UbieBusiness
Policies›VCDP

Vulnerability Coordination and Disclosure Policy

Since the services and applications provided by our Company, Ubie, Inc., handle personal identifiable medical information (Medical PII), which is the most sensitive type of personal data, we recognize that vulnerabilities in our services and applications ("our Services") pose a significant risk to the confidentiality and security of customers' data.

While we make continuous efforts to detect and respond to vulnerabilities before they occur, such as checking for known vulnerabilities in operating systems and middleware and conducting vulnerability assessments by third-party experts, we also actively gather information not only from within the company but also from outside the company to enhance the safety of our Services.

As part of this effort, we have developed vulnerability coordination and disclosure policy, called "Ubiquitous Vulnerability Coordination and Disclosure Policy" (the "Policy"), for external security researchers who conduct research on our Services, which outlines what we look for in their communications with us and other companies, and what they can expect from us..

We recommend reading this policy carefully and complying with it at all times when you report vulnerabilities to Ubie.

Scope

This Policy applies to our website, Ubie AI Health Assistant, Ubie AI Symptom Checker, and any other services and applications we provide.

Reporting

If you find a vulnerability in our Services or websites, please send a vulnerability report to the following address.

security@dr-ubie.com

When reporting via e-mail, please use our PGP key or an appropriate encryption tool to encrypt the information before sending it to us. Please make sure that you do not include sensitive information such as personally identifiable medical information.

Please be sure to include the following information in your report.

  • Information on where the vulnerability was detected
    • For applications, information about the version of the application, the detected page, the IP address, and the OS on which the application is running.
    • For websites, information about the URL and IP address where the vulnerability was detected.
  • A summary of the vulnerabilities
    • Summary of discovered vulnerabilities such as remotely executable code, cross-site request forgery, SQL injection, etc.
  • Detailed information on how to reproduce the vulnerabilities
    • Detailed information on the steps to verify the vulnerability. These should be benign, non-destructive, proof of concept that does not cause system damage, data corruption, etc.

Well-written reports in Japanese or English have a higher chance of resolution.

What to expect

  • We will acknowledge receipt of your message within five (5) business days.
  • Our security team will contact you regarding the following items during the initial triage and assessment phases;
    • Request for additional information,
    • Communicate an expected process and timeline, or
    • Inform you of the results of the evaluation, whether the report is accepted or rejected
      • In case of rejection, we will inform you the reason thereof.
  • Once the necessary information has been provided and the report has been accepted, we will:
    • Review the report by the security officer or engineer in charge of the affected area;
    • Provide information on the investigation and remediation process; and
    • Provide final conclusions, including prioritization of improvements.
      • Remediation priorities will be determined based on our policy, taking into account the impact, severity, and complexity of the exploit.
  • When a reported vulnerability is fixed, we may notify the security researcher who reported the vulnerability to confirm that our countermeasure adequately covers the vulnerability.
  • Once the vulnerability has been resolved, we welcome requests for disclosure of the report.
    • If the vulnerability report is disclosed to the public, we will publicly acknowledge the security researcher's contribution (if requested).

Guidance

Security researchers are required to adhere to the following throughout the entire process of investigating, researching, and disclosing to us or others our Services.

  • Comply with all applicable laws and regulations of your location and the location in which we do business
  • Do not perform any of the following inappropriate actions using the vulnerability
    • Viewing, deletion, modification or disclosure of source code or the data on our Services
    • Viewing, deletion, modification or disclosure of other user's data
    • Any act in relation to vulnerability testing and reporting that violates others' rights
    • Any other actions that affect the availability of our services (DDoS attacks, etc.)
  • Do not engage in phishing activities against our company's employees or systems.
  • Do not perform any actions that may cause harm to users of our Services (including medical institutions and patients).
  • Do not conduct any network-level testing targeting medical institutions that use our Services.
  • Do not disclose vulnerability details to the public until an upon deadline agreed with us has been reached.
  • Notify us beforehand if you communicate with regulators or third parties about any vulnerabilities you discover.
  • Do not access personal information of others using the vulnerabilities. In the event you access any personal information of others, you shall immediately cease such action, report the details to us, and delete such personal information from all of your computer devices.

Rights on Inventions

In instances where a Reporter creates an invention, methodology or design for verifying or studying repair methods for a vulnerability ("Inventions"), industrial property rights and other patent filing/application rights related to such Inventions (including rights prescribed in Copyright Act of Japan, Article 27 and 28) and all other rights shall be transferred to us with the submission of the vulnerability details by the Reporter, and we shall be able to freely exercise and dispose of those rights.

Handling of Confidential Information

The Reporters shall treat vulnerability information, and any information obtained using the vulnerability, as confidential information, and cannot disclose, leak, or make public said vulnerability information to a third party until we finishes fixing the vulnerability and makes such information publicly available.

Changes to This Policy

We may modify the content of this Policy from time to time at our reasonable discretion. In such case, we will indicate the contents of changes as well as the effective date of the modification on our website or will publicize the same to the Reporters by notifying them in the manner prescribed by us.

Legalities

This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause incident.io or partner organisations to be in breach of any legal obligations.

Enacted: December 10, 2021

Ubie

Healthcare technology built for patients and the systems that serve them.

Company

  • Careers
  • Policies

Products

  • Smart Support
  • Advertising
  • Symptom Checker
  • Doctor's Note
  • Consult

Offices

New York

379 W Broadway, 2nd Floor
New York, NY 10012

Tokyo

Nihonbashi Life Science Building 4,
5th Floor, 3 Chome-8-4 Nihonbashihoncho,
Chuo City, Tokyo 103-0023, Japan

© 2026 Ubie, Inc.PrivacyTerms