generated: '2026-09-07' method: searched source: https://hackerone.com/centene_vdp provider: Centene providerId: centene note: >- Centene runs a coordinated vulnerability disclosure program on HackerOne. Found by search and verified by direct fetch (HTTP 200). Centene does NOT serve a /.well-known/security.txt on any host - all twelve hosts were probed and every one returned 404, 403 or 401 - so the program is discoverable only if a researcher already knows to look on HackerOne. program: published: true type: vulnerability-disclosure-program platform: HackerOne handle: centene_vdp url: https://hackerone.com/centene_vdp http_status: 200 bounty: >- Not established from the public page. Listed as a Vulnerability Disclosure Program, which on HackerOne is conventionally non-paying, but no reward table is published anonymously. scope_note: >- The program page states researchers must obtain explicit consent from the organization before conducting security testing against its mobile apps or APIs, and must report findings promptly and responsibly. security_txt: published: false hosts_probed: - host: centene.com status: 404 - host: www.centene.com status: 404 - host: partners.centene.com status: 403 - host: developer.centene.com status: 403 - host: external-api.my.centene.com status: 403 - host: iopc-pa.api.centene.com status: 404 - host: iopc-pd.api.centene.com status: 404 - host: prod.api.centene.com status: 404 - host: external-api.search.my.centene.com status: 401 - host: content.centene.com status: 404 recommendation: >- A three-line RFC 9116 security.txt at https://www.centene.com/.well-known/security.txt with Contact: https://hackerone.com/centene_vdp would make an existing program machine-discoverable at no cost. The program is the hard part and Centene has already done it. governance: source: https://www.centene.com/why-were-different/corporate-sustainability/business-accountability/data-privacy-security.html roles: - Chief Security and Privacy Officer (CSPO) - Chief Information Security Officer (CISO) oversight: - Board of Directors - Audit and Compliance Committee - Enterprise Risk Committee - Quality Committee maintainers: - FN: Kin Lane email: kin@apievangelist.com