Skip to content

Report a security problem

Found a weakness in Kliniqo? We want to hear about it. This page says what you may test, how to tell us, and what we promise in return. In force from 02/10/2026.

How to tell us

  • Write to rupaparapriyam@gmail.com in English, Hindi or Gujarati.
  • Say what you found, where, and the steps to see it again. Screenshots or a short video help.
  • Leave any real person's health information out of your report.

What we promise

  • We reply within 3 working days to say we have your report.
  • We keep you told while we fix it, and tell you when it is fixed.
  • We will not take legal action against research done in good faith within these rules, and we will not ask anyone else to.
  • With your permission, we thank you by name once the fix is out.
  • We do not pay rewards at present.

What you may test

  • The Kliniqo app for iPhone and Android.
  • This website, kliniqo.co.in, and the app's API under kliniqo.co.in/api/app/v1.
  • Only with accounts you made yourself, or a test account we give you when you ask.

What you must not do

  • Do not open, change or keep any real patient's information. If you reach some by accident, stop, tell us, and delete what you saw.
  • Do not test a laboratory's own website or domain. Tell us instead, and we will pass it on.
  • No denial of service, no spam, no tricking our staff or a laboratory's staff, and no physical attacks.
  • Do not make the problem public until it is fixed or 90 days have passed, unless we agree otherwise.

For automated tools

The same contact is published at /.well-known/security.txt, as the web's standard asks.