Security
Security Vulnerability Disclosure
Gobiquity, Inc. (dba GoCheck Kids) values the work of the security research community and welcomes reports of potential security vulnerabilities affecting our products and services. This page explains what is in scope, how to submit a report, and what you can expect from us.
Scope
The following systems and services are in scope for vulnerability reports submitted by external parties, including independent security researchers, customers, and members of the public:
-
GoCheck Kids Vision Screener and MultiScreener mobile applications
-
GoCheck Kids Web Application Portal
-
Any other public-facing infrastructure owned or operated by Gobiquity, Inc.
Any system or service not expressly listed above — including third-party services and integrated electronic health record (EHR) systems — is out of scope and is not authorized for testing.
Guidelines for Security Researchers
We consider security research to be conducted in good faith, and will not pursue legal action against researchers, when the researcher:
-
Avoids privacy violations, destruction of data, and interruption or degradation of our services.
-
Only interacts with accounts they own or with the explicit permission of the account holder.
-
Provides us at least ninety (90) calendar days before any public disclosure to investigate and address the reported issue, or another timeframe mutually agreed upon based on the complexity and risk of the vulnerability.
-
Does not exploit a vulnerability to access more data than necessary to demonstrate the issue. If protected health information (PHI), personal information, credentials, or other sensitive data is encountered, the researcher must immediately stop, must not download, retain, copy, modify, or disclose that data, and must promptly notify us.
-
Does not perform denial-of-service (DoS/DDoS) testing, social engineering (including phishing) directed at our workforce, or physical intrusion attempts against our facilities.
How to Report a Vulnerability
If you believe you have discovered a security vulnerability in an in-scope system, please email us at security@gocheckkids.com. To help us investigate quickly, please include:
-
A description of the location and nature of the vulnerability
-
Detailed steps needed to reproduce the issue (proof-of-concept scripts or screenshots are helpful)
-
The potential impact of the vulnerability
What to Expect
We will acknowledge receipt of your report in a timely manner and, where practicable, provide status updates as we validate and remediate the issue. Gobiquity does not currently operate a paid bug bounty program and does not offer financial rewards for vulnerability reports; however, we are happy to publicly acknowledge your contribution, with your permission, once the issue has been resolved.
Safe Harbor
Security research conducted in good faith and consistent with these guidelines is authorized by Gobiquity, Inc., and we will not recommend or pursue legal action related to that research. If you inadvertently encounter sensitive data or otherwise exceed the scope described above, please stop testing immediately, avoid any further access or disclosure, and notify us promptly at security@gocheckkids.com.