Please use the fake doctor - Dr Bug Bounty to do your tests.
Welcome to the OneDoc Bug Bounty program! We're excited to offer a way for the security community to help us find and fix vulnerabilities on our platform.
Our mission, as a leading healthcare service provider in Switzerland, is to ensure the confidentiality, integrity, and availability of our users' (patients and healthcare professionals) data.
We believe that no technology is perfect and that working with skilled security researchers is crucial in identifying weaknesses in our technology.
If you've found a security bug in our service, we are happy to work with you to resolve the issue promptly and ensure you are fairly rewarded for your discovery.
We ask that you conduct your bug bounty activities in a way that does not impact the experience of our platform. If you are interested in testing something that may be considered dangerous, please contact us through the Yes We Hack platform to provide the necessary testing conditions.
Please adhere to the following rules while performing research on this program:
In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program’s scope and identified outside of our program’s scope, such as:
Also, in order not to encourage dark and grey economies, in particular the purchase, resale and trade of identifiers or stolen information, as well as all types of dangerous behavior (e.g. social engineering, ...), we will not accept or reward any report based on information whose source is not the result of failure on the part of our organization or one of our employees/service providers.
This excludes, but is not limited to:
Source of leak is in-scope | Source of leak belongs to our organization but is out-of-scope | Source of leak does not belong to our organization and is out-of-scope | |
---|---|---|---|
Impact is in-scope (e.g. valid credentials on an in-scope asset) | Eligible | Eligible | Not Eligible |
Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset) | Eligible | Not Eligible | Not Eligible |
As a complement to the Program’s rules and testing policy :
We are happy to thank everyone who submits valid reports which help us improve the security of OneDoc, however only those that meet the following eligibility requirements may receive a monetary reward:
Reward amounts are based on:
Our public application, which allows patients to:
Our video consultation application, accessible through a link sent to the patient by email so they can remotely consult their doctor. Patients should not be able to access a video room that is not created for them.
Our professional application, only accessible to registered and verified healthcare professionals. Patients should not be able to login.
Scope Type | Scope Name |
---|---|
api | https://api.onedoc.ch |
web_application | https://www.onedoc.ch |
web_application | https://pro.onedoc.ch |
web_application | https://telehealth.onedoc.ch |
Scope Type | Scope Name |
---|---|
undefined | All domains or subdomains not listed in the above list of 'Scopes' |
This program crawled on the 2025-04-01 is sorted as bounty.
FireBounty © 2015-2025