Security & Vulnerability Disclosure
tebIQ is a product of TebScribe LLC.
We take the security of clinician and patient data seriously and welcome reports from security researchers. If you believe you have found a security vulnerability in tebIQ, please tell us — we would rather hear it from you first.
No ads. No data brokers. No pharma. Your personal information stays yours — permanently.
Read the pledge, signed by the founder.
What to report
- Authentication or authorization flaws (accessing data you shouldn't).
- Ways to read, modify, or delete another account's or tenant's data.
- Injection, remote code execution, or server-side request forgery.
- Exposure of secrets, credentials, or personal / health information.
- Anything that could compromise the confidentiality, integrity, or availability of the service.
How to report
- Email security@tebscribe.com with a clear description and reproduction steps.
- Give us reasonable time to investigate and remediate before any public disclosure.
- Do not access, modify, or delete data that isn't yours, and stop as soon as you have confirmed a vulnerability.
- Do not run automated scans that degrade the service for others.
Safe harbor
We consider security research and vulnerability disclosure conducted in good faith under this policy to be authorized. If you make a good-faith effort to comply with this policy during your research, we will not pursue or support legal action against you for that research, and will work with you to understand and resolve the issue quickly.
This policy does not offer a monetary reward or bug bounty. It describes how to report an issue responsibly and how we will respond.