generated: '2026-08-29' method: searched source: https://www.cybersecurity.abbott/home/coordinated-disclosure-program.html program: present: true name: Abbott Coordinated Disclosure Program type: coordinated-vulnerability-disclosure bug_bounty: false policy_url: https://www.cybersecurity.abbott/home/coordinated-disclosure-program.html contact_email: productsecurity@abbott.com scope: >- Medical Devices, Software as a Medical Device (SaMD), and Mobile Medical Applications. acknowledgement_sla: 5 business days, via a secure communication channel governance: >- Run by Abbott's cross-functional Product Security Working Group — product development, information security, information technology and quality assurance — which acts as the steering committee for the program. terms_note: >- Abbott's published terms state that submitted information is treated as non-proprietary and non-confidential and may be used without restriction or obligation to the reporter. There is no stated safe-harbour and no bounty. advisories: url: https://www.cybersecurity.abbott/home/product-advisories.html status: 200 note: Abbott publishes product security advisories/bulletins here (e.g. the Amnesia:33 advisory). security_txt: present: true host: www.libreview.com url: https://www.libreview.com/.well-known/security.txt status: 200 file: ../well-known/abbott-laboratories-security.txt rfc: RFC 9116 contact: mailto:adcsecops@abbott.com expires: '2026-12-16T05:00:00.000Z' encryption: https://abbottadc-pgpkey-security.s3.amazonaws.com/pgp.pub policy: https://abbottadc-pgpkey-security.s3.amazonaws.com/CVD-Policy.pdf note: >- Scoped to Abbott Diabetes Care (LibreView / FreeStyle Libre). www.abbott.com answers 403 for /.well-known/security.txt, so the corporate host serves no RFC 9116 document. probes: - url: https://www.libreview.com/.well-known/security.txt status: 200 - url: https://abbottadc-pgpkey-security.s3.amazonaws.com/CVD-Policy.pdf status: 200 - url: https://abbottadc-pgpkey-security.s3.amazonaws.com/pgp.pub status: 200 - url: https://www.cybersecurity.abbott/home/coordinated-disclosure-program.html status: 200 - url: https://www.cybersecurity.abbott/home/product-advisories.html status: 200 - url: https://www.abbott.com/.well-known/security.txt status: 403 not_found: - name: HackerOne program url: https://hackerone.com/abbott status: 200 verdict: not-abbott-operated note: >- The HackerOne page for Abbott is an externally-claimed directory stub (HackerOne's own markup tags it "spec-external-claimed") describing a known reporting process, not an Abbott-run bug bounty. Abbott's own program page names no bounty platform. Recorded as NOT a bug bounty.