A stone watchtower with a lantern glowing over a walled garden

Security and vulnerability disclosure

How to report a security vulnerability in ViaCara, what is in scope, what we ask of researchers and what you can expect from us.

Our commitment

The people who use ViaCara trust us with information about their mental health and wellbeing. We take that seriously. If you believe you have found a security vulnerability in our service, we want to hear from you and we will work with you in good faith.

This page explains how to report a vulnerability, what is in scope and what you can expect from us. We do not operate a bug bounty programme and we do not offer financial rewards for reports.

How to report

Email security@viacara.com with as much of the following as you can:

Please send your report as soon as possible after finding the issue and do not share it publicly before we have had a reasonable opportunity to fix it. A machine-readable summary of this policy is published at /.well-known/security.txt.

If your report contains sensitive detail, you can encrypt it with our OpenPGP key (fingerprint 36D3 4A42 0F0D 88C3 363A 14FD 10AD B6FD D292 FE56).

What we ask of you

Because our service handles sensitive personal data, these rules protect the people who use it:

What you can expect from us

Scope

In scope: viacara.com and the subdomains we operate.

Out of scope:

How we look after the service

Security checks run on every change we ship, our dependencies are monitored for known vulnerabilities and our infrastructure is hosted in the EU. Details of how we handle personal data, including your rights and how to exercise them, are in our privacy policy.

Last updated: June 2026

This policy is written in plain language and is periodically reviewed for accuracy.