Report a vulnerability
Help us address security issues responsibly.
How to report
Send a private report to contato@clinicalcorvus.com with the subject Clinical Corvus security report. Include a description, reproduction steps, potential impact, and affected environment.
Do not send PHI, credentials, keys, tokens, databases, or screenshots containing identifiable data. If an example requires clinical data, describe the scenario synthetically.
Responsible research
Avoid service degradation, access to third-party data, social engineering, and any test that changes or exposes information. We prefer clear, reproducible reports to invasive demonstrations.
Initial scope
Reports may cover the public site, the official hellf17/clinical-corvus repository, and integrations made available directly by the team. Eligibility and scope for every clinical deployment are confirmed separately.
Receiving a report does not create a reward program or authorization to test systems outside that scope.