Security policy and coordinated disclosure
This is the policy referenced in our /.well-known/security.txt file. If you've found a security issue in the site itself, please read this first and then reach out through the contact channel below.
What this site is (and isn't)
AnxietyResearch.org publishes research summaries, statistics, and editorial content. There's no patient portal, no login, no clinical scheduling, and no personal health information stored on this site. If you're looking to report a clinical or medical-record concern, that belongs to the treating practice, not to us.
Reporting a security issue
Preferred contact: [email protected]. If that address doesn't reach us for any reason, [email protected] is the backup.
Include the affected URL, a short description of the issue, reproduction steps, and any proof-of-concept material. We ask that testing stay non-destructive, stay within the URLs on this domain, and don't touch third-party services we integrate with.
Response window
We aim to acknowledge a report within five business days, confirm the finding or ask for more information within fifteen business days, and ship a fix or share a mitigation timeline within thirty days for anything material. We're a small editorial team, so complex reports may take longer. If the issue is being actively exploited, tell us in the first message and we'll drop everything else.
Coordinated disclosure
We prefer coordinated disclosure. Please give us a reasonable window to fix the issue before publishing details. In return, if you'd like to be credited, we'll add you to the acknowledgments below with the wording of your choice.
Safe harbor
We won't pursue legal action against good-faith security research that stays within this policy: no destructive testing, no exfiltration of data beyond what's needed to demonstrate the issue, no social-engineering of our staff or contributors, and no testing on infrastructure we don't own.
Acknowledgments
Nothing to acknowledge yet. If you're the first, this section will name you.