generated: '2026-08-15' method: searched probe: true source: https://trust.beaconhealth.ai/ description: >- Beacon Health publishes a security contact and a security-issue reporting channel through its trust center at https://trust.beaconhealth.ai/. That is a real, provider-published intake path, so it is recorded as a verified hit. It is NOT a vulnerability disclosure policy: there is no published safe-harbour language, no scope statement, no response-time commitment, no bug bounty, and no /.well-known/security.txt on any Beacon Health host. What exists is a channel, not a policy — recorded that way rather than upgraded. policy: [] policy_url: null contact: - security@beaconhealth.ai contact_source: >- Published as the security contact on the Beacon Health trust center (trust.beaconhealth.ai), read from the anonymous trust-page data endpoint. reporting_channels: - kind: email value: security@beaconhealth.ai source: https://trust.beaconhealth.ai/ - kind: web-form value: "Report a security issue (Oneleet trust-center form)" source: https://trust.beaconhealth.ai/ note: >- The trust-center application ships a report-a-security-issue flow backed by POST /api/v1/tenants/{tenant}/report-trust-security-issue on the Oneleet platform. The form is Oneleet's; the destination is Beacon Health. bug_bounty: program: none platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false security_txt: present: false hosts_probed: - {url: 'https://www.beaconhealth.ai/.well-known/security.txt', status: 404} - {url: 'https://api.beaconhealth.ai/.well-known/security.txt', status: 404} - {url: 'https://trust.beaconhealth.ai/.well-known/security.txt', status: 200, note: 'SPA catch-all returning the 604-byte HTML shell — not a security.txt'} disclosure_pages_probed: - {url: 'https://www.beaconhealth.ai/responsible-disclosure', status: 404} - {url: 'https://www.beaconhealth.ai/security/responsible-disclosure', status: 404} - {url: 'https://www.beaconhealth.ai/vulnerability-disclosure', status: 404} - {url: 'https://www.beaconhealth.ai/security', status: 200, note: '307 redirect to https://trust.delve.co/beacon-health, which answers 429'} supporting_controls: source: security/beacon-health-trust-center.yml note: >- The trust center reports these vulnerability-management controls as PASSING, which is the company asserting a program exists behind the contact above. controls: - Vulnerability management policy established - Vulnerabilities scanned - Penetration testing performed within the last 12 months - Penetration testing findings remediated related_contacts: privacy: privacy@beaconhealth.ai legal: legal@beaconhealth.ai support: support@beaconhealth.ai evidence: - source: https://trust.beaconhealth.ai/ kind: trust-center fetched: '2026-08-15' http_status: 200 - source: https://api.oneleet.com/api/v1/tenants/trust.beaconhealth.ai/trust kind: trust-center-data fetched: '2026-08-15' http_status: 200 note: anonymous read of the trust page's own runtime data