Security & Responsible Disclosure
1. Security commitment
Spot Now's architecture includes encryption in transit and at rest, managed keys with rotation, unique identities with role-based and attribute-based access control, MFA for privileged users, comprehensive audit logging, environment isolation, secure software development (threat modeling, static and dependency scanning, penetration testing), rate limiting and abuse detection, and an incident-response process covering detection through post-incident review.
2. How to report a vulnerability
Email security@getmyspotnow.com. We acknowledge reports promptly, keep you informed of remediation status, and credit researchers who wish to be credited once a fix ships. Never include protected health information or another person's personal data in an ordinary email report.
3. What a useful report includes
The affected URL or endpoint, reproduction steps, the impact you believe is possible, any proof-of-concept (minimized — do not exfiltrate data to demonstrate impact), and how we can reach you for follow-up.
4. Prohibited testing
Do not access, modify, or delete data belonging to others; do not run denial-of-service, spam, or social-engineering attacks; do not test physical security; do not use automated scanners that degrade service; and do not attempt to access production patient data. Test accounts you create yourself are the correct target.
5. Good-faith reporting
[FOR COUNSEL REVIEW] Research conducted in good faith within these rules will not be met with legal action, and we will work with you to understand and resolve the issue. The formal safe-harbor language is finalized by counsel.