Skip to content

Security: cld2labs/CareXtract

Security

SECURITY.md

Security Policy

CarExtract does not include production-grade security controls.

This repository is not secure by default and must not be used in production without a comprehensive security review.

Users are responsible for implementing appropriate:

  • Authentication and authorization mechanisms
  • Encryption and secure data storage
  • Monitoring, logging, and auditing
  • Regulatory and compliance safeguards
  • Patient data protection controls (HIPAA, GDPR, or applicable regulations)

Do not upload real patient data, personally identifiable information (PII), or protected health information (PHI) to any deployment of this blueprint unless you have implemented and validated the necessary security and compliance controls.

There aren't any published security advisories