Free, source-traceable HIV knowledge

Responsible disclosure

Security Reporting

How to report a security or privacy vulnerability without exposing sensitive health or personal information.

Publisher
The Bach Foundation
Audience
Public · Professional · Research
Last reviewed
18 August 2026
Status
Published standard
Jurisdiction
Global context; local guidance may vary

Commitment at a glance

Report reproducible security concerns responsibly. Do not access, retain or transmit other people's information to demonstrate an issue.

Security guidance reviewed 18 August 2026

In scope

  • A vulnerability affecting the AIDS Research Center production site.
  • Unexpected exposure of information created by site features.
  • A compromised download or external destination presented as trusted.
  • A privacy failure involving browser-only preferences or saved resources.

Safe testing rules

  • Use only your own browser state and accounts, if any.
  • Do not use social engineering, denial of service or automated high-volume scanning.
  • Do not access, alter, download or retain information belonging to another person.
  • Stop when a possible vulnerability is confirmed and report the minimum necessary detail.

A useful report

  • Affected page or feature and date observed.
  • Clear reproduction steps with non-sensitive test data.
  • Expected and actual behavior.
  • Potential impact and any suggested mitigation.

Direct reporting

The contact control opens your own email client. The website does not run a submission script. Never include passwords, private medical information or exploit data from another person.

Contact only when necessary

The control below constructs the Foundation address only after your click and opens your own email application. No form, background script or website database receives the message. Do not include private health information.