generated: '2026-08-14' method: searched probe: true source: https://www.healthgorilla.com/home/security-txt description: >- Health Gorilla publishes a security.txt document naming a dedicated security contact address, an OpenPGP encryption key and a policy URL. The finding worth recording is the delivery: the document exists and its content is a valid RFC 9116 field set, but it is served as an HTML page at /home/security-txt rather than as text at /.well-known/security.txt, so no automated scanner or agent following RFC 9116 will ever find it. Its Expires field also lapsed on 2025-12-31, which under RFC 9116 makes the document formally stale. disclosure_program: false bug_bounty: false contact: - security@healthgorilla.com policy: - https://www.healthgorilla.com/home/privacy-policy encryption: - https://healthgorilla.com/pgp-key.txt preferred_languages: [EN] expires: '2025-12-31' expired: true security_txt: published: true url: https://www.healthgorilla.com/home/security-txt http_status: 200 served_at_well_known: false content_type: text/html file: health-gorilla-security-txt.txt rfc9116_fields_present: [Contact, Encryption, Policy, Expires, Preferred-Languages] findings: - >- Delivered as an HTML page, not text/plain at /.well-known/security.txt. GET https://www.healthgorilla.com/.well-known/security.txt returns the Webflow site shell (soft-404), and GET https://api.healthgorilla.com/.well-known/security.txt returns 404. - >- The Contact field is written "mailto: security@healthgorilla.com" with a space after the scheme colon, which is not a valid mailto URI. - >- Expires is 2025-12-31, in the past as of this probe. RFC 9116 states a security.txt whose Expires date has passed should not be trusted as current. - >- Policy points at the general privacy policy rather than a dedicated vulnerability disclosure or responsible disclosure page. bounty_platforms: hackerone: not found bugcrowd: not found intigriti: not found disclosure_pages_probed: - {url: 'https://www.healthgorilla.com/security', http_status: 200, result: 'soft-404 site shell — rejected'} - {url: 'https://www.healthgorilla.com/compliance', http_status: 200, result: 'soft-404 site shell — rejected'} - {url: 'https://api.healthgorilla.com/.well-known/security.txt', http_status: 404, result: miss} - {url: 'https://developer.healthgorilla.com/.well-known/security.txt', http_status: 404, result: miss} - {url: 'https://www.healthgorilla.com/.well-known/security.txt', http_status: 200, result: 'soft-404 site shell — rejected'} related_security_posture: page: https://www.healthgorilla.com/home/company/health-data-security certifications: [HITRUST r2, SOC 2 Type 2] detail: security/health-gorilla-trust-center.yml recommendation_for_provider: >- Serve the existing document as text/plain at https://www.healthgorilla.com/.well-known/security.txt, fix the mailto URI, refresh Expires, and point Policy at a dedicated disclosure page. The content already exists — only the delivery is missing. evidence: - {source: 'https://www.healthgorilla.com/home/security-txt', kind: security.txt, http_status: 200} - {source: security/health-gorilla-security-txt.txt, kind: harvested-verbatim} - {source: 'https://www.healthgorilla.com/sitemap.xml', kind: sitemap, note: 'located the real /home/security-txt path'} x-evidence: - {url: 'https://www.healthgorilla.com/home/security-txt', http_status: 200, fetched: '2026-08-14'} - {url: 'https://healthgorilla.com/pgp-key.txt', http_status: 200, fetched: '2026-08-14'}