4G Clinical · Vulnerability Disclosure

4Gclinical Vulnerability Disclosure

Vulnerability disclosure

4G Clinical runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

Clinical TrialsLife SciencesRandomizationTrial Supply ManagementRTSMClinical Supply ChainPharmaceuticalsHealthcareForecastingCompany
Program: Bugcrowd

Disclosure Policy

Policy

Security Contact

Contact
vdp-4gclinical@submit.bugcrowd.com

Source

Vulnerability Disclosure

4gclinical-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
probe: true
source: https://www.4gclinical.com/vulnerability-disclosure
policy:
- https://www.4gclinical.com/vulnerability-disclosure
contact:
- vdp-4gclinical@submit.bugcrowd.com
program:
  name: 4G Clinical Vulnerability Disclosure Policy
  last_updated: '2025-06'
  intake_partner: Bugcrowd
  intake_kind: partner email intake address (VDP, no published bounty)
  bounty: false
  alternate_intake: web form on the disclosure page
  acknowledgement: >-
    "The 4G Clinical Security Team will acknowledge receipt of each vulnerability report,
    conduct a thorough investigation, and then take appropriate action for resolution."
scope:
  in_scope:
  - all 4G Clinical web applications and services
  - public-facing systems and APIs
  - mobile applications developed by 4G Clinical
  - any system that processes, stores, or transmits confidential and clinical trial data
  out_of_scope:
  - third-party services, applications and technology used but not owned by 4G Clinical
  - physical security testing
  - social engineering against 4G Clinical staff, users or clients
  - disclosure of known public files (e.g. robots.txt) with no material risk
  - denial of service (DoS) attacks
  - testing that accesses or modifies data belonging to other users
  - attacks that hinge on a user's computer first being compromised
safe_harbor:
  stated: partial
  note: >-
    The policy sets participation conditions (comply with applicable law; no employment or
    agency relationship is created) but does not publish an explicit authorization or
    non-prosecution safe-harbor clause.
security_txt: null
notes:
- /.well-known/security.txt was probed on 4gclinical.com, www.4gclinical.com,
  api.4gclinical.com, portal.4gclinical.com and support.4gclinical.com — see
  well-known/4gclinical-well-known.yml. None served one.
- The in-scope list is the provider's own written confirmation that it operates public-facing
  APIs, even though it publishes no API documentation.
evidence:
- source: https://www.4gclinical.com/vulnerability-disclosure
  kind: disclosure page
  http_status: 200
  fetched: '2026-09-05'
  keywords:
  - vulnerability disclosure policy
  - security researchers
  - bugcrowd

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/4gclinical-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.