Reporting a
security issue.
CIVITERA welcomes responsible disclosure of vulnerabilities affecting this website or our published materials.
Reporting a vulnerability
If you believe you have found a security vulnerability in civitera.ai, please report it to security@civitera.ai. Include the affected URL, a description of the issue, and the steps required to reproduce it. Our machine-readable security contact is published at /security.txt and at the RFC 9116 canonical location /.well-known/security.txt.
What we ask
- Give us a reasonable opportunity to remediate before any public disclosure.
- Avoid privacy violations, service degradation, and destruction or modification of data.
- Do not run automated scanning that materially degrades availability for others.
- Do not attempt social engineering, physical intrusion, or access to systems beyond the scope of this website.
What we commit to
- Acknowledge your report, normally within five business days.
- Keep you informed as we investigate and remediate.
- Not pursue legal action against researchers acting in good faith within this policy.
Scope
In scope: the civitera.ai website and its published assets. Out of scope: third-party services we do not control, and any matter relating to patent prosecution, which is handled through the United States Patent and Trademark Office rather than this channel.
Site security measures
This site is served over HTTPS with HSTS, a Content Security Policy restricting script sources, and standard protections including frame-ancestor restrictions, MIME-type sniffing prevention, and a restrictive referrer policy.
