Clinical platform security and responsible disclosure
How to report a potential PatientTwin Bio security, privacy or patient-safety issue.
Report responsibly
Use the public inquiry form, select Clinical research partnership and begin the objective with “Security disclosure”. Do not include patient or participant data, credentials, access tokens, private keys or sensitive clinical information in the initial submission.
Good-faith research
- Do not disrupt monitoring, care or research operations.
- Do not access, alter, export or retain patient or participant records without authorisation.
- Do not perform social engineering, upload malware or attempt persistence.
- Provide sufficient reproducible detail for safe assessment without including sensitive records.
Patient-safety concerns
Do not use the public security channel for urgent clinical or emergency-care matters. Follow the responsible care organisation’s established clinical and emergency procedures.
Platform controls
PatientTwin Bio uses authenticated access, role-aware policies, organisation isolation, controlled transitions, audit events and evidence-integrity controls. Security responsibilities remain shared with authorised care, research and infrastructure organisations.