21 CFR Part 11 · EU GMP Annex 11 · GAMP 5 · ALCOA+
Re-authenticated signatures · Tamper-evident audit trail · Security practices (not certified)
Security

Coordinated vulnerability disclosure

If you believe you've found a security issue in GxP-Desk, please tell us privately before disclosing it publicly. We investigate every report.

01

How to report

Email contact@seydel.consulting with a description of the issue, the steps to reproduce it, and any proof-of-concept material. Encrypting your report is not required, but if you prefer PGP, ask for a key in your first message and we will provide one.

Please include enough detail for us to reproduce the issue (affected URL or endpoint, request/response samples, and the impact you observed). Reports without reproduction steps take longer to triage.

02

Scope

In scope: the GxP-Desk application at gxpdesk.app and its subdomains, and the APIs those hosts serve.

Out of scope: denial-of-service testing, automated scanning that generates significant load, social engineering or phishing of GxP-Desk staff or customers, physical access attempts, and any testing against accounts or data you do not own or have explicit permission to test. Do not access, modify, or exfiltrate data belonging to other tenants — stop and report as soon as you can demonstrate impact.

03

Safe harbor

We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: report privately, avoid privacy violations and service disruption, and give us a reasonable opportunity to investigate and remediate before any public disclosure. This is not a bug bounty program — we do not offer monetary rewards, and we do not currently run a formal, continuous third-party penetration test program. We do take reports seriously and act on them.

04

What to expect

We aim to acknowledge new reports within 3 business days and to give you a status update — triage outcome, severity, and expected next steps — within 10 business days. Timelines for a fix depend on severity and complexity; we will keep you informed as we work on it. We ask that you give us a reasonable window to remediate before any public disclosure, and we are happy to coordinate a disclosure timeline with you directly.