RadContour handles medical imaging data, so its security matters. We welcome reports from security researchers and users who find weaknesses in our software or website, and we will treat every report seriously.
This policy explains how to report a vulnerability, what we will do in response, and the boundaries we ask you to work within. Please read it fully before testing or reporting, and act in line with it.
Scope
In scope:
- The RadContour iPad application
- The website radcontourapp.com, including its waitlist endpoint
Out of scope:
- Third-party services we build on — for example Apple and Cloudflare. Report those to the provider directly.
- Any PACS, treatment planning system or hospital network that RadContour connects to. Those belong to their operators, and you must not test them.
- Findings that are already documented as known limitations in our DICOM Conformance Statement — notably that DICOM network traffic is unencrypted by design and must be deployed on a hospital-managed network.
- Reports that a service does not follow a "best practice" without a demonstrable security impact.
Reporting a vulnerability
Send your report to [email protected]. Reports may be submitted anonymously; you do not need to identify yourself to be taken seriously.
Please include:
- Where the vulnerability can be observed — the app screen, URL or endpoint
- A short title and a description of the type of vulnerability
- Its impact — what an attacker could actually achieve
- Steps to reproduce it, as a benign, non-destructive proof of concept
Clear reproduction steps let us triage quickly and accurately, and reduce duplicate reports.
What to expect
- We aim to acknowledge your report within 5 working days.
- We aim to complete an initial assessment within 10 working days, and will keep you informed as we go.
- We prioritise remediation by impact, severity and how easily the issue can be exploited. Some fixes take time, particularly where an App Store release is involved.
- We will tell you when the issue is resolved, and you are welcome to confirm that the fix genuinely addresses it.
RadContour is developed by a small team. We would rather set expectations we can meet than promise same-day turnaround we cannot.
Rules of engagement
Please do not:
- Break any applicable law or regulation
- Access more data than is necessary to demonstrate the issue — and stop as soon as you have
- Modify or delete any data that is not yours
- Run high-intensity, invasive or destructive scanning
- Attempt, or report, denial-of-service issues — including flooding a service with requests
- Disrupt the availability of our services for other users
- Social-engineer, phish or physically target anyone associated with RadContour
- Disclose the issue publicly, or to anyone else, other than through this policy
- Demand payment as a condition of disclosing a vulnerability
Please do:
- Comply with data protection law, and respect the privacy of our users and anyone whose data you might encounter
- Securely delete any data obtained during your research as soon as it is no longer needed — and in any case within one month of the issue being resolved
Coordinated disclosure
We are committed to fixing vulnerabilities promptly. Publishing details before a fix exists increases the risk to users, so we ask that you keep your findings confidential until we have confirmed the issue and, where applicable, released a fix. If you believe there is a strong reason to inform others sooner, contact us first and we will agree an approach together.
We may share a report with affected vendors or a relevant security authority where that is necessary to get the issue fixed. We will not share your name or contact details without your explicit permission.
Recognition
We do not currently run a paid bug bounty. If you would like to be credited for a valid report, tell us how you wish to be named and we will acknowledge you once the issue is resolved.
Legal
This policy follows common good practice for coordinated vulnerability disclosure. It does not authorise you to act in any way that breaks the law, nor in any way that would put RadContour or a partner organisation in breach of its own legal obligations. Research conducted in good faith and in line with this policy will not lead to us pursuing action against you.