Report a security vulnerability

Last updated: September 2026

Found a security vulnerability in Meditag? We're grateful for any report and ask that you reach out to us responsibly before disclosing it publicly.

What's in scope

How to report

Please do not report a vulnerability through a public app review or a public forum. Instead, email us directly:

privacy@meditag.ch

Briefly describe what you found, what impact it could have, and — if possible — how to reproduce it. A working exploit isn't required.

We don't currently offer PGP-encrypted email. If your finding involves especially sensitive details, say so in your first message and we'll agree on a safer way to exchange the details.

What to expect

We don't currently offer a bug bounty program.

Why this matters especially at Meditag

Meditag stores medication and health-adjacent data. The app is built so our server never sees plaintext patient data (see our privacy policy) — but a vulnerability in the app itself, in sync, or in caregiver pairing could still expose a patient's own device-local data. That's exactly the kind of report we most want to hear about early.

Data controller: Robomoe Genossenschaft, Sägagass 23, 9490 Vaduz, Liechtenstein