Responsible Disclosure
Last updated: July 2026
1. Security Contact
If you discover a security vulnerability in MedCite, please report it to security@medcite.eu. We will acknowledge receipt within 5 business days and work to resolve the issue promptly.
2. What to Include
- A clear description of the vulnerability
- Steps to reproduce the issue
- Affected version or component
- Your contact information (optional for anonymous reports)
3. In-Scope Vulnerabilities
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Server-side request forgery (SSRF)
- SQL or command injection
- Authentication or authorisation bypass
- Sensitive data exposure
- Remote code execution
4. Out of Scope
- Social engineering of users or staff
- Physical attacks on infrastructure
- Denial-of-service attacks
- Issues in third-party websites or services linked from MedCite
- TLS configuration weaknesses that are not exploitable
- Missing security headers without demonstrated impact
5. Testing Rules
When investigating potential vulnerabilities, you must:
- Not access, modify or delete user data
- Not disrupt or degrade the service
- Not perform denial-of-service testing
- Not exploit a vulnerability beyond what is necessary to confirm its existence
- Report the issue privately and allow reasonable time for remediation before public disclosure
- Comply with all applicable laws
6. Safe Harbour
We consider good-faith security research conducted in accordance with this policy as authorised activity. We will not pursue legal action against researchers who follow these guidelines. This policy is not an offer of a bug bounty or financial reward.
7. Acknowledgement
We thank and acknowledge security researchers who report valid vulnerabilities in accordance with this policy, unless they request anonymity. We will respond to reports within 5 business days and keep reporters informed of remediation progress.