CaseLink Trust Center
Security Policy
CaseLink protects public research workflows, accounts, submissions, documents, APIs, and restricted review tools with role checks and operational controls.
Effective: July 25, 2026
1. Account security
Users are responsible for keeping login credentials secure and should report suspected account compromise, unauthorized access, or suspicious activity.
2. Restricted access
Admin tools, investigator workflows, tickets, review queues, imports, audit logs, restricted documents, private submissions, and user data are limited to authorized roles.
3. Prohibited activity
Do not test, scan, exploit, bypass, scrape, attack, or overload CaseLink systems without written authorization. Do not attempt to access another user account or restricted data.
4. Responsible disclosure
Security reports should include the affected URL, steps to reproduce, impact, and contact information. Do not publicly disclose vulnerabilities before CaseLink has a reasonable chance to review and address them.
5. Logs and controls
CaseLink may retain security logs, IP-derived data, user-agent data, audit records, and administrative actions to investigate abuse and protect the platform.