Security

Vulnerability disclosure

Effective July 9, 2026

We want to hear from you. Carabel builds software for people recovering at home after acute care, so security is not an afterthought for us. If you believe you have found a security vulnerability in any Carabel service, we would genuinely like to know about it, and we will treat your report with respect and urgency.

How to report

Email security@carabel.ai with a description of the issue, the steps to reproduce it, and any relevant URLs or request details. Plain email is fine. We will acknowledge your report within 3 business days and keep you informed as we investigate and fix the issue.

What we ask

  • Give us a reasonable opportunity to fix the issue before sharing it publicly.
  • Make a good‑faith effort to avoid accessing, modifying, or destroying data that is not yours. If you encounter personal or health information, stop, do not save or share it, and tell us immediately.
  • Do not degrade our services. No denial‑of‑service testing, spam, or social engineering of our staff or users.
  • Only test against accounts and data you own or are authorized to use.

What you can expect from us

If you follow the guidelines above and act in good faith, we will not pursue or support legal action against you for your research, and we will not refer your report to law enforcement. We consider good‑faith security research authorized activity under applicable anti‑hacking laws, including the Computer Fraud and Abuse Act. We do not currently offer a bug bounty, but we are happy to credit you for your finding if you would like.

Scope

This policy covers services operated by Carabel Inc., including carabel.ai and its subdomains. If you are unsure whether something is in scope, ask us first at security@carabel.ai.