Skip to main content
MedXlineClinical systems
held accountable

MedXline · Security

Coordinated vulnerability disclosure

MedXline accepts security reports from anyone — researchers, partners, customers, and automated security tooling operated by an accountable person. This page is the canonical policy. It is also published as a machine-readable manifest at /.well-known/security.txt per IETF RFC 9116, and surfaced inside the A2A agent card under policies.disclosurePolicy.

How to report

Send a concise description of the issue, minimum reproduction steps, and observed impact through the contact route below. Do not include personal or clinical data.

Disclosure contact
Contact form
RFC 9116 manifest
/.well-known/security.txt
A2A agent policies
/.well-known/agent.json
Acknowledgments
/security/hall-of-fame

In scope

  • medxline.com and www.medxline.com
    Low-volume, non-destructive testing of unauthenticated public pages and the published contact flow.
  • Published /.well-known documents
    Read-only validation of the security and public planning manifests.

Out of scope

  • Third-party services and infrastructure not controlled by MedXLine.
  • Authenticated, tenant, clinical, payment, or administrative data and workflows unless MedXLine gives written authorization for the exact test.
  • Denial-of-service, destructive, or high-volume tests.
  • Social engineering of staff or partners.
  • Findings that require physical access to user devices.
  • Reports based purely on outdated browsers / OS versions without an exploitable path.

Safe harbor

  • We intend to coordinate in good faith with researchers who stay within this policy; this statement is not legal advice or a waiver of third-party rights.
  • Use only accounts and data you own or are explicitly authorized to test.
  • If a finding requires accessing data that is not your own, stop, document the impact, and report immediately — do not exfiltrate or persist data beyond what is necessary to demonstrate the issue.