generated: '2026-08-22' method: searched source: https://healthy.io/trust-center/security/reporting-suspected-vulnerabilities name: Healthy.io Coordinated Vulnerability Disclosure program: type: coordinated-disclosure bug_bounty: false bounty_platform: null note: >- Healthy.io publishes a coordinated vulnerability disclosure (CVD) policy on its public trust center. There is no bug bounty program and no HackerOne/Bugcrowd/Intigriti listing was found; reporting is direct-to-security-team by email. policy: url: https://healthy.io/trust-center/security/reporting-suspected-vulnerabilities status: 200 scope: >- "any aspect of its cloud services" - vulnerabilities affecting Healthy.io products and cloud services (verbatim scope language from the policy page). contact: email: security@healthy.io method: email source: https://healthy.io/trust-center/security/reporting-suspected-vulnerabilities commitments: - name: acknowledgement value: non-automated response within 24 hours confirming receipt verbatim: >- "The entity will receive a non-automated response to its initial contact within 24 hours, confirming receipt of the reported vulnerability." - name: progress_updates value: at least every five working days verbatim: '"The entity will receive progress updates at least every five working days."' - name: severity_scoring value: CVSS 2.0 verbatim: >- "Healthy.io uses version 2.0 of the Common Vulnerability Scoring System (CVSS) to evaluate potential vulnerabilities." - name: confidentiality value: reports kept confidential, not shared with third parties without permission - name: public_notification value: coordinated public notification with the reporter before disclosure process: - submit report with supporting material (proof-of-concept code, tool output) to security@healthy.io - Healthy.io assigns a tracking number and acknowledges receipt within 24 hours - dedicated security team validates and reproduces the reported vulnerability - severity scored with CVSS 2.0; results delivered with a resolution and disclosure plan - public notification coordinated with the reporter supporting_pages: - url: https://healthy.io/trust-center/security/incident-response status: 200 topic: incident response - url: https://healthy.io/trust-center/security/vulnerability-management status: 200 topic: vulnerability management - url: https://healthy.io/trust-center/security/penetration-test status: 200 topic: penetration testing - url: https://healthy.io/trust-center/security/secure-sdlc status: 200 topic: secure SDLC - url: https://healthy.io/trust-center/compliance/data-breach-notification status: 200 topic: data breach notification security_txt: served: false note: >- No RFC 9116 /.well-known/security.txt is served. Probed 2026-08-22 on healthy.io, direct.healthy.io and minuteful.com - all returned 404. The CVD policy exists only as an HTML page on the trust center, so an automated agent cannot discover the security contact from a well-known location. Publishing a security.txt pointing at https://healthy.io/trust-center/security/reporting-suspected-vulnerabilities and mailto:security@healthy.io would close that gap. x-evidence: fetched: '2026-08-22' probes: - url: https://healthy.io/trust-center/security/reporting-suspected-vulnerabilities status: 200 - url: https://healthy.io/.well-known/security.txt status: 404