Security

Vulnerability disclosure policy

We welcome reports from security researchers. If you find a weakness in Capture.Study, tell us and give us a fair chance to fix it before anyone else hears about it. In return, we'll work with you openly and won't pursue legal action for good-faith research.

Last updated September 29, 2026

How to report

Email security@capture.study with:

  • what the vulnerability is and where it is (URL, page or endpoint);
  • the steps to reproduce it, with screenshots or a short video if that helps;
  • what an attacker could do with it, as far as you know;
  • how you would like to be credited, or that you would rather not be named.

Please don't put participant data, passwords or other secrets in your report. If you need to show that data was exposed, describe it (for example, “a participant's email address from another study”) rather than copying it. Reports in English are easiest for us to handle quickly.

Scope

In scope:

  • app.capture.study, the Capture.Study application, including the participant portal and eConsent;
  • the backend services the application calls on your behalf;
  • capture.study, this website.

Out of scope:

  • denial-of-service or load testing, and anything that degrades the service for other users;
  • social engineering, phishing or physical attacks against our staff, customers or offices;
  • spam or email-bombing through sign-up, password reset or contact forms;
  • vulnerabilities in third-party services we use, unless you can show a direct impact on Capture.Study (report those to the vendor as well);
  • findings from automated scanners with no demonstrated impact, missing best-practice headers on their own, clickjacking on pages with no sensitive action, and self-XSS.

Rules for testing

  • Test only against accounts and studies you own. The free sandbox gives you a full study with every feature and no credit card, so you can create as many test accounts, roles and participants as you need.
  • Never access, change or delete data that belongs to someone else. If you reach real study or participant data, stop straight away, do not download or keep it, and tell us immediately. Clinical trial data belongs to real patients.
  • Do only what you need to demonstrate the problem. Don't pivot to other systems, keep access open, or run exploits that could affect other customers.
  • Keep the details between you and us until the issue is fixed or 90 days have passed since your report, whichever comes first. If we need longer, we will explain why and agree a date with you.
  • Follow the law, and don't test from a place or in a way that breaks it.

What you can expect from us

  • We acknowledge your report within 3 business days.
  • We give you our first assessment, including whether we can reproduce it and how serious we think it is, within 10 business days.
  • We keep you updated while we fix it and tell you when the fix is live.
  • We credit you publicly once the issue is fixed, if you want us to.
  • We treat your report and your identity as confidential and share them only with the people who need them to fix the issue.

We do not run a paid bug bounty programme at the moment, so we can't offer money for reports. We are grateful for every good-faith report all the same.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorised. We will not bring legal action against you or ask law enforcement to investigate you for it, and if a third party does, we will make it known that you acted with our authorisation.

If you are unsure whether something you plan to do is covered, ask us at security@capture.study before you do it.

Machine-readable contact

Our contact details and this policy are also published in /.well-known/security.txt (RFC 9116).