Security and Vulnerability Disclosure

Last updated: 28 July 2026

GlowBook is run by a small team and we take the security of practitioner and client data seriously. If you believe you have found a vulnerability in our platform, we want to hear about it. This page sets out what you may test, how to report what you find, and what we do in return.

1. What is in scope

The following belong to GlowBook and are covered by this policy:

  • glowbook.biz and its subdomains, including the marketing site and the practitioner dashboard
  • Public booking pages and the embeddable booking widget
  • The GlowBook API under glowbook.biz/api
  • Our email infrastructure, insofar as it concerns spoofing or delivery of GlowBook messages

The following are out of scope. Please do not test them:

  • Third-party services we rely on, including Stripe, Cloudflare, Google and Meta. Report those to the provider directly.
  • Websites, social accounts and booking pages belonging to individual practitioners, even when linked from GlowBook
  • Any account, appointment or client record that is not yours. Register your own account and use your own test data.
  • Physical premises, staff and practitioners. Social engineering and phishing are not permitted.

2. Rules of engagement

Stay inside these limits and you stay inside this policy:

  • Test only against accounts you registered yourself. Two free accounts are enough to test whether one tenant can reach another tenant's data.
  • Stop as soon as you have confirmed a vulnerability exists. Do not pivot deeper, escalate further, or pull more records than you need to demonstrate it.
  • Never access, download, modify or delete data belonging to a real practitioner or their clients. That includes appointments, intake forms and contact details, which often contain health-related information.
  • If you come across real personal data by accident, stop immediately, do not save or share it, and say so in your report.
  • No denial of service, no load testing, and no high-volume automated scanning. Respect our rate limits rather than trying to evade them.
  • Do not publish anything about the vulnerability until we have agreed a timeline with you.

3. How to report

Email [email protected]. A useful report contains:

  • A clear description of the vulnerability and what an attacker could do with it
  • The exact steps to reproduce it, including URLs, requests, and any accounts you created
  • Evidence such as a short screen recording, a request and response pair, or a minimal proof of concept
  • The IP addresses and user agents you tested from, so we can tell your traffic apart from a real attack in our logs
  • How you would like to be credited, if at all

4. What you can expect from us

GlowBook is a small independent company, so these are commitments we can actually keep:

  • We acknowledge your report within five working days
  • We give you our assessment and a rough remediation timeline within ten working days
  • We keep you updated while we fix it, and tell you when the fix is live
  • We will not take legal action against you, or ask anyone else to, as long as you followed this policy

5. Findings we generally do not act on

These usually come out of automated scanners and, on their own, do not describe a real risk. We will still read them, but please include a working proof of concept if you think we are wrong:

  • Missing security headers with no demonstrated impact
  • Opinions on SPF, DKIM or DMARC configuration without a working spoofing proof
  • Self-XSS, or issues that need the victim to paste code into their own browser console
  • Clickjacking on pages with no state-changing action
  • Rate limiting reported as a problem in itself, with no demonstrated consequence
  • Outdated library versions with no exploitable path in our deployment
  • Reports consisting only of raw scanner output

6. Legal position

Belgium has had a national coordinated vulnerability disclosure framework since 15 February 2023, which protects researchers who report in good faith even without a prior agreement. The conditions are strict: act without fraudulent intent, do no more than is necessary and proportionate to confirm the vulnerability, report in writing to the organisation and to the Centre for Cybersecurity Belgium as soon as possible, and publish nothing without the CCB's agreement.

This policy is written to sit alongside that framework. If you follow it, we treat your research as authorised and we will not pursue you. You may also report to the CCB at ccb.belgium.be. Nothing here limits your rights under Belgian or EU law, and nothing here authorises you to break it.

7. Recognition

We do not run a paid bug bounty programme and we cannot offer money. What we can offer is a fast response from a human, public credit on this page if you want it, and a straight answer about what we fixed and when.

Questions about this policy? Write to [email protected].