Security & Vulnerability Disclosure
Responsible disclosure — no PHI in reports
AOR Medical Solutions takes the security of AOR ONE™ CARE AUTHORITY seriously. If you believe you have found a security vulnerability, please report it responsibly.
How to report
Send an email to security@aormedicalsolutions.com . Include a clear description of the issue, steps to reproduce, and any evidence. Do not include patient information, screenshots with PHI, or live credentials in your report.
What we promise
- We will acknowledge receipt within 72 business hours.
- We will investigate promptly and share a timeline for remediation when available.
- We will not take legal action against researchers who follow this disclosure policy.
- We will credit researchers publicly if they wish and the issue is confirmed.
Out of scope
- Social engineering or phishing against AOR Medical Solutions staff.
- Denial-of-service attacks against production environments.
- Accessing or attempting to access patient data.
- Physical security testing.
Trust Center
For platform-level security evidence and machine-readable posture, review the Lovable Trust Center . It is maintained by the hosting platform and covers infrastructure security evidence.
This page does not create a contractual obligation or guarantee. Legal counsel should review the final disclosure policy before publication.
AOR ONE™, CARE AUTHORITY™, AOR HealIQ™ and associated systems are proprietary platforms and intellectual property of AOR Medical Solutions.
