We take the security of our users' data seriously. If you believe you have found a vulnerability in any Fetch product — the marketing site, the practice web portal, the mobile app, or our API — we'd like to hear from you so we can fix it.
How to report
Email [email protected] with as much detail as you can share. Helpful things to include:
- A clear description of the issue and where you found it.
- Steps to reproduce, screenshots, or a minimal proof-of-concept.
- The impact you think the issue has, and any prerequisites for exploiting it.
- Your name or handle if you'd like to be credited.
This same address is published in our security.txt for automated discovery (RFC 9116).
What to expect from us
- An acknowledgement within 3 working days.
- A triage update within 10 working days, including our assessment of severity and whether we are treating it as a security issue.
- Regular updates while we work on a fix. Time-to-fix varies with severity and complexity.
- Credit in our release notes when the fix ships, if you'd like it. We don't currently offer cash bounties.
In scope
fetchvet.coand its subdomainsapi.fetchvet.coandapi-staging.fetchvet.co- The Fetch iOS and Android apps
Out of scope
- Findings that require physical access to a victim's unlocked device.
- Social engineering of Fetch staff or users.
- Denial-of-service attacks, including volumetric flooding.
- Vulnerabilities in third-party services we depend on (please report those to the vendor directly).
- Best-practice issues without a demonstrable security impact (e.g. missing security headers on a page that doesn't handle authenticated content).
- Reports generated solely from automated scanners without a reproducible proof-of-concept.
Safe harbour
If you make a good-faith effort to comply with this policy when investigating and reporting an issue, we will not pursue legal action against you. Please don't:
- Access, modify, or delete user data that doesn't belong to you, beyond what is strictly necessary to demonstrate the issue.
- Use findings for any purpose other than reporting them to us.
- Publicly disclose the issue before we've had a reasonable opportunity to fix it (typically 90 days, sooner by mutual agreement).
