Support
Security Disclosure
How to responsibly report a security vulnerability to OnePath.
OnePath takes security seriously. If you've discovered a vulnerability, we want to know — and we'll work with you quickly to address it.
How to Report
Email security@onepath.health with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Any proof-of-concept code (if applicable)
We will acknowledge receipt within 24 hours and provide a timeline for resolution within 72 hours.
What We Ask
- Give us reasonable time to address the issue before public disclosure
- Do not access or modify data that isn't yours
- Do not perform denial-of-service testing
What We Promise
- We will not take legal action against researchers who follow this policy
- We will acknowledge your contribution (unless you prefer anonymity)
- We will notify you when the vulnerability is fixed
Scope
In scope:
api.onepath.health— Partner APIportal.onepath.health— Partner Portalsandbox.onepath.health— Sandbox environment
Out of scope:
- Social engineering
- Physical security
- Third-party services