Senior Living Watch

Security & Vulnerability Disclosure

We welcome good-faith security research. If you believe you have found a vulnerability in Senior Living Watch, we want to hear about it.

Contact: security@seniorliving.watch

Scope

This policy covers the Senior Living Watch application at seniorliving.watch and its subdomains.

The following are out of scope:

  • Third-party infrastructure we do not control (Stripe, Cloudflare, Render, SendGrid).
  • Volumetric or denial-of-service (DoS) testing.
  • Social engineering of our staff or users.
  • Physical attacks.
  • Any testing that accesses, modifies, or degrades real user data.

Rules

  • Test only against your own account and your own data.
  • Do not access, modify, or delete other users' data.
  • Report what you find promptly.
  • Give us reasonable time to remediate before any public disclosure.

Rewards

We do not offer a monetary reward at this time. This is a disclosure policy, not a paid bug bounty. We acknowledge valid reports, and we are glad to credit reporters who would like recognition.

Safe harbor

Good-faith security research conducted in line with this policy is authorized. We will not pursue legal action against researchers who follow it. If you are unsure whether an action is permitted, ask first at security@seniorliving.watch.