generated: '2026-08-26' method: probed source: Direct probe of RFC 9116 and common disclosure paths on every Sempre Health host. name: Sempre Health Vulnerability Disclosure description: 'No vulnerability disclosure program of any kind could be found. There is no security.txt on any host, no /security or /responsible-disclosure page, and no HackerOne, Bugcrowd or Intigriti listing. The only security-adjacent public surface is the Vanta trust center at trust.semprehealth.com, which does not publish a disclosure policy anonymously. Recorded as an honest absence, not a failure to look.' program: none security_txt: false bug_bounty: false disclosure_page: null security_contact: null probes: - url: https://www.semprehealth.com/.well-known/security.txt status: 404 - url: https://www.semprehealth.com/security.txt status: 404 - url: https://www.semprehealth.com/security status: 404 - url: https://eligibility.semprehealth.com/.well-known/security.txt status: 200 note: SPA catch-all HTML shell, not a security.txt - treated as a miss. - url: https://enroll.semprehealth.com/.well-known/security.txt status: 404 - url: https://docs.semprehealth.com/.well-known/security.txt status: 429 note: Netlify edge returned 429 with an empty body on every request to this host. checked: '2026-08-26'