SETPOINTk.ai · Governance

Security

SETPOINTk.ai separates a public educational surface from future clinical workflows. Clinical features (when enabled) are authenticated, governed, and auditable.

Public surface

  • No PHI required.
  • No diagnosis or treatment recommendation.
  • Public-safe demo data only.

Clinical surface (future)

  • Authenticated access (RBAC).
  • Audit logging + retention posture.
  • Least-privilege data exposure.

Vulnerability reporting

Email security@setpointk.ai with:

  • summary + affected URL(s)
  • repro steps / PoC
  • impact assessment
  • your preferred contact for follow-up

We will acknowledge receipt and coordinate a fix window for valid reports.