Skip to content
viggoVet
Legal & Trust Center

Vulnerability Disclosure Policy

Last updated June 5, 2026

Security is central to viggoVet. We welcome good-faith research that helps us keep the platform and our customers’ data safe, and we will work with researchers who follow this Policy.

1. How to report

Report suspected vulnerabilities through our security disclosure form at viggo.vet/legal/security. Please include enough detail to reproduce the issue, the affected URL or component, and its potential impact. Do not include real patient or client personal data in your report.

2. Safe harbour

If you make a good-faith effort to comply with this Policy during your research, we will consider your testing authorised, will not pursue or support legal action against you for that research, and will work with you to understand and resolve the issue quickly. If legal action is brought by a third party, we will make clear that your activity complied with this Policy.

3. Rules of engagement

  1. act in good faith and avoid privacy violations, data destruction, and service disruption;
  2. only interact with accounts you own or have explicit permission to test;
  3. stop immediately and notify us if you encounter personal or clinical data, and do not access, copy, store, or share it;
  4. use only the minimum testing necessary to demonstrate an issue; and
  5. give us reasonable time to remediate before any public disclosure, and coordinate disclosure with us.

4. Out of scope

The following are not authorised: denial-of-service or volumetric testing, social engineering of staff or customers, physical attacks, attacks on third-party modules or services not operated by viggoVet, and automated scanning that degrades the service. Third-party modules are the responsibility of their developers.

5. What to expect from us

We aim to acknowledge reports promptly, validate and triage them, keep you informed of progress, and remediate verified issues as quickly as is practical. We may publicly recognise researchers who report valid issues, with their consent. We do not operate a paid bug-bounty programme at this time.

6. Contact

Security reports: our security disclosure form at viggo.vet/legal/security.