generated: '2026-08-15' method: probed probe: true result: none note: >- DoseSpot publishes NO vulnerability disclosure programme. Probed on 2026-08-15: /.well-known/security.txt returns 404 on dosespot.com, www.dosespot.com, my.dosespot.com, staging.dosespot.com and docs.dosespot.com (status.dosespot.com and trust.dosespot.com answer 200 with an SPA shell, which is not a security.txt document). https://dosespot.com/security/ is a marketing security-posture page naming SOC 2 Type 2, HITRUST (in progress), HIPAA, NIST and PCI DSS - it contains no responsible disclosure policy, no security@ contact and no bug bounty. No HackerOne, Bugcrowd or Intigriti programme was found. /security/responsible-disclosure, /responsible-disclosure and /vulnerability-disclosure are not in the published sitemap. Because there is no verified disclosure surface, NO `Security` or `VulnerabilityDisclosure` pointer is wired into apis.yml - this file records the absence. policy: [] contact: [] bug_bounty: [] evidence: - {source: 'https://dosespot.com/.well-known/security.txt', http_status: 404} - {source: 'https://www.dosespot.com/.well-known/security.txt', http_status: 404} - {source: 'https://my.dosespot.com/.well-known/security.txt', http_status: 404} - {source: 'https://docs.dosespot.com/.well-known/security.txt', http_status: 404} - {source: 'https://status.dosespot.com/.well-known/security.txt', http_status: 200, kind: soft-404, note: 'PagerDuty SPA shell, not a document'} - {source: 'https://trust.dosespot.com/.well-known/security.txt', http_status: 200, kind: soft-404, note: 'Vanta SPA shell, not a document'} - {source: 'https://dosespot.com/security/', http_status: 200, note: 'security posture page; no disclosure policy or contact'} recommendation: >- A HIPAA-regulated, EPCS-certified prescribing platform with a Vanta trust center and a SOC 2 Type 2 report is three lines of text away from a served /.well-known/security.txt. Publishing one (Contact, Policy, Expires) would close the highest-value operational gap on this profile.