← Back to home

Security & Responsible Disclosure

Last updated: 19 May 2026

We take the security of our users' data seriously. If you believe you have found a vulnerability in any Fetch product — the marketing site, the practice web portal, the mobile app, or our API — we'd like to hear from you so we can fix it.

How to report

Email [email protected] with as much detail as you can share. Helpful things to include:

  • A clear description of the issue and where you found it.
  • Steps to reproduce, screenshots, or a minimal proof-of-concept.
  • The impact you think the issue has, and any prerequisites for exploiting it.
  • Your name or handle if you'd like to be credited.

This same address is published in our security.txt for automated discovery (RFC 9116).

What to expect from us

  • An acknowledgement within 3 working days.
  • A triage update within 10 working days, including our assessment of severity and whether we are treating it as a security issue.
  • Regular updates while we work on a fix. Time-to-fix varies with severity and complexity.
  • Credit in our release notes when the fix ships, if you'd like it. We don't currently offer cash bounties.

In scope

  • fetchvet.co and its subdomains
  • api.fetchvet.co and api-staging.fetchvet.co
  • The Fetch iOS and Android apps

Out of scope

  • Findings that require physical access to a victim's unlocked device.
  • Social engineering of Fetch staff or users.
  • Denial-of-service attacks, including volumetric flooding.
  • Vulnerabilities in third-party services we depend on (please report those to the vendor directly).
  • Best-practice issues without a demonstrable security impact (e.g. missing security headers on a page that doesn't handle authenticated content).
  • Reports generated solely from automated scanners without a reproducible proof-of-concept.

Safe harbour

If you make a good-faith effort to comply with this policy when investigating and reporting an issue, we will not pursue legal action against you. Please don't:

  • Access, modify, or delete user data that doesn't belong to you, beyond what is strictly necessary to demonstrate the issue.
  • Use findings for any purpose other than reporting them to us.
  • Publicly disclose the issue before we've had a reasonable opportunity to fix it (typically 90 days, sooner by mutual agreement).