Report a security vulnerability
Last updated: September 2026
Found a security vulnerability in Meditag? We're grateful for any report and ask that you reach out to us responsibly before disclosing it publicly.
What's in scope
- The Meditag app for Android and iOS
- Our server at
api.meditag.ch - This website (
meditag.ch) and its subdomains
How to report
Please do not report a vulnerability through a public app review or a public forum. Instead, email us directly:
Briefly describe what you found, what impact it could have, and — if possible — how to reproduce it. A working exploit isn't required.
We don't currently offer PGP-encrypted email. If your finding involves especially sensitive details, say so in your first message and we'll agree on a safer way to exchange the details.
What to expect
- Acknowledgement within 5 business days.
- A response on whether we could reproduce the issue and how we're prioritizing it.
- A request to give us time to ship a fix before any public disclosure. We're happy to credit you as the finder once a fix is out, if you'd like.
We don't currently offer a bug bounty program.
Why this matters especially at Meditag
Meditag stores medication and health-adjacent data. The app is built so our server never sees plaintext patient data (see our privacy policy) — but a vulnerability in the app itself, in sync, or in caregiver pairing could still expose a patient's own device-local data. That's exactly the kind of report we most want to hear about early.
Data controller: Robomoe Genossenschaft, Sägagass 23, 9490 Vaduz, Liechtenstein