Report a vulnerability
Email security-sensitive reports to security@anduine.com. Include the affected URL or component, reproduction steps, impact and any proof of concept that does not expose another person’s health information.
Anduine uses layered access control, encryption, privacy redaction, automated security scanning and data-minimisation safeguards. Security is a continuing process, so we also welcome responsible reports.
Email security-sensitive reports to security@anduine.com. Include the affected URL or component, reproduction steps, impact and any proof of concept that does not expose another person’s health information.
Use only accounts and data you control, avoid privacy violations or service disruption, do not persist access after demonstrating the issue, and give us a reasonable opportunity to remediate before public disclosure.
Production changes are built and tested in CI, dependencies are audited, and the JavaScript/TypeScript tree is scanned with CodeQL. Health and smoke checks verify critical production configuration after release.
Do not put patient data, secrets, access tokens, passwords or private keys into a public issue. If a report contains sensitive material, use the security email above.
Anduine is a patient-side memory and organisation service, not an emergency service, diagnostic system or prescribing tool.