Skip to content

Security: balsm-health/Balsm-API-DotNet

SECURITY.md

Security Policy

Balsm is healthcare software. Security reports are treated with the highest priority, and we are grateful to researchers who disclose responsibly.

Reporting a Vulnerability

Please do not open public issues, discussions, or pull requests for security vulnerabilities.

Report privately using one of these channels:

  1. GitHub private vulnerability reporting (preferred) — open the Security tab of the affected repository and click "Report a vulnerability". See GitHub's guide to privately reporting a vulnerability.
  2. Email — if the button is unavailable or you prefer email, write to legal@balsm.health with the subject line SECURITY.

Include as much of the following as you can: the affected repository and version/commit, steps to reproduce, impact assessment, and any suggested remediation.

What to Expect

  • We will acknowledge your report within 72 hours.
  • We will work with you on assessment, remediation, and coordinated disclosure.
  • Please give us a reasonable window to ship a fix before any public disclosure.

Scope

This policy applies to every repository in the balsm-health organization unless a repository defines its own SECURITY.md.

There aren't any published security advisories