Report a security problem
Found a weakness in Kliniqo? We want to hear about it. This page says what you may test, how to tell us, and what we promise in return. In force from 02/10/2026.
How to tell us
- Write to rupaparapriyam@gmail.com in English, Hindi or Gujarati.
- Say what you found, where, and the steps to see it again. Screenshots or a short video help.
- Leave any real person's health information out of your report.
What we promise
- We reply within 3 working days to say we have your report.
- We keep you told while we fix it, and tell you when it is fixed.
- We will not take legal action against research done in good faith within these rules, and we will not ask anyone else to.
- With your permission, we thank you by name once the fix is out.
- We do not pay rewards at present.
What you may test
- The Kliniqo app for iPhone and Android.
- This website, kliniqo.co.in, and the app's API under kliniqo.co.in/api/app/v1.
- Only with accounts you made yourself, or a test account we give you when you ask.
What you must not do
- Do not open, change or keep any real patient's information. If you reach some by accident, stop, tell us, and delete what you saw.
- Do not test a laboratory's own website or domain. Tell us instead, and we will pass it on.
- No denial of service, no spam, no tricking our staff or a laboratory's staff, and no physical attacks.
- Do not make the problem public until it is fixed or 90 days have passed, unless we agree otherwise.
For automated tools
The same contact is published at /.well-known/security.txt, as the web's standard asks.