How DentalX protects a clinic's records

Report a vulnerability

If you find a security problem in DentalX, please tell us. This page says what is covered, how to report it, and the rules that keep patients' information safe while you look.

What is covered

The website and the apps served from these addresses, and the server functions they call:

  • dentalx.studio
  • app.dentalx.studio
  • admin.dentalx.studio

Not covered

  • Denial-of-service attacks and load testing.
  • Social engineering or phishing of clinics, patients or our staff.
  • Physical attacks on offices, clinics or devices.
  • Services run by other companies, such as Google, Stripe or Meta: report those to that company.

How to report

Write to admin@vstreamx.com with what you found, where, and the steps that reproduce it. Leave any patient information out of the report.

We read every report and reply to the address you write from.

Rules while you test

This policy is not, by itself, permission to test DentalX's security: section 7 of the Terms of Service requires our written permission for that, so write to us first. The rules below apply to any testing we permit, and to anything you come across.

  1. Do not access, keep or copy patient information. If you reach any, stop at once, look no further, and report it to us.
  2. Test only with accounts you created yourself or that we gave you, and do not change or delete data that is not yours.
  3. Do not slow down or interrupt the service for clinics.
  4. Give us the time to fix a problem before you tell anyone else about it.

Rewards

No bug bounty is offered.

Our security.txt file gives the same contact to automated tools. security.txt