Disclosure policy
If you find a security defect in THOS, write to support@laetoli.tz. Tell us what you found and how to reproduce it.
Do not access, alter or retain another person’s health record. If a defect exposes one, stop there and say so in the report rather than demonstrating its extent.
What you can expect
- Acknowledgement
- Five working days
- Assessment
- Thirty days
- Time before you publish
- Ninety days
- Credit
- Yes, unless you decline
- A bounty
- None
What has been tested
- Row-level security
- On every clinical table
- Column grants
- Enumerated and checked
- Two-factor authentication
- Required for the operator
- Independent penetration test
- Never performed
- Sign-in throttling
- Not configured
What is in scope
tibaecosystem.co.tz and its subdomains, the clinical application, and the database behind them. Out of scope: the third-party services we run on, which have their own disclosure policies.