Openwater builds medical-device research software. We take security and patient-safety-adjacent issues seriously and appreciate coordinated disclosure.
Please do not report security vulnerabilities through public GitHub issues.
Instead, use one of the following:
- GitHub's private vulnerability reporting ("Report a vulnerability" under the Security tab) on the affected repository, or
- Email security@openwater.health (placeholder — confirm) with a description, affected repo/version, and reproduction steps.
- Acknowledgement within 3 business days.
- An initial assessment and severity triage within 10 business days.
- Coordinated disclosure: we will agree on a disclosure timeline with you and credit you unless you prefer to remain anonymous.
This policy applies to all repositories in the OpenwaterHealth organization. For deployments operated by third parties (including "Openwater-Certified" deployments), contact the operator; safety-event reporting obligations for certified deployments are defined in the Certification Agreement.
Clinical or device safety concerns are handled separately from software vulnerabilities. Certified clinical deployments follow the safety-event flowback process defined in the Certification program.