OnePath Connect
OnePath Connect
OnePath Connect Documentation
Error ReferenceFAQSecurity Disclosure
Support

Security Disclosure

How to responsibly report a security vulnerability to OnePath.

OnePath takes security seriously. If you've discovered a vulnerability, we want to know — and we'll work with you quickly to address it.

How to Report

Email security@onepath.health with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any proof-of-concept code (if applicable)

We will acknowledge receipt within 24 hours and provide a timeline for resolution within 72 hours.

What We Ask

  • Give us reasonable time to address the issue before public disclosure
  • Do not access or modify data that isn't yours
  • Do not perform denial-of-service testing

What We Promise

  • We will not take legal action against researchers who follow this policy
  • We will acknowledge your contribution (unless you prefer anonymity)
  • We will notify you when the vulnerability is fixed

Scope

In scope:

  • api.onepath.health — Partner API
  • portal.onepath.health — Partner Portal
  • sandbox.onepath.health — Sandbox environment

Out of scope:

  • Social engineering
  • Physical security
  • Third-party services

FAQ

Frequently asked questions about OnePath Connect.

On this page

How to ReportWhat We AskWhat We PromiseScope