generated: '2026-09-06' method: probed probe: true source: https://www.dentsplysirona.com/.well-known/security.txt notes: >- Dentsply Sirona serves an RFC 9116 security.txt from its primary web host, so a disclosure channel exists and is machine-discoverable. The document is thin and partly broken: no Expires field (required by RFC 9116), the Encryption key 404s, the Policy URL is the consumer privacy policy rather than a disclosure policy, and Contact is a phone number with no email or web form. No bug bounty programme was found on HackerOne, Bugcrowd or Intigriti, and no /security, /responsible-disclosure or /vulnerability-disclosure page exists on the site. policy: - https://www.dentsplysirona.com/privacy-policy contact: - tel:+1704-587-0453 bug_bounty: null evidence: - source: https://www.dentsplysirona.com/.well-known/security.txt kind: security.txt http_status: 200 content_type: text/plain - source: https://www.dentsplysirona.com/pgp-key.txt kind: encryption-key http_status: 404 note: the key the security.txt names is not served - source: https://www.dentsplysirona.com/en-us/legal/security.html kind: security-policy-page http_status: 404 - source: https://security.dentsplysirona.com/ kind: security-subdomain http_status: 000 note: does not resolve gaps: - Add an `Expires:` field — without it the document is non-conformant to RFC 9116. - Publish the PGP key the `Encryption:` field points at, or drop the field. - Point `Policy:` at a vulnerability-disclosure policy, not the consumer privacy policy. - Add an email `Contact:` (security@dentsplysirona.com) so reports can be filed asynchronously.