Legal
Security
Last updated September 15, 2026
Foresica is operated by REB Human Services for immigration psychological evaluations. This page is the public account of how we handle security reports and the safeguards that apply to the Service.
1. Report a vulnerability
Email security@foresica.io. Use that address for suspected vulnerabilities, misconfigurations, or unauthorized access. Do not include protected health information, client names, credentials, session cookies, or live case material in the report.
Please tell us the affected URL or surface, what you observed, and enough detail to reproduce the issue. We will acknowledge reports sent to this mailbox and follow up as we investigate. We do not operate a public bug bounty.
Please do not attempt to access another practice’s data, degrade the Service, or run destructive testing. A machine-readable contact file is published at /.well-known/security.txt.
2. Safeguards in the Service
The Service is built for clinical and legal records. Practices keep their own policies; we provide technical and organizational controls so those records stay inside a reviewable system:
Access — practice-scoped accounts, roles, and case-level permissions. Each person has their own login. Password sign-in requires an emailed one-time code before a session is issued.
Transport and records — encrypted transport, protected clinical storage, and a private path from the application to the database.
Signature and delivery — tamper-evident report signatures, verification records, and a controlled attorney portal rather than an open email attachment.
Oversight — case access and delivery activity that can be audited, availability and error alerts to the security mailbox, and BAA documentation during practice onboarding.
3. Clinical control
Foresica can propose structure and language. It does not replace the clinician’s judgment, automatically sign a report, or treat an inference as a clinical fact. The licensed evaluator reviews, edits, and signs.
