
Our commitment
The people who use ViaCara trust us with information about their mental health and wellbeing. We take that seriously. If you believe you have found a security vulnerability in our service, we want to hear from you and we will work with you in good faith.
This page explains how to report a vulnerability, what is in scope and what you can expect from us. We do not operate a bug bounty programme and we do not offer financial rewards for reports.
How to report
Email security@viacara.com with as much of the following as you can:
- What you found and where you found it
- Steps to reproduce the issue
- What an attacker could do with it
- Any relevant evidence such as request and response details or screenshots
Please send your report as soon as possible after finding the issue and do not share it publicly before we have had a reasonable opportunity to fix it. A machine-readable summary of this policy is published at /.well-known/security.txt.
If your report contains sensitive detail, you can encrypt it with our OpenPGP key (fingerprint 36D3 4A42 0F0D 88C3 363A 14FD 10AD B6FD D292 FE56).
What we ask of you
Because our service handles sensitive personal data, these rules protect the people who use it:
- Never access, modify or store real user data. If you encounter someone else's data, stop immediately, do not save or share it and tell us in your report.
- Test only with accounts you created yourself.
- No automated scanning of our production service.
- No denial of service testing or anything that degrades the service for others.
- No social engineering of our team or the professionals on our platform, and no physical attacks.
What you can expect from us
- We will acknowledge your report within 5 working days.
- We will keep you informed as we investigate and fix the issue.
- We will not pursue legal action against research carried out in good faith within the rules on this page.
- With your permission, we are happy to credit you once the issue is resolved.
Scope
In scope: viacara.com and the subdomains we operate.
Out of scope:
- Services run by our third-party infrastructure providers and sub-processors. Report issues in those services to the provider directly.
- Findings from automated tools without a demonstrated security impact.
- Reports about email configuration records, missing security headers or software version disclosure without a working exploit.
- Denial of service, social engineering and physical attacks, which this policy does not authorise.
How we look after the service
Security checks run on every change we ship, our dependencies are monitored for known vulnerabilities and our infrastructure is hosted in the EU. Details of how we handle personal data, including your rights and how to exercise them, are in our privacy policy.
Last updated: June 2026
This policy is written in plain language and is periodically reviewed for accuracy.