What to report
Report a reproducible security weakness affecting cra.clarityclinicalsolutions.com. Include the affected URL, application version, expected behavior, observed behavior and potential impact.
Use synthetic test data and the minimum steps needed to explain the issue. Screenshots should be redacted before they are shared.
Never include sensitive records
Do not submit PHI, participant identifiers, credentials, API keys, sponsor-confidential material or real visit-report content. If you encounter such data unexpectedly, stop testing and report only that exposure occurred.
Testing boundaries
This policy does not authorize disruptive testing, social engineering, denial of service, persistence, data extraction or access to another person's account or systems.
Scope
This guidance covers the public CRA AI Assistant website. Report vulnerabilities in Render, Cloudflare, YouTube or other third-party services directly to those providers.