SMILE EDITOR — RESPONSIBLE DISCLOSURE POLICY
Effective Date: [EFFECTIVE DATE]
We take the security of Smile Editor and customer data seriously. If you believe you have found a security vulnerability, please report it responsibly to [SECURITY EMAIL].
What to Include
Please provide:
- summary and potential impact;
- affected URL, feature or endpoint;
- reproduction steps;
- relevant screenshots with sensitive data redacted;
- browser/device/environment;
- proof-of-concept where safe and necessary.
In Scope
- smileeditor.com and official subdomains;
- authenticated Smile Editor application;
- official APIs;
- authentication and authorization;
- cross-tenant access;
- unauthorized access to patient/customer files;
- storage access controls;
- privilege escalation;
- material injection or remote-code vulnerabilities;
- exposure of secrets or sensitive data.
Out of Scope / Prohibited
- denial of service;
- social engineering;
- physical attacks;
- destructive testing;
- accessing, copying or changing another user's real Patient Data;
- high-volume automated scanning that degrades the Service;
- spam;
- attacks against third-party services not controlled by Smile Editor;
- purely theoretical issues without meaningful security impact.
Low-rate automated testing may be acceptable when it does not affect other users or availability.
Patient Data Rule
If you accidentally obtain access to Patient Data belonging to another user or organization:
- stop testing immediately;
- do not copy, retain, further access or disclose the data;
- collect only the minimum evidence necessary to describe the issue;
- report it promptly to [SECURITY EMAIL].
Coordinated Disclosure
Please give Smile Editor a reasonable opportunity to investigate and remediate before public disclosure.
Safe Harbor
If you make a good-faith effort to comply with this Policy, Smile Editor will not initiate legal action against you solely for authorized security research conducted under this Policy. This safe harbor does not authorize unlawful access, extortion, privacy violations, destruction, service disruption or conduct outside this Policy.
Response Targets
We aim to:
- acknowledge receipt within 3 business days;
- provide a substantive status update within 10 business days;
- maintain reasonable communication for validated issues.
These are targets, not service guarantees.
Bug Bounty
Smile Editor does not currently operate a paid bug bounty unless separately announced.
Contact
Security: [SECURITY EMAIL]