Security & Vulnerability Reporting
Please report a suspected vulnerability privately to security@lifeorg.app. Do not include unnecessary personal data, exploit other users, disrupt the service or publicly disclose an unremediated issue.
Controls required before public launch
- TLS for production network traffic and no production cleartext fallback.
- Least-privilege access, private-by-default storage for user files and authenticated access to sensitive uploads. Public registration must remain closed until this control is verified.
- Verified email, secure authentication configuration, protected secrets and separation of production from development.
- Dependency and vulnerability review, audit logging, encrypted backups, restoration tests and an incident-response process.
- Risk assessments for health data, AI providers and international transfers, with documented retention and deletion controls.
Coordinated disclosure
Include a clear description, affected URL or component, reproduction steps and impact. We aim to acknowledge a valid report within 3 business days and provide status updates. This is a reporting channel, not a promise of a bounty.
Claims such as end-to-end encryption or formal certification will appear here only after the corresponding implementation and independent verification exist.