Security
Report a flaw. Understand the current boundary.
Updated
Report a vulnerability
Send a concise report to security@automedha.ai. Include the affected URL or interface, reproduction steps, impact, and a way to contact you. Remove secrets and personal data that the report does not need.
We will review the report and coordinate disclosure when the issue is valid. Automedha does not currently operate a paid bug bounty or publish a Pretty Good Privacy key. Ask for a protected exchange before sending sensitive evidence.
Research boundaries
Do not access another person’s data, degrade availability, send bulk traffic, use social engineering, or test third-party systems outside Automedha. Stop once you have enough evidence to explain the issue. These limits do not authorize conduct that applicable law prohibits.
Website and form controls
The marketing site renders statically except for bounded runtime interfaces. The generated HTML carries a Content Security Policy, while the hosting provider’s header configuration defines transport security, framing restrictions, content-type protections, referrer controls, cross-origin window isolation, and the device permissions the page may ask for, including the microphone.
The production configuration requires server-validated bot-verification tokens and dedicated rate-limit bindings for forms and artificial intelligence interfaces. Deployment acceptance verifies those resources before launch.
Access requests persist before best-effort email delivery. An idempotency key and request fingerprint prevent a retry from creating a conflicting record. Subscriber confirmation and unsubscribe tokens are stored as Secure Hash Algorithm 256-bit hashes, and confirmation links expire after seven days.
Artificial intelligence and voice controls
Retrieval answers are designed to ground on the public Automedha corpus and return source records. The gateway the answer and voice routes call is configured to require authentication and to hold a daily spending ceiling. Location-based rate limits are the configured burst control.
Voice uploads have bounded size and container checks before transcription. Speech generation requires a separate actor-bound grant that expires after 180 seconds. The voice grant uses a dedicated secret rather than the bot-verification secret.
Product isolation boundary
Automedha currently runs reviewed, platform-authored workflow templates. It does not claim safe arbitrary customer-code deployment because customer-authored artifact isolation remains open. The private-beta review keeps each use case inside the behavior the running system can support.
Operational dependencies
The production service boundary is designed around a managed serverless runtime, a database, a vector index, hosted AI models, an AI gateway, bot verification, email delivery, and rate limiting. A separate payment mandate defines spending authority for paid capability dispatch. Security questions that are not vulnerability reports can go to hello@automedha.ai.