TrialThread

Clinical trials, findable.

Reporting a security problem

Reports are welcome and taken seriously. TrialThread is one person’s project, so replies are not instant — but they are real, and credit is offered gladly.

The preferred channel

Open a private security advisory on GitHub →

This is private, threaded, authenticated, and it does not become public until and unless it is fixed and published. Please do not open a normal GitHub issue for a security finding — issues are public and permanent.

No GitHub account?

There is an email address, and it is deliberately not written anywhere a scraper can read it — the moment it appears in plain text in a well-known file, it belongs to spammers rather than to researchers. Click to reveal it:

What is actually worth attacking here

TrialThread is stateless. There is no patient database, no accounts, and no stored health data — so “exfiltrate the data at rest” is not the interesting attack, because there is no data at rest. What is interesting:

  1. The integrity of what a patient is told about a trial. An attacker who can change what a frightened person reads about their eligibility does real harm. This is the one that could hurt someone. Please weight it accordingly.
  2. Prompt injection — through pasted text, or through content coming back from the registry itself.
  3. Denial-of-wallet. The inference budget is small and hard-capped. Auto- reload is deliberately off, so exhausting it degrades to an outage rather than a surprise bill — but an outage still means a patient cannot search.
  4. The API key.

Never include real patient information in a report, through any channel. There is no bug bounty — this is a free, unfunded, public-interest project.

Machine-readable version: /.well-known/security.txt