EHRbase · Vulnerability Disclosure

Ehrbase Vulnerability Disclosure

Vulnerability disclosure

EHRbase runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyHealthcareHealth ITElectronic Health RecordsClinical DataopenEHRInteroperabilityOpen SourceDatabasesStandards
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
mailto:ehrbase-security@vitagroup.ag

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-02'
method: searched
source: >-
  https://github.com/ehrbase/ehrbase/blob/develop/SECURITY.md,
  https://github.com/ehrbase/ehrbase/security/policy,
  probes of /.well-known/security.txt on every EHRbase host
published: true
policy_url: https://github.com/ehrbase/ehrbase/security/policy
policy_source: https://raw.githubusercontent.com/ehrbase/ehrbase/develop/SECURITY.md
contact: mailto:ehrbase-security@vitagroup.ag
note: >-
  EHRbase publishes a genuine responsible-disclosure policy - as SECURITY.md in the
  server repository, which GitHub surfaces at /security/policy. It names a dedicated
  security mailbox operated by vitagroup rather than routing reports through public
  issues, and it explains WHY: "Given that EHRbase is used to handle sensitive, medical
  data, we would like to ask you to submit the vulnerability to
  ehrbase-security@vitagroup.ag, to allow triaging and handling of the vulnerability
  with standardized processes and response times."
policy:
  model: coordinated / responsible disclosure
  channel: private email to a dedicated security mailbox
  acknowledgement: >-
    "Each report is acknowledged, analyzed and responded to by the team as soon as
    possible." No numeric SLA is published.
  disclosure_timing: >-
    "We will notify you as soon as the issue is triaged and we identify a fix and a
    release date, and create a full disclosure after a patch is released."
  in_scope:
    - A potential security vulnerability in EHRbase
    - Uncertainty about whether a vulnerability affects EHRbase
  out_of_scope:
    - Support in securely deploying/operating EHRbase
    - Support for additional environment-dependent security measures
    - Support with security-related updates
    - Non-security issues
security_txt:
  published: false
  probes:
    - {url: 'https://www.ehrbase.org/.well-known/security.txt', status: 404}
    - {url: 'https://ehrbase.org/.well-known/security.txt', status: 404}
    - {url: 'https://docs.ehrbase.org/.well-known/security.txt', status: 404}
    - {url: 'https://sandkiste.ehrbase.org/.well-known/security.txt', status: 200, note: 'Vaadin SPA HTML shell served for every /.well-known/* path - not a document'}
  gap: >-
    The policy exists but is only discoverable from the GitHub repository. An RFC 9116
    security.txt on ehrbase.org pointing at SECURITY.md and
    ehrbase-security@vitagroup.ag would make it machine-discoverable at no cost.
bug_bounty:
  program: false
  platform: null
  detail: >-
    No HackerOne / Bugcrowd / Intigriti program. SECURITY.md cites Bugcrowd only as a
    reference definition of responsible disclosure, not as a program EHRbase runs.
advisories:
  github_security_advisories: https://github.com/ehrbase/ehrbase/security/advisories
supply_chain:
  license: Apache-2.0
  code_of_conduct: https://github.com/ehrbase/ehrbase/blob/develop/CODE_OF_CONDUCT.md
  contributing: https://github.com/ehrbase/ehrbase/blob/develop/CONTRIBUTING.md
  notice: https://github.com/ehrbase/ehrbase/blob/develop/NOTICE

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ehrbase-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.