Balsm is healthcare software. Security reports are treated with the highest priority, and we are grateful to researchers who disclose responsibly.
Please do not open public issues, discussions, or pull requests for security vulnerabilities.
Report privately using one of these channels:
- GitHub private vulnerability reporting (preferred) — open the Security tab of the affected repository and click "Report a vulnerability". See GitHub's guide to privately reporting a vulnerability.
- Email — if the button is unavailable or you prefer email, write to legal@balsm.health with the subject line
SECURITY.
Include as much of the following as you can: the affected repository and version/commit, steps to reproduce, impact assessment, and any suggested remediation.
- We will acknowledge your report within 72 hours.
- We will work with you on assessment, remediation, and coordinated disclosure.
- Please give us a reasonable window to ship a fix before any public disclosure.
This policy applies to every repository in the balsm-health organization unless a repository defines its own SECURITY.md.