generated: '2026-09-02' method: searched source: https://www.graphitehealth.io/about/trust-security program: present: true name: Responsible Disclosure statement: >- Graphite welcomes users to report security, confidentiality, integrity and availability issues. Reports will be verified and addressed promptly, and, where appropriate, awarded a "bug bounty." policy_url: https://www.graphitehealth.io/about/trust-security policy_status: 200 submission_url: https://www.graphitehealth.io/contact submission_status: 200 submission_channel: general web contact form ("Disclose an Issue" links to /contact/) security_email: null pgp_key: null safe_harbor: not stated bug_bounty: offered: true qualifier: >- Rewards are discretionary — "where appropriate, awarded a 'bug bounty'". No amounts, scope, or rules of engagement are published. platform: none — no HackerOne, Bugcrowd, Intigriti or Open Bug Bounty program found program_url: null security_txt: served: false probe: https://www.graphitehealth.io/.well-known/security.txt status: 404 gaps: - No RFC 9116 /.well-known/security.txt, so an automated scanner or agent cannot find the disclosure channel. - No dedicated security@ address or PGP key; reports route through the same marketing contact form as sales enquiries. - No published scope, safe-harbour language, or response-time commitment.