Legal
Report a vulnerability
If you believe you have found a security vulnerability in the Neogenic website or app, please tell us so we can fix it. Last updated 30 September 2026.
How to report
-
01
Where to report
Email security@neogenic.ai. Our machine-readable contact details are published at /.well-known/security.txt.
-
02
What to include
Describe the vulnerability, the affected page, feature or address, the steps to reproduce it and the impact you expect. Screenshots or a short proof of concept help. Do not include patient information, other people’s personal data, passwords or private access links.
-
03
Rules for testing
Only test against your own account or a clinic account you are authorised to use. Stop as soon as you have shown the problem, and do not view, change, download or delete other people’s data. Do not run denial-of-service or high-volume automated tests, social engineering, phishing or physical attacks, and do not attack the services of our providers.
-
04
Good-faith research
If you follow these rules, report the vulnerability to us promptly and keep it confidential until we have fixed it, Scality Limited will not pursue legal action against you for your research. This does not authorise access to any data beyond what is needed to show the vulnerability.
-
05
What happens next
We acknowledge your report, investigate it, keep you informed of our progress and tell you when it is fixed. We do not currently run a paid bug bounty programme.
-
06
Concerns about Neo, the AI assistant
To report a concern about how Neo behaved, for example an answer that was wrong, unsafe or unexpected, email privacy@neogenic.ai with the date, your clinic and a description. Please leave patient information out of your message.
Related information
Security contact
Email security@neogenic.ai. Please do not include patient records, passwords or private access links.