Security
Last reviewed: August 27, 2026
Healthwired Games welcomes responsible reports that help protect developers, players, and health-data integrations. This page explains how to report a potential vulnerability without exposing sensitive details publicly.
Report a security issue
Section titled “Report a security issue”Use the official Healthwired Games contact page and put Security vulnerability in the subject. Provide a short, non-sensitive summary and ask for a private follow-up channel before sending exploit code, credentials, private repository details, or unpublished technical evidence.
Do not report vulnerabilities through Discord, a public documentation issue, a store review, or social media.
What to include
Section titled “What to include”- Affected product, package/plugin version, URL, or documentation page.
- Platform, operating system, and engine version when relevant.
- Clear reproduction steps and the observed security impact.
- Whether the issue is already public or appears to be actively exploited.
- Minimal screenshots or logs with credentials, tokens, health data, record IDs, routes, and personal information removed.
- A safe way for the team to contact you.
Responsible testing boundaries
Section titled “Responsible testing boundaries”Only test systems and data you own or are explicitly authorized to test. Do not:
- access another person’s account, device, health data, or private project;
- degrade availability, perform denial-of-service testing, or generate excessive automated traffic;
- use social engineering, phishing, malware, or credential attacks;
- alter or delete records that are not your own test data;
- retain, share, or publish sensitive information discovered during testing.
Stop testing if you encounter personal, health, authentication, or confidential data and report the exposure through the private process above.
Documentation portal safeguards
Section titled “Documentation portal safeguards”This portal is generated as a static Astro site and delivered through Cloudflare Pages over HTTPS. The repository pins dependencies with a lockfile and requires formatting, lint, content diagnostics, a production build, and internal-link validation before documentation changes are accepted.
These measures reduce risk but are not a claim that the site or SDK is free of vulnerabilities. Healthwired does not claim a security certification or a guaranteed response time on this page.
Guidance for HealthBridge integrators
Section titled “Guidance for HealthBridge integrators”Applications using HealthBridge remain responsible for their own threat model, platform configuration, consent flow, storage, telemetry, access control, and release review. Request only the health-data access required by a visible feature, keep raw health records and identifiers out of general diagnostics, and use current SDK releases from approved distribution channels.
See the documentation privacy notice for this portal’s data handling and Support and community for non-security questions.
