Security Posture
The architecture is designed around tenant isolation, least privilege,
synchronous audit evidence, immutable document storage, controlled AI, encrypted
transport, encrypted storage, minimum-necessary communication, and controlled
infrastructure. We use current security guidance, including NIST CSF 2.0 and
CISA Secure by Design principles, and we design control evidence with common
customer diligence frameworks in mind.
Security and compliance diligence artifacts are shared through approved diligence
channels or signed agreements. This page is an overview, not a certification or
audit report.
HIPAA And Regulated Data
Public website and public email channels are for business, privacy, security,
vendor, and product evaluation communication. Customer PHI or regulated clinical-trial
records must be handled only through governed application routes and signed
customer terms.
Public Site Protection
- HTTPS-only public site delivery with security headers.
- Private static origin behind a controlled CDN edge.
- Deployment through short-lived cloud identity rather than long-lived access keys.
- No advertising pixels, analytics cookies, or session replay on the public site.
Report A Vulnerability
Send security reports to security@clinistack.io.
Include a clear description, affected URL or component, steps to reproduce,
observed impact, and whether any data was exposed. Do not include PHI or regulated
trial records in a public security report.
We aim to acknowledge credible reports within three business days and provide
a triage update within ten business days. Timelines can change based on severity,
reproducibility, third-party dependency involvement, and legal obligations.
Good-Faith Research Rules
For public assets you may perform non-destructive testing that stays within these rules:
- Do not access, modify, delete, exfiltrate, or retain data that is not yours.
- Stop testing and report immediately if you encounter non-public data.
- Do not perform denial-of-service, spam, phishing, social engineering, physical attacks, or destructive tests.
- Do not test customer tenants, non-public environments, employees, contractors, vendors, or personal accounts.
- Do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate it.
Safe Harbor
If your research follows this policy, is limited to public Clinistack-owned
assets, avoids harm, and is reported promptly, Clinistack will not pursue legal
action against you for that good-faith research. This does not authorize access
to third-party systems or customer data, and it does not waive rights for conduct
outside this policy.
Security Report Compensation
Paid rewards are not offered unless a written program states otherwise.
Credible reports are reviewed under this disclosure policy; submission does
not create a right to compensation, employment, attribution, or public acknowledgment.
Machine-Readable Contact
The machine-readable vulnerability contact file is available at
/.well-known/security.txt.