Vulnerability Disclosure
This page is for security researchers reporting a vulnerability in a Headway system. If you have a question about your account, billing, or how we handle your health information, our help center is the right place to start.
Reporting a vulnerability
Email [email protected]. Reports may be submitted anonymously. Contact information is optional, but we can only follow up with you if you provide it.
If you share contact information, we will acknowledge your report within three business days, tell you whether we were able to reproduce the issue, and may keep you updated through remediation.
What to include
- The affected URL, endpoint, or application, and the type of vulnerability.
- Steps to reproduce it — request and response pairs, screenshots, or proof-of-concept code.
- What an attacker could do with it.
- Redact any personal or health information from everything you send us.
Reports in English are easiest for us to act on quickly. Confirm findings by hand before sending them; automated scanner output on its own is not a report.
Safe harbor
If you make a good faith effort to follow this policy, we will consider your research authorized and we will work with you to resolve the issue.
We treat demands for payment in exchange for withholding a report, or for not disclosing or destroying data, as extortion rather than research.
Rules of engagement
- If you encounter personal or health information, stop immediately. Do not access, save, copy, transfer, or disclose it. Tell us right away, and delete any copies once we confirm we have your report.
- Use exploits only as far as needed to confirm a vulnerability exists. Do not exfiltrate data, establish persistent access, or pivot to other systems.
- Test only with accounts you create. Do not interact with real client, provider, or employee accounts.
- Rate-limit automated scanning. People rely on Headway to get care and to get paid, so testing that degrades the platform is not authorized.
- Do not submit a high volume of low-quality reports.
Denial-of-service testing, social engineering of clients, providers, or employees, and physical testing are not authorized. Neither is testing against third-party services we use — report those to the vendor directly.
Discouraged Submissions
These kinds of issues generally do not represent actionable risk. If submitting something like this, provide increased detail about actual risk.
- Missing hardening with no demonstrated exploit: TLS configuration, cookie flags on non-sensitive cookies, email authentication records, reported version numbers.
- Denial of service or credential brute forcing.
- Self-XSS, logout CSRF, and clickjacking on pages without sensitive state changes.
- Issues simply describing end-of-life software without a specific relevant vulnerability.
- Issues that assume a compromised device or improbable user actions.
Questions
Reach us at [email protected]. We welcome suggestions for improving this policy.
Last updated: September 9, 2026