How DentalX protects a clinic's records
Report a vulnerability
If you find a security problem in DentalX, please tell us. This page says what is covered, how to report it, and the rules that keep patients' information safe while you look.
What is covered
The website and the apps served from these addresses, and the server functions they call:
- dentalx.studio
- app.dentalx.studio
- admin.dentalx.studio
Not covered
- Denial-of-service attacks and load testing.
- Social engineering or phishing of clinics, patients or our staff.
- Physical attacks on offices, clinics or devices.
- Services run by other companies, such as Google, Stripe or Meta: report those to that company.
How to report
Write to admin@vstreamx.com with what you found, where, and the steps that reproduce it. Leave any patient information out of the report.
We read every report and reply to the address you write from.
Rules while you test
This policy is not, by itself, permission to test DentalX's security: section 7 of the Terms of Service requires our written permission for that, so write to us first. The rules below apply to any testing we permit, and to anything you come across.
- Do not access, keep or copy patient information. If you reach any, stop at once, look no further, and report it to us.
- Test only with accounts you created yourself or that we gave you, and do not change or delete data that is not yours.
- Do not slow down or interrupt the service for clinics.
- Give us the time to fix a problem before you tell anyone else about it.
Rewards
No bug bounty is offered.
Our security.txt file gives the same contact to automated tools. security.txt