generated: '2026-09-02' method: searched probe: true source: https://www.cencora.com/responsible-disclosure note: >- Cencora (formerly AmerisourceBergen) publishes a full Responsible Security Disclosure program: scope, researcher guidelines, excluded submission types, a stated remediation workflow, and an explicit good-faith safe harbour. Reports go through a web form, with security-disclosures@cencora.com given as the fallback when the form is unavailable. There is no bug-bounty platform (no HackerOne / Bugcrowd / Intigriti listing) and no /.well-known/security.txt is served on any Cencora host — the program is discoverable only from the site footer. policy: - https://www.cencora.com/responsible-disclosure contact: - security-disclosures@cencora.com submission_channel: web form at https://www.cencora.com/responsible-disclosure bug_bounty: false security_txt: false safe_harbor: true scope: >- Internet-accessible systems, applications, websites and services that Cencora owns and operates. Third-party or partner-operated systems are out of scope unless Cencora explicitly names them as eligible. excluded: - Informational or best-practice findings with no demonstrated security impact - Unvalidated automated scanner output - Missing headers, TLS/certificate observations, version disclosure, DNS or email-auth configuration, clickjacking and similar hardening issues with no realistic attack scenario - Denial-of-service, load, stress and resource-exhaustion testing - Social engineering, phishing, physical security testing, credential stuffing, brute force, spam - Duplicates, publicly known issues already being remediated, unsupported browsers/software - Findings affecting systems Cencora does not own or operate commitments: - Acknowledge receipt of the report - Review, validate and risk-assess the issue - Coordinate remediation by severity and business impact - Provide status updates where appropriate - Treat reporter personal information as confidential disclosure_policy: >- Coordinated. Researchers must not publicly disclose until Cencora has had a reasonable opportunity to investigate and remediate, and must coordinate any proposed disclosure in advance. evidence: - source: https://www.cencora.com/responsible-disclosure kind: disclosure-page http_status: 200 keywords: [responsible disclosure, security vulnerability, safe harbor, good faith, remediation] - source: https://www.cencora.com/.well-known/security.txt kind: security.txt http_status: 404 note: not served x-evidence: checked: '2026-09-02'