Skip to content

Security: OpenwaterHealth/.github

Security

SECURITY.md

Security Policy

Openwater builds medical-device research software. We take security and patient-safety-adjacent issues seriously and appreciate coordinated disclosure.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use one of the following:

  • GitHub's private vulnerability reporting ("Report a vulnerability" under the Security tab) on the affected repository, or
  • Email security@openwater.health (placeholder — confirm) with a description, affected repo/version, and reproduction steps.

What to expect

  • Acknowledgement within 3 business days.
  • An initial assessment and severity triage within 10 business days.
  • Coordinated disclosure: we will agree on a disclosure timeline with you and credit you unless you prefer to remain anonymous.

Scope

This policy applies to all repositories in the OpenwaterHealth organization. For deployments operated by third parties (including "Openwater-Certified" deployments), contact the operator; safety-event reporting obligations for certified deployments are defined in the Certification Agreement.

Safety events

Clinical or device safety concerns are handled separately from software vulnerabilities. Certified clinical deployments follow the safety-event flowback process defined in the Certification program.

There aren't any published security advisories