# Sard — responsible disclosure # # RFC 9116. A researcher who finds a hole in clinical software had no address # that says "security": the only published ones were contact@, support@, # privacy@ and legal@, and none of them says what will happen to a report. # # Deliberately a file and not a page. A disclosure policy nobody can find is # worse than a line in a text file everybody's tooling already reads. Contact: mailto:security@sardscribe.com Expires: 2027-09-15T00:00:00.000Z Preferred-Languages: ar, en Canonical: https://sardscribe.com/.well-known/security.txt Policy: https://sardscribe.com/en/privacy # What we will do: acknowledge within three working days, tell you what we # found, and tell you when it is fixed. Sard is in pilot on synthetic or # consented test data — if you believe you have reached real patient data, # say so in the first line and stop. # # What we ask: no automated scanning that degrades the service, no access to # any account that is not yours, and no disclosure until we have answered.