Security Vulnerability Disclosure Policy
Last updated: 25 September 2026
Aromha is committed to the security and privacy of the people who use the Aromha Brain Health Test. If you believe you have found a security vulnerability in any Aromha system or website, we want to hear from you and will work with you to resolve it.
How to report
Email support@aromha.com with “Security” in the subject line. Please include:
- a description of the issue;
- the steps to reproduce it;
- the affected URL or system;
- any proof of concept.
Please report promptly, and give us a reasonable time to respond and fix the issue before any public disclosure.
Our commitment
We will acknowledge your report within 5 business days, keep you informed as we investigate, and let you know when the issue is resolved.
We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and do not access or modify data beyond what is necessary to demonstrate the issue.
What is in scope
- aromha.com
- testyourbrainhealth.com, the web application for the Aromha Brain Health Test
- Aromha-operated APIs
What is out of scope
- Third-party services Aromha uses, for example the Square payment service
- Denial-of-service testing
- Physical attacks
- Social engineering of Aromha staff
Please do not
- access, store, or share any personal or health information you encounter; if you do encounter any, stop, tell us in your report, and delete it once your report is submitted;
- disrupt the service or degrade it for other users;
- access or modify data beyond what is necessary to demonstrate the issue.
Contact
support@aromha.com Aromha, Inc., 10008 Hemswell Lane, Potomac, MD 20854
A machine-readable version of this contact information is published at /.well-known/security.txt.