Familis coordinates care around people at home. Our systems hold health-adjacent and personal data about beneficiaries and their families, so we take reports seriously and we answer them.
Please do not open a public issue, pull request, or discussion for a security problem.
Report it privately, either way:
- GitHub private vulnerability reporting — on any public Familis repository, open the Security tab and choose Report a vulnerability. This is the preferred route: it keeps the report, the discussion, and the fix in one private thread.
- Email — hello@familis.care with
SECURITYin the subject line.
A useful report includes:
- what the issue is, and which repository, service, or URL it affects;
- the steps to reproduce it, or a proof of concept;
- what an attacker could do with it — the impact is what sets our priority;
- any Familis version, commit, or environment involved.
Write in English or French, whichever you prefer.
| When | What we do |
|---|---|
| Within 3 business days | Acknowledge that we received your report. |
| Within 10 business days | Tell you whether we could reproduce it, our assessment of the severity, and how we intend to proceed. |
| Until it is closed | Keep you updated as we work, and tell you when the fix ships. |
We will credit you when we publish the fix, unless you would rather stay anonymous — just say so.
In scope: Familis production services (familis.care and its subdomains), the tablet kiosk, our published npm packages, and the source in this organisation's public repositories.
Out of scope: reports from automated scanners with no demonstrated impact, missing security headers or best practices with no exploitable consequence, denial of service through volume alone, social engineering of our staff or users, and vulnerabilities in third-party services we merely use.
While you are investigating, please stay within what you would want done to your own users:
- work only against accounts and data that are yours, or that we have given you;
- do not access, modify, or exfiltrate anyone else's data — if you stumble into it, stop and tell us;
- do not degrade or disrupt the service for real families;
- give us a reasonable window to fix the issue before you disclose it publicly.
Research conducted in good faith under these rules is welcome, and we will not pursue legal action over it.
Familis is a hosted product: the version that matters is the one running in production, and that is the one we patch. For our published packages, we support the latest released major version.