vitagroup · Vulnerability Disclosure

Vitagroup Vulnerability Disclosure

Vulnerability disclosure

vitagroup publishes a vulnerability disclosure policy for reporting security issues.

CompanyHealthcareHealth ITElectronic Health RecordsopenEHRFHIRClinical Data RepositoryInteroperabilityGermanyOpen Source
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-02'
method: searched
source: https://github.com/ehrbase/ehrbase/blob/develop/SECURITY.md
note: >-
  probe-security-programs.py found nothing, because vitagroup serves no
  /.well-known/security.txt on any of its hosts (all four probed, all 404 or SPA
  redirect — see well-known/vitagroup-well-known.yml). The policy exists anyway: it is
  published as SECURITY.md in the EHRbase source repository and routes to a
  vitagroup.ag mailbox, which is what makes it vitagroup's programme rather than an
  unowned community one.
program:
  published: true
  title: Responsible disclosure of security issues
  policy_url: https://github.com/ehrbase/ehrbase/blob/develop/SECURITY.md
  contact_email: ehrbase-security@vitagroup.ag
  model: responsible-disclosure
  bug_bounty: false
  bounty_platform: null
  safe_harbor_stated: false
  scope: EHRbase and HIP EHRbase
  rationale_quoted: >-
    "Given that EHRbase is used to handle sensitive, medical data, we would like to ask
    you to submit the vulnerability to ehrbase-security@vitagroup.ag, to allow triaging
    and handling of the vulnerability with standardized processes and response times."
  process:
  - Each report is acknowledged, analyzed and responded to by the team as soon as
    possible.
  - The reporter is notified once the issue is triaged and a fix and release date are
    identified.
  - A full disclosure is created after a patch is released.
  out_of_scope:
  - Support with securely deploying or operating EHRbase
  - Support for environment-dependent security measures
  - Support with security-related updates
  - Non-security issues
  response_sla_stated: false
security_txt:
  served: false
  hosts_probed:
  - www.vitagroup.ag
  - hip.vitagroup.ag
  - docs.ehrbase.org
  - sandkiste.ehrbase.org
  status: 404 on all four (302 to /login on sandkiste)
gaps:
- No /.well-known/security.txt on any vitagroup or ehrbase host, so an automated
  scanner or agent cannot discover this policy — it is only findable by opening the
  GitHub repository.
- No published response-time commitment, no safe-harbour language, and no bug bounty.
- The policy is not linked from vitagroup.ag or hip.vitagroup.ag.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/vitagroup-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.