generated: '2026-08-15' method: searched source: https://www.lumahealth.io/security-and-trust/ published: true program_type: security-contact note: >- Luma Health publishes a named security-reporting channel and an explicit invitation to report vulnerabilities on its Safety and Security page. There is NO bug bounty (no HackerOne / Bugcrowd / Intigriti program was found), no published safe-harbor or legal-protection language, no scope statement and no disclosure timeline or SLA - it is a disclosure mailbox rather than a structured VDP. It is also not machine-discoverable: no /.well-known/security.txt is served on any Luma host (www.lumahealth.io returns 404, api.lumahealth.io 302-redirects every /.well-known/ path to the marketing homepage), so an automated scanner finds nothing. Publishing an RFC 9116 security.txt pointing at this same mailbox would be a one-file fix. contact: email: security@lumahealth.io url: https://www.lumahealth.io/security-and-trust/ policy_url: null safe_harbor: null bug_bounty: present: false platforms_checked: [hackerone, bugcrowd, intigriti] security_txt: served: false probes: - url: https://www.lumahealth.io/.well-known/security.txt status: 404 - url: https://www.lumahealth.io/security.txt status: 404 - url: https://api.lumahealth.io/.well-known/security.txt status: 302 redirect: https://www.lumahealth.io/ quoted_policy: >- "If you have a security concern with the Luma platform, or you have reason to believe you have discovered a security weakness or vulnerability in our platform, let us know at security@lumahealth.io." related_practices: - annual third-party external penetration testing - annual independent audit of security policies, procedures and controls evidence: - url: https://www.lumahealth.io/security-and-trust/ status: 200 keywords: [security concern, vulnerability, security@lumahealth.io, penetration testing]