DEMONSTRATION ENVIRONMENT — ALL PATIENT AND OPERATIONAL DATA IS SYNTHETIC

Security & Vulnerability Disclosure

Responsible disclosure — no PHI in reports

AOR Medical Solutions takes the security of AOR ONE™ CARE AUTHORITY seriously. If you believe you have found a security vulnerability, please report it responsibly.

How to report

Send an email to security@aormedicalsolutions.com . Include a clear description of the issue, steps to reproduce, and any evidence. Do not include patient information, screenshots with PHI, or live credentials in your report.

What we promise

  • We will acknowledge receipt within 72 business hours.
  • We will investigate promptly and share a timeline for remediation when available.
  • We will not take legal action against researchers who follow this disclosure policy.
  • We will credit researchers publicly if they wish and the issue is confirmed.

Out of scope

  • Social engineering or phishing against AOR Medical Solutions staff.
  • Denial-of-service attacks against production environments.
  • Accessing or attempting to access patient data.
  • Physical security testing.

Trust Center

For platform-level security evidence and machine-readable posture, review the Lovable Trust Center . It is maintained by the hosting platform and covers infrastructure security evidence.

This page does not create a contractual obligation or guarantee. Legal counsel should review the final disclosure policy before publication.

AOR ONE™, CARE AUTHORITY™, AOR HealIQ™ and associated systems are proprietary platforms and intellectual property of AOR Medical Solutions.