SECURITY DISCLOSURE
Vulnerability Disclosure Policy
How to report a suspected security vulnerability, the limits of current testing authorization, sensitive-data handling, triage, and future coordinated disclosure.
Status: Current governance standard for applicable RTH public operations. Product-specific controls apply when the relevant product or program is enabled.
1. Reporting channel
RTH welcomes good-faith reports of suspected security vulnerabilities at security@restartingtheheart.com. Include the affected URL or asset, a clear description, reproducible steps where safely available, potential impact, and a way to contact you.
2. No open testing authorization yet
RTH does not currently operate an open penetration-testing or bug-bounty program. Publishing this reporting channel does not authorize access to accounts or data, credential attacks, denial of service, social engineering, physical testing, persistence, destructive activity, privacy invasion, or testing against third-party infrastructure.
3. Good-faith handling
If you encounter a suspected vulnerability without intentionally exceeding authorized access, stop when you can demonstrate the issue, avoid collecting or retaining personal information, do not publicly disclose sensitive details while remediation is underway, and report the issue promptly. RTH will evaluate reports based on the facts and applicable law.
4. Sensitive information
Do not include passwords, private keys, authentication tokens, medical records, child information, or unrelated personal data in a report. If evidence necessarily contains sensitive data, first request a secure transfer method.
5. Triage and communication
RTH will prioritize reports according to exploitability, affected data, privilege required, user impact, scope, and operational risk. RTH aims to acknowledge actionable reports promptly, may request additional details, and may coordinate a disclosure timeline when warranted. Response time can vary by severity and available resources.
6. Bounties
No payment or bounty is promised unless RTH separately publishes a written bounty program covering the reported system and activity.
7. Future coordinated disclosure program
If RTH later authorizes a broader security-research program, the in-scope assets, safe-harbor language, permitted techniques, exclusions, and disclosure expectations will be published explicitly. Researchers should rely on that published scope rather than infer authorization from this page.
Security reports: security@restartingtheheart.com. See the Vulnerability Disclosure Policy before performing security testing.
General questions may use the RTH contact page.