# Onkydra security contact, per RFC 9116. # # There was no disclosure route at all before 2026-07-31. The DPA carried a # vulnerability-management clause describing how advisories are handled, and no # address for a researcher who had found something to send it to. A commitment # to fix things with no way to be told is not a disclosure process. # # hello@onkydra.com is a real, monitored mailbox and is the address the DPA # already uses. It is not a dedicated security alias, and pretending otherwise # by publishing a security@ address that does not exist would be worse than # publishing the one that works. Contact: mailto:hello@onkydra.com Expires: 2027-07-31T00:00:00.000Z Preferred-Languages: en Canonical: https://onkydra.com/.well-known/security.txt Policy: https://onkydra.com/terms # Scope: onkydra.com and app.onkydra.com. # # Onkydra is a research-use-only hypothesis generator. It holds no patient data # and no direct identifiers: cohorts are simulated from published summary # statistics, not derived from records. The data that does exist is account # email addresses, run traces, and marketing signups. # # We will acknowledge a report within five working days. There is no bug bounty. # Please do not run automated scanning against app.onkydra.com; it is a single # small instance and load testing is indistinguishable from an outage.