Security
Report a vulnerability.
If you have found a way to read, change or lose a lab’s data that Dictum should prevent, we want to hear about it first.
How to report
Write to [email protected]. Tell us the version (from About Dictum), what you did, what happened, and what you expected. Steps we can repeat on a synthetic case are the most useful thing you can send.
Please
- Test only on your own installation, with synthetic patients. Never test against a lab’s installation, its Google account, or its iPads.
- Do not access, keep or share real patient data. If you come across any, stop and tell us.
- Give us a reasonable time to fix the problem before you publish it.
What we do
- We reply to say we have your report, and keep you told as we work on it.
- We fix it, ship the fix through Dictum’s own updates, and tell affected labs what to do, if anything.
- If you would like to be credited when the fix ships, we will name you.
What is in scope
The Dictum desktop app, the iPad companion, the encrypted backup and pairing, the installer and its updates, and this website.
Machine-readable contact: /.well-known/security.txt