generated: '2026-08-04' method: searched probe: true source: https://support.ekohealth.com/hc/en-us/articles/13156748752155-Security-and-HIPAA policy: [] contact: - security@ekohealth.com program: formal_vdp: false bug_bounty: false security_txt: false published_security_contact: true notes: >- Eko Health publishes a named security-reporting contact in its "Security and HIPAA" help-center article, under a "Security contact" heading: "To report security issues or concerns, please contact: security@ekohealth.com". That is a real, public intake channel for vulnerability reports. It is NOT a formal vulnerability disclosure policy: there is no /.well-known/security.txt on any Eko host (all four hosts probed returned 404), no responsible-disclosure page, no safe-harbour language, no scope or response-time commitment, and no bug bounty program on HackerOne, Bugcrowd or Intigriti. The mechanical probe (0-working/probe-security-programs.py) reported vdp=none; this file is the docs-searched upgrade of that result. gaps: - No /.well-known/security.txt (RFC 9116) on www.ekohealth.com, ekohealth.com, ekodevices.com, or api.ekodevices.com. - No published disclosure policy, scope statement, or safe-harbour commitment. - No bug bounty or coordinated-disclosure program. evidence: - source: https://support.ekohealth.com/hc/en-us/articles/13156748752155-Security-and-HIPAA kind: security-contact-page http_status: 200 quote: 'Security contact — To report security issues or concerns, please contact: security@ekohealth.com' article_updated: '2026-02-06' - source: https://www.ekohealth.com/.well-known/security.txt kind: security.txt http_status: 404 - source: https://api.ekodevices.com/.well-known/security.txt kind: security.txt http_status: 404 x-evidence: fetched: '2026-08-04'