generated: '2026-09-05' method: searched probe: true source: https://www.4gclinical.com/vulnerability-disclosure policy: - https://www.4gclinical.com/vulnerability-disclosure contact: - vdp-4gclinical@submit.bugcrowd.com program: name: 4G Clinical Vulnerability Disclosure Policy last_updated: '2025-06' intake_partner: Bugcrowd intake_kind: partner email intake address (VDP, no published bounty) bounty: false alternate_intake: web form on the disclosure page acknowledgement: >- "The 4G Clinical Security Team will acknowledge receipt of each vulnerability report, conduct a thorough investigation, and then take appropriate action for resolution." scope: in_scope: - all 4G Clinical web applications and services - public-facing systems and APIs - mobile applications developed by 4G Clinical - any system that processes, stores, or transmits confidential and clinical trial data out_of_scope: - third-party services, applications and technology used but not owned by 4G Clinical - physical security testing - social engineering against 4G Clinical staff, users or clients - disclosure of known public files (e.g. robots.txt) with no material risk - denial of service (DoS) attacks - testing that accesses or modifies data belonging to other users - attacks that hinge on a user's computer first being compromised safe_harbor: stated: partial note: >- The policy sets participation conditions (comply with applicable law; no employment or agency relationship is created) but does not publish an explicit authorization or non-prosecution safe-harbor clause. security_txt: null notes: - /.well-known/security.txt was probed on 4gclinical.com, www.4gclinical.com, api.4gclinical.com, portal.4gclinical.com and support.4gclinical.com — see well-known/4gclinical-well-known.yml. None served one. - The in-scope list is the provider's own written confirmation that it operates public-facing APIs, even though it publishes no API documentation. evidence: - source: https://www.4gclinical.com/vulnerability-disclosure kind: disclosure page http_status: 200 fetched: '2026-09-05' keywords: - vulnerability disclosure policy - security researchers - bugcrowd