Skip to main content

Vulnerability disclosure

Last updated: August 4, 2026

This page explains how to report security vulnerabilities in VA Rating Assistant responsibly. It is for educational and operational clarity and is not legal advice.

Scope

In scope (examples):

  • Authentication, authorization, and tenancy boundaries (including VSO / partner portals)
  • Cross-user or cross-organization data exposure
  • Injection, XSS, CSRF, SSRF, and similar web/API issues on our domains
  • Misconfiguration that exposes PHI, PII, secrets, or backup material
  • Mobile app issues that expose tokens or health data on a locked device

Out of scope (examples):

  • Social engineering of employees or veterans
  • Physical attacks against data centers
  • Denial-of-service / volumetric flooding
  • Reports that require privileged access you do not own
  • Issues in third-party products we do not operate (report to that vendor)

How to report

  1. Email support@varatingassistant.com with a clear subject (for example, “Security vulnerability report”).
  2. Include the affected URL or component, steps to reproduce, impact, and any proof-of-concept that does not include real veteran PHI.
  3. Do not access, modify, or exfiltrate data that is not yours. Stop testing if you encounter live PHI.
  4. Allow a reasonable time for triage before public disclosure.

Our commitments

  • Acknowledge reports when practical (target: within 5 business days).
  • Triage severity and share material status updates when contact is available.
  • Not pursue legal action against good-faith researchers who follow this policy and do not violate privacy or disrupt service.
  • Optional credit in Acknowledgments after a fix ships.

Remediation targets

Internal engineering targets (not contractual guarantees):

  • Critical / CISA KEV: immediate triage; goal ≤ 7 days to remediate or mitigate
  • High: ≤ 30 days
  • Medium: ≤ 90 days
  • Low: best effort / next maintenance window

This information is for educational purposes only and is not legal or medical advice.