# Theracharts security contact (RFC 9116) # https://theracharts.com/.well-known/security.txt Contact: mailto:security@theracharts.com Expires: 2027-04-10T23:59:59.000Z Preferred-Languages: en Canonical: https://theracharts.com/.well-known/security.txt Policy: https://theracharts.com/privacy # Theracharts is a HIPAA-compliant mental health SaaS. We take reports of # security vulnerabilities seriously and investigate every good-faith # submission. Please include a clear reproduction, the affected URL or # endpoint, and the impact you were able to demonstrate. Do not access, # modify, or exfiltrate data that does not belong to you. # # We do not currently run a paid bug bounty program and do not pay # unsolicited vulnerability reports. We will publicly acknowledge # researchers who report verified issues responsibly. # # Please do not report non-security issues (feature requests, billing, # support) to this address. Use support@theracharts.com instead.