generated: '2026-08-04' method: searched probe: true source: https://www.getcovered.io/security summary: >- Get Covered publishes a dedicated "Security Concerns" page under its Legal section with a named security contact address. It is a contact channel, not a full vulnerability disclosure program — there is no published policy document, no scope or safe-harbor statement, no response-time commitment, and no bug bounty on HackerOne, Bugcrowd or Intigriti. No RFC 9116 security.txt is served on any host. policy: [] contact: - security@getcovered.io pages: - url: https://www.getcovered.io/security http_status: 200 title: Security Concerns | GetCovered content: 'Report security concerns to Get Covered. Security Concerns: security@getcovered.io' security_txt: published: false probed: - {url: 'https://www.getcovered.io/.well-known/security.txt', http_status: 404} - {url: 'https://www.getcovered.io/security.txt', http_status: 404} - {url: 'https://getcoveredinsurance.com/.well-known/security.txt', http_status: 404} - {url: 'https://api.getcoveredinsurance.com/.well-known/security.txt', http_status: 404} bug_bounty: program: null platforms_checked: [hackerone, bugcrowd, intigriti] found: false gaps: - No RFC 9116 /.well-known/security.txt on any host. - No disclosure policy, scope statement, or safe harbor language. - No stated acknowledgement or remediation timeline. evidence: - {source: 'https://www.getcovered.io/security', kind: security-contact-page, http_status: 200} x-evidence: fetched: '2026-08-04'