Responsible Disclosure

Found a security issue? Report it responsibly.

We welcome good-faith reports that help improve the security of Umoja Afya EHR. Do not access real or unauthorized data, disrupt services, or publicly disclose a vulnerability before a reasonable remediation process.

What to include

  • A clear description of the issue
  • The affected URL, route, component or version
  • Reproduction steps that minimize impact
  • Observed versus expected behavior
  • Potential security impact
  • Your preferred contact information

Rules of engagement

Use only accounts and data you are authorized to access. Do not perform denial-of-service testing, destructive actions, credential attacks, broad automated scanning, data exfiltration or social engineering.

Protect information

If you unexpectedly encounter sensitive information, stop testing, do not copy or redistribute it, and report the issue promptly.

Coordination

Please allow reasonable time to investigate, reproduce, remediate and validate a fix before public disclosure. Production customers may have additional contractual incident-reporting channels.

Where to report

Use the public contact form and select the most appropriate technical/security inquiry category, or use the dedicated security contact published by the operator when available.