Security

Responsible disclosure

If you believe you have found a vulnerability in Epimely, please report it privately before disclosing it publicly. We will investigate, remediate, and follow up as quickly as the issue requires.

Where to report

Send reports to [email protected]. Include "Security report" in the subject if possible.

What to include

  • The affected URL, endpoint, feature, or mobile app surface.
  • Steps to reproduce the issue with a minimal proof of concept.
  • The expected impact, especially whether tenant data, PII, care notes, authentication, or audit logs are affected.
  • Any screenshots, request logs, timestamps, or test accounts that help us verify the issue.

What we ask

Please avoid accessing, modifying, deleting, exfiltrating, or publicly sharing another church's data. Do not use automated testing that degrades service availability. We welcome good-faith reports and will not pursue action for research that stays within these boundaries.

Security overview

For a buyer-facing overview of how Epimely protects pastoral-care records, read the Security overview.