generated: '2026-08-25' method: searched source: https://lucemhealth.com/report-security-issue/ program: published: true name: Report a Security Issue url: https://lucemhealth.com/report-security-issue/ http_status: 200 type: email-intake contact: - type: email value: kyle@lucemhealth.com instructions: >- The page asks reporters to include as much detail as possible to assist Lucem Health in the investigation and potential remediation of the issue. security_txt: served: false probed: - url: https://lucemhealth.com/.well-known/security.txt status: 404 - url: https://lucemhealth.com/security.txt status: 404 note: >- A disclosure page exists but is not advertised at the RFC 9116 location, so no automated scanner will find it. Publishing /.well-known/security.txt with a Contact: line pointing at this page is a one-file fix. bug_bounty: present: false searched: - hackerone.com - bugcrowd.com - intigriti.com note: No bug bounty or coordinated-disclosure platform listing was found. gaps: - No safe-harbor / authorized-testing language on the disclosure page. - No stated acknowledgement or remediation timeline. - No defined in-scope / out-of-scope asset list. - No PGP key or encrypted-submission channel. - Contact is a named individual mailbox rather than a role address (e.g. security@).