# Carmen Vulnerability Disclosure Policy

Carmen (askcarmen.eu) is a medical dictation and ambient-scribe platform used by physicians. Every recording and transcript it processes is health data. If you have found a security weakness in Carmen, we want to hear from you, and we want to fix it before anyone can misuse it.

This policy tells you how to report, what we promise in return, and which rules keep your research lawful and safe for patients.

## How to report

Send your report to **[security@askcarmen.eu](mailto:security@askcarmen.eu)** in English or Dutch. The same contact is published machine-readably at [/.well-known/security.txt](https://askcarmen.eu/.well-known/security.txt).

Please include:

- the affected component and URL, app version or endpoint;
- the steps needed to reproduce the issue, with a proof of concept where possible;
- the impact you believe it has;
- how you would like to be credited, or that you prefer to stay anonymous.

**Do not send patient data, transcripts, recordings or other people's personal data.** If you encountered such data while testing, stop, do not store or forward it, and tell us in your report that you saw it.

If your report contains sensitive detail, encrypt it to our OpenPGP key: [https://askcarmen.eu/pgp-key.txt](https://askcarmen.eu/pgp-key.txt), fingerprint `9735 021E 5C64 7F1E C279 7400 56D2 8D7A 5F38 331E` (Ed25519, expires 1 September 2027, renewed together with `security.txt`).

## What we promise

- We will **acknowledge your report within 5 business days**.
- We will keep you informed while we investigate and remediate.
- We aim to **fix confirmed vulnerabilities within 60 days** of your report, and sooner for severe ones.
- We will credit you publicly, if you want that, once the issue is fixed.
- We **will not pursue legal action** against you, and will not report you to law enforcement, for security research carried out in good faith and in accordance with this policy. If a third party takes legal action against you for research that complies with this policy, we will make it known that you acted in accordance with it.

We do not run a paid bug-bounty programme at this time.

## Coordinated disclosure

We ask you to give us **60 days from your report** before you publish any detail of the vulnerability, or until we confirm that a fix is in production, whichever comes first. If we need more time, for example because a fix depends on a hospital rollout or on an app-store release, we will ask you for an extension and explain why. We will not ask you to keep silent indefinitely.

## Scope

In scope:

- `askcarmen.eu` and `www.askcarmen.eu` (website and web app);
- `api.askcarmen.eu` (backend API);
- the Carmen desktop widget for Windows and macOS;
- the Carmen mobile app for Android and iOS.

Out of scope:

- infrastructure and services operated by our providers, such as Hetzner, OpenAI, Resend, GitLab or Apple and Google app stores, unless the weakness is in how Carmen uses them;
- denial-of-service, load or brute-force testing;
- social engineering, phishing or physical attacks against Carmen staff, users or hospitals;
- vulnerabilities in third-party dependencies without a demonstrated impact on Carmen;
- missing best-practice headers or configuration without an exploitable consequence;
- reports from automated scanners without analysis.

## Rules

Your research is covered by this policy when you:

- act in good faith, to help us fix the problem rather than to profit from it;
- test only with accounts you own (a free trial sign-up is fine) and never access, change or delete data that belongs to someone else;
- go no further than needed to prove the vulnerability, and stop as soon as you encounter patient data or another user's data;
- do not degrade the service — clinicians use Carmen live during consultations;
- do not use social engineering, physical intrusion or attacks on third parties;
- keep the details confidential until coordinated disclosure, as described above;
- comply with applicable law.

Carmen is established in Belgium. Belgium has a legal framework for coordinated vulnerability disclosure, operated by the Centre for Cybersecurity Belgium (CCB). If you want the protection of that framework in addition to this policy, notify the CCB as well, following the coordinated vulnerability disclosure guidance published on [ccb.belgium.be](https://ccb.belgium.be/en).

## Personal data

We process your name, email address and the content of your report only to handle the vulnerability and, if you asked for it, to credit you. We do not share your identity with third parties without your consent, except where the law requires it. See the [privacy policy](https://askcarmen.eu/privacy) for our general practices.

---

Version 1.0, published 12 September 2026. This policy is reviewed annually.
