Yürürlük: 2026-09-20 · Sürüm: v1.1
Security Notice
Güvenlik uygulamaları, sorumlu bildirim ve taahhütlerin sınırları.
İşletmeci: Celiums Solutions, LLC
Security program
Celiums Solutions, LLC maintains technical and organizational practices proportionate to OncoRadar's current service stage. Security is shared: users must protect devices, credentials and exported data.
- TLS in transit and managed encryption capabilities at rest
- Tenant-scoped authorization and least-privilege application access
- Hashed session tokens and API secrets, revocation, quotas and audit trails
- Origin checks for browser mutations and secure, HttpOnly session cookies
- Dependency, incident and vulnerability management appropriate to the service stage
- RDS and Hyphae backup processes with restoration procedures
Authentication and isolation
Cognito supports account authentication. OncoRadar stores session and API credential verification values as one-way hashes in the control plane, supports revocation, scopes data operations to authorized projects, and records selected access and quota events. Browser mutations use origin checks and secure cookies.
Data and backups
Managed AWS capabilities protect data in transit and at rest where configured. RDS and Hyphae backups support recovery. Backup rotation means a deletion request does not erase every backup immediately; restored data remains subject to the deletion workflow.
Report a vulnerability
Send a concise description, affected URL or component, reproduction steps and impact to security@oncoradar.org. Do not access other users' data, disrupt service, use social engineering or publish sensitive details before remediation coordination. This draft identifies a reporting channel but does not promise a bounty, response time or remediation outcome.
No certification claim
This notice does not claim SOC 2, ISO 27001, HIPAA, PCI DSS or any other certification or regulated-service status. No system is perfectly secure. Customers should assess OncoRadar for their own risk and compliance needs and must not submit PHI or patient data.
Incidents
Incident response procedures, legally required notices, notification periods, contacts and contractual security schedules require operational verification and legal review. This draft does not represent that a particular regulatory incident-response standard or deadline has been implemented.