generated: '2026-08-08' method: searched probe: true source: https://www.buoyhealth.com/security-and-privacy summary: >- Buoy publishes a named security contact on its public Security and Privacy page ("Need to report a security issue or get in touch with our Security team? Contact security" linking to mailto:security@buoyhealth.com). There is no published responsible-disclosure policy document, no bug-bounty program on HackerOne/Bugcrowd/Intigriti, and no RFC 9116 security.txt on any Buoy host — so the contact exists but is not machine-discoverable. policy: [] contact: - mailto:security@buoyhealth.com security_page: https://www.buoyhealth.com/security-and-privacy bug_bounty: present: false platforms_checked: [hackerone, bugcrowd, intigriti] security_txt: present: false hosts_checked: - https://www.buoyhealth.com/.well-known/security.txt - https://api.buoyhealth.com/.well-known/security.txt - https://api.sandbox.buoyhealth.com/.well-known/security.txt - https://auth.buoyhealth.com/.well-known/security.txt - https://auth.sandbox.buoyhealth.com/.well-known/security.txt evidence: - source: https://www.buoyhealth.com/security-and-privacy http_status: 200 kind: security-page extract: 'mailto:security@buoyhealth.com' fetched: '2026-08-08' - source: https://www.buoyhealth.com/.well-known/security.txt http_status: 404 kind: security.txt fetched: '2026-08-08' gaps: - id: no-security-txt detail: >- A real security@ contact is published in HTML but not at /.well-known/security.txt, so scanners and agents cannot find it. Publishing RFC 9116 would close this with a five-line file. - id: no-disclosure-policy detail: >- No safe-harbour / responsible-disclosure terms are published, so a researcher has no stated scope or legal assurance before reporting.