Responsible Disclosure Policy
Effective 25 September 2026
If you think you've found a security weakness in SmileSort, we want to hear from you. SmileSort holds dental practices' clinical photographs, so a report that helps us close a gap protects patients — thank you for taking the time.
This policy explains how to report, what you may test and how, and what you can expect from us in return, including our promise not to take legal action over good-faith research that follows it.
Report a vulnerability
Email security@smilesort.com — we'll acknowledge it within 3 working days.
1. How to report
Email security@smilesort.com with:
- what you found, and where — the page, feature or address;
- the steps to reproduce it, and any proof-of-concept or screenshots;
- what you think someone could do with it;
- how you'd like to be credited, if at all (see section 8).
Please don't put patient information, or anything that identifies a real person, in your report — describe it instead ("a photograph from another practice was visible"). If you need to send us something sensitive, say so and we'll arrange a secure way to receive it.
One issue per report helps us track each fix, but a short chain of related findings is fine in one email. Reports in English, please.
2. What you can expect from us
- We'll acknowledge your report within 3 working days.
- Within 10 working days we'll tell you whether we could reproduce it and how serious we think it is.
- We'll keep you updated while we fix it, and tell you when it's fixed.
- If you'd like, we'll credit you publicly once it's fixed.
- We'll only use your details to handle your report, and won't share them without your permission.
Working days are Monday to Friday, excluding bank holidays in England and Wales. SmileSort is a small team; these are commitments we can keep, not an out-of-hours response.
3. What's in scope
In scope: smilesort.com and any of its subdomains (*.smilesort.com) — the website, the SmileSort app, share links and the endpoints behind them.
Out of scope:
- Services run by the companies we use — Supabase, Cloudflare, Stripe, Anthropic and Resend. Please report problems in their platforms to them directly. How we have configured them is in scope, though: a storage bucket of ours that anyone can read is our problem, and we want to know.
- Denial-of-service or load testing, and spam.
- Social engineering or phishing of our team or of dental practices, and physical attacks.
- Output from automated scanners that you haven't confirmed is a real, exploitable issue.
- Issues that need an already-compromised device or an unsupported, out-of-date browser.
If you're unsure whether something is in scope, ask us before testing it.
4. Testing safely
Ask us for a test account. Email security@smilesort.com and we'll set up a test practice for you, with no card needed. Only test against that account and the data you create in it — never another practice's account, and never real patient photographs.
While testing, please:
- access only what you need to show the problem exists — once you've shown it, stop;
- never change, download or delete data that isn't yours;
- keep automated testing light — nothing that could slow SmileSort down for the practices relying on it;
- send share links and emails only to addresses you control, so no one outside your test is contacted;
- don't leave anything behind — no backdoors, and tell us about test data you'd like removed;
- keep what you find confidential until it's fixed (see section 6).
5. If you come across personal data
If your testing reaches any data that isn't yours — above all a patient's photograph or details — stop immediately. Don't save, copy, share or keep it, and delete anything already on your device. Then tell us straight away, describing what you saw rather than sending it.
We treat a report like this as a possible personal data breach, which includes telling the dental practices affected, as our Data Processing Agreement requires. Stopping and reporting promptly is following this policy, not breaking it.
6. Publishing your findings
Please give us a fair chance to fix the problem before you tell anyone else. We ask that you wait until we've confirmed it's fixed, or 90 days from your report, whichever comes first. If a fix genuinely needs longer, we'll explain why and agree a date with you.
When you do publish, leave out any personal data you came across.
7. Legal protection for good-faith research
If you act in good faith and follow this policy:
- we consider your research authorised by SmileSort, and we won't take legal action against you or report you to the police for it, including under the Computer Misuse Act 1990;
- if anyone else takes action against you over research that followed this policy, we'll make it known that we authorised it.
This covers SmileSort's own systems. We can't authorise testing of other companies' services, or give permission on behalf of the dental practices whose data SmileSort holds — which is why testing has to stay within your own test account.
It doesn't cover deliberately accessing other people's data beyond what's needed to show a problem, keeping or sharing that data, demanding payment in exchange for a report, or causing harm to SmileSort, the practices using it or their patients.
8. Thanks
We don't run a paid bug bounty. If your report leads to a fix and you'd like to be credited, we'll add your name or handle to this page once the fix is live.
9. Changes to this policy
We may update this policy as SmileSort changes; the effective date at the top shows the current version. A report made under an earlier version is handled under the version it was made under.
For security questions that aren't vulnerability reports — reviewing SmileSort for your practice, for example — the same address works, and our Trust Centre sets out how SmileSort protects clinical photography.