generated: '2026-07-24' method: searched probe: true source: https://healthverity.com/vulnerability-disclosure/ policy: - https://healthverity.com/vulnerability-disclosure/ contact: - mailto:security@healthverity.com bug_bounty: false bug_bounty_note: >- HealthVerity does not currently operate a paid bug-bounty program; no compensation or rewards are offered for vulnerability reports. safe_harbor: true safe_harbor_note: >- Good-faith researchers who stay within the policy scope are protected from civil or criminal action for accidental, good-faith violations. scope: - Internet-accessible HealthVerity-owned websites and web applications - Publicly accessible HealthVerity APIs - Authentication and authorization issues - Sensitive-information exposure out_of_scope: - Third-party systems - Denial-of-service attacks - Social engineering - Automated scanning that impacts availability reporting: method: email address: security@healthverity.com acknowledgement: within five business days disclosure: coordinated with the researcher expires: '2027-07-21T00:00:00Z' evidence: - source: https://healthverity.com/.well-known/security.txt kind: security.txt (live probe, 200) - source: https://healthverity.com/vulnerability-disclosure/ kind: vulnerability disclosure policy page (200)