OpenEvidence is committed to carefully protecting and security your data and ensuring that OpenEvidence.com is always available when you need it. We use a variety of industry-standard technologies and services to safeguard your data from unauthorized access, disclosure, use, and loss, and are constantly monitoring and improving our products and services.
OpenEvidence's services are primarily hosted on Google Cloud Platform and Vercel, industry leaders providing highly scalable and secure cloud computing platforms. We leverage Google Cloud's secure infrastructure as described in the Google infrastructure security design overview and Google security overview whitepaper. Vercel provides comprehensive Infrastructure Security and Application security protections as described in the Security and Compliance Measures overview.
OpenEvidence strives to maintain high operational availability of our services platform.
OpenEvidence stores and processes user data securely according to our Privacy Policy and Terms of Use.
Data is encrypted in transit and at rest. OpenEvidence uses SSL/TLS to encrypt data in transit and encrypts data at rest using industry-standard encryption algorithms, using strong encryption and authentication (TLS 1.2 with SHA256 certificate). Data is stored within our databases with AES-256. This helps ensure that none of your data can be read by anyone that is not authorized.
OpenEvidence tests all code for security vulnerabilities before release, and regularly scans our network and systems for vulnerabilities.
OpenEvidence maintains security polices, which are reviewed annually and updated regularly. These policies include:
OpenEvidence requires annual security training for all employees.
We take all reports of security vulnerabilities seriously and will respond to valid reports as we verify the vulnerability and develop a fix.
We take all reports of security vulnerabilities seriously and will respond to valid reports as we verify the vulnerability and develop a fix. Vulnerabilities and security concerns related to OpenEvidence can be responsibly reported to security@openevidence.com. Please include a detailed description of your discovery with clear, concise reproducible steps or a working proof-of-concept.
We welcome security researchers to submit reports of vulnerabilities affecting OpenEvidence.com, the OpenEvidence app, and other properties involved in the processing of user data. Please be aware that bug bounties are typically reserved for confirmed reports of vulnerabilities that are medium or higher severity and offered at the discretion of our information security team. We take into account attack scenario, exploitability, and security impact.