MedXline · Security
Coordinated vulnerability disclosure
MedXline accepts security reports from anyone — researchers, partners, customers, and automated security tooling operated by an accountable person. This page is the canonical policy. It is also published as a machine-readable manifest at /.well-known/security.txt per IETF RFC 9116, and surfaced inside the A2A agent card under policies.disclosurePolicy.
How to report
Send a concise description of the issue, minimum reproduction steps, and observed impact through the contact route below. Do not include personal or clinical data.
- Disclosure contact
- Contact form
- RFC 9116 manifest
- /.well-known/security.txt
- A2A agent policies
- /.well-known/agent.json
- Acknowledgments
- /security/hall-of-fame
In scope
- medxline.com and www.medxline.comLow-volume, non-destructive testing of unauthenticated public pages and the published contact flow.
- Published /.well-known documentsRead-only validation of the security and public planning manifests.
Out of scope
- Third-party services and infrastructure not controlled by MedXLine.
- Authenticated, tenant, clinical, payment, or administrative data and workflows unless MedXLine gives written authorization for the exact test.
- Denial-of-service, destructive, or high-volume tests.
- Social engineering of staff or partners.
- Findings that require physical access to user devices.
- Reports based purely on outdated browsers / OS versions without an exploitable path.
Safe harbor
- We intend to coordinate in good faith with researchers who stay within this policy; this statement is not legal advice or a waiver of third-party rights.
- Use only accounts and data you own or are explicitly authorized to test.
- If a finding requires accessing data that is not your own, stop, document the impact, and report immediately — do not exfiltrate or persist data beyond what is necessary to demonstrate the issue.
