generated: '2026-08-06' method: searched probe: true source: https://security.arbitalhealth.com/ policy: - https://security.arbitalhealth.com/ contact: - security@arbitalhealth.com bug_bounty: null security_txt: false statement: >- "If you think you may have discovered a vulnerability, please send us a note." — published on the Arbital Health Security Trust Center, with a Report a Vulnerability action that opens a mail to security@arbitalhealth.com. No formal written policy document, safe-harbor language, response SLA, or scope statement is published, and there is no bug bounty program (no HackerOne / Bugcrowd / Intigriti listing found). gaps: - No /.well-known/security.txt (RFC 9116) on any Arbital Health host — all four probed hosts return 404 or a login redirect. - No published disclosure scope, safe harbor, or acknowledgement timeline. evidence: - source: https://security.arbitalhealth.com/ kind: trust-center-disclosure http_status: 200 detail: 'mailto:security@arbitalhealth.com?subject=SafeBase Responsible Disclosure Report for Arbital Health' - source: https://arbitalhealth.com/.well-known/security.txt kind: security.txt http_status: 404 - source: https://auth.arbitalhealth.com/.well-known/security.txt kind: security.txt http_status: 404 x-evidence: fetched: '2026-08-06' url: https://security.arbitalhealth.com/ http_status: 200