generated: '2026-08-25' method: probed source: live probes of mantrahealth.com and api.mantrahealth.com name: Mantra Health vulnerability disclosure note: >- NO VULNERABILITY DISCLOSURE PROGRAM WAS FOUND. This file records the negative probe. No `Security` pointer is wired into apis.yml, because the `security_disclosure` check asserts the provider publishes a disclosure route and Mantra does not. Recorded because it is a meaningful gap for a company holding student Protected Health Information under HIPAA and SOC 2. present: false security_txt: present: false probed: - url: https://mantrahealth.com/.well-known/security.txt status: 301 note: Redirects to the homepage — soft-404, no document. - url: https://api.mantrahealth.com/.well-known/security.txt status: 404 policy_url: null contact: null contact_note: >- The only published contact of any kind is the general address hi@mantrahealth.com and the sales form at https://mantrahealth.com/get-in-touch/. Neither is designated for security reports, and the Security and Privacy page offers no security contact. bug_bounty: present: false platform: null note: No HackerOne, Bugcrowd or Intigriti program was found for Mantra Health. disclosure_pages_probed: - url: https://mantrahealth.com/responsible-disclosure status: 200 note: Soft-404 — redirects to the homepage. - url: https://mantrahealth.com/vulnerability-disclosure status: 200 note: Soft-404 — redirects to the homepage. - url: https://mantrahealth.com/security status: 200 note: >- Redirects to /security-and-privacy/, which is a compliance marketing page. It contains no disclosure policy, no security contact and no reporting instructions.