Legal
Trust & Security
This page explains the security model and trust practices used for Alle's ClinX Knowledge, including what the static architecture reduces, what remains dependent on hosting and browsers, and how to report a security concern responsibly.
01Static architecture and reduced application state
Knowledge is published primarily as static HTML, CSS, JavaScript, JSON and media. Reading an article does not require a Knowledge account, server-side profile, shopping cart, password or payment flow.
Reducing server-side application state lowers some categories of risk, but static sites can still be affected by supply-chain issues, malicious dependencies, hosting compromise, browser vulnerabilities, content errors, unsafe external links or configuration mistakes.
02HTTPS and GitHub Pages hosting
GitHub Pages supports HTTPS for correctly configured Pages sites, which protects data in transit against ordinary interception or modification between a browser and the served site. GitHub's current guidance on Pages HTTPS is available in its Pages security documentation.
Hosting, edge delivery, certificates and platform-level security controls are provided in part by GitHub and related infrastructure. Those controls are governed by GitHub's own terms, policies and operational practices rather than by this page alone.
03Version control, review and automated checks
Knowledge source files are version-controlled, which creates a change history and supports review before publication. Shared site changes are tested through automated repository workflows, including production builds, interaction smoke tests, PWA checks and mobile overflow regression coverage.
Passing automated checks reduces known regression risk but does not prove the absence of vulnerabilities. Security-sensitive changes may require additional review depending on their scope.
04Search, local processing and browser storage
Knowledge search loads a static index and ranks results in the browser, so ordinary search does not require a dedicated Alle's ClinX search server to receive each phrase. Article text-size preferences are stored locally in the browser.
The progressive web app uses a service worker and Cache Storage for offline support. Users on shared or managed devices should clear site data when local persistence is not appropriate. The Cookie Policy describes these technologies in more detail.
05Personal-data security and India's DPDP framework
Where Alle's ClinX controls personal-data processing, security measures should be proportionate to the nature of the data, processing and risk. India's DPDP framework includes security and breach obligations on the timetable prescribed by the Act, Rules and commencement notifications.
Because substantive DPDP obligations are being phased in, this page does not misstate a future commencement date as a present certification. We will apply duties as they become legally applicable and continue to use reasonable safeguards before then.
06Cyber-incident obligations and CERT-In
India's Computer Emergency Response Team, CERT-In, issues directions under section 70B of the Information Technology Act, 2000 concerning cyber-incident prevention, response, logging and reporting. Reportable incidents can be subject to rapid notification requirements, including the six-hour reporting framework described in CERT-In's current directions and FAQs.
Where those directions apply to an Alle's ClinX-controlled entity or system, incident handling must be performed at the responsible system level. This statement does not imply that Alle's ClinX directly controls every log or security process inside GitHub's hosting infrastructure. See CERT-In Directions under section 70B.
07External links, third parties and supply chain
Knowledge links may open government sources, standards bodies, GitHub, allesclinx.com, email applications, social-sharing destinations and other third parties. A legitimate link does not make Alle's ClinX responsible for the destination's security controls or privacy practices.
Before entering credentials or sensitive information, verify the destination domain and the context. Knowledge pages on GitHub Pages should not be used to submit passwords or payment-card information.
08AI-assisted services and prompt security
AI services can introduce risks such as prompt injection, fabricated sources, sensitive-data disclosure and unsafe automation. AI-assisted output should be checked against current authoritative sources where a decision affects safety, compliance, product handling or another consequential outcome.
Do not place secrets, credentials or unnecessary sensitive information into an AI prompt. Additional controls and disclosures for AI are described in AI & Data Use.
09Responsible vulnerability reporting
If you identify a potential vulnerability affecting Knowledge, report it privately with the affected URL or component, steps needed to reproduce the issue, expected versus observed behaviour and any non-sensitive evidence that helps us understand the risk.
Do not include passwords, access tokens or personal data that is not necessary to demonstrate the issue. Avoid destructive testing, denial-of-service activity, social engineering, persistence, accessing data that is not yours, or testing third-party infrastructure without that provider's permission.
10No bug-bounty or testing authorisation
This page is not a bug-bounty programme and does not promise payment, reward or legal safe harbour. It also does not grant permission to bypass access controls or test systems owned by GitHub, hosting providers, customers or other third parties.
Good-faith reports are welcome, but any security testing must remain within applicable law and any permissions you independently hold.
11Incident response, correction and recovery
When a material security issue is confirmed, appropriate response can include containment, investigation, correction, deployment of a fixed version, preservation of evidence, communication to affected parties and legally required notification to authorities.
Content-integrity problems—such as a wrong safety document, misleading citation or compromised page—are also treated as trust issues and may require rapid correction even when no personal data is involved.
12Security limitations and updates
No website can guarantee perfect security, continuous availability or immunity from future vulnerabilities. Users should keep browsers and operating systems updated and exercise caution with external links and downloads.
We may update this statement when the hosting model, security controls, applicable law or incident-response process changes materially.