HIKMA
FeaturesPricingAboutFree readiness quiz
● BETARequest early access

Security & Responsible Disclosure

Last updated · June 2026

We take the security of HIKMA and your data seriously. This page explains how we protect the platform and how security researchers can report a vulnerability to us safely.

Found a security issue? Email [email protected]. We welcome good-faith reports and will work with you to resolve them.

Our commitment

Protecting your account and study data is a core priority. The measures we take include:

  • Encryption in transit — traffic to and from HIKMA is served over HTTPS (TLS).
  • Access controls — internal access to systems and data is restricted on a least-privilege basis.
  • Isolation — each user's content (including documents you upload to Study Hub) is scoped to their account.
  • Trusted providers — we rely on established providers (for example, Clerk for authentication, Stripe for payments, and Cloudflare for bot protection) so sensitive data such as passwords and full card numbers is handled by specialists, not stored by us.

No system is perfectly secure. We work continuously to improve our defenses and will notify affected users of a material breach as required by law.

Reporting a vulnerability

If you discover a potential security vulnerability, please report it privately to [email protected] rather than disclosing it publicly. Give us a reasonable opportunity to investigate and remediate before any public disclosure.

What to include

  • A clear description of the issue and its potential impact.
  • Step-by-step instructions to reproduce it, with any proof-of-concept.
  • The affected URL, endpoint, or component, and the date/time you observed it.
  • How we can contact you for follow-up.

Safe harbor for good-faith research

We will not pursue legal action against, or report to law enforcement, security researchers who act in good faith and in accordance with this policy. Good-faith research means you:

  • Avoid privacy violations, data destruction, and degradation of our service.
  • Only interact with accounts you own or have explicit permission to test.
  • Do not access, modify, or retain more data than is necessary to demonstrate the issue, and delete any such data afterward.
  • Give us reasonable time to remediate before public disclosure.

If in doubt about whether an action is authorized, contact us first at [email protected] and ask.

Out of scope

The following are generally not in scope for this program:

  • Denial-of-service (DoS/DDoS), volumetric, or brute-force attacks.
  • Social engineering, phishing, or physical attacks against our staff or facilities.
  • Vulnerabilities in third-party services (such as Clerk, Stripe, or Cloudflare) — please report those to the respective provider.
  • Reports from automated scanners without a demonstrated, exploitable impact, and best-practice or missing-header findings with no security consequence.
  • Issues requiring a rooted/jailbroken device or already-compromised account.

Contact

Security reports: [email protected]. For all other questions, see Privacy or email [email protected].

HIKMA

Walk the path to mastery. HIKMA is a clinical reasoning simulator built from scratch for the new USMLE — Step 1 and Step 2 CK — branching cases where your decisions shape the patient.

Product

  • Features
  • Pricing
  • About

Study library

  • Disease reviews
  • Differentials
  • High-yield topics
  • Am I ready? — free check

HIKMA is an educational study tool, not medical advice, and is not a substitute for professional clinical judgment or supervision. Clinical scenarios are fictional teaching cases and some content is AI-generated.

HIKMA is independent and is not affiliated with, endorsed by, or sponsored by the NBME or FSMB. “USMLE”, “Step 1”, “Step 2 CK”, and “Step 3” are trademarks of their respective owners and are used for identification purposes only.

© 2026 HIKMA
PrivacyTermsLegal
Walk the path to mastery

We value your privacy

HIKMA uses cookies that are strictly necessary to run the app, plus optional cookies for functionality, analytics, and marketing. You decide what we use. See our Cookie Policy and Privacy Policy.