generated: '2026-08-27' method: searched probe: true source: https://sibelhealth.com/security/ name: Sibel Health Vulnerability Disclosure Policy program: type: coordinated-disclosure published: true policy_url: https://sibelhealth.com/security/ contact_email: security@sibelhealth.com pgp_key_published: true pgp_note: A PGP public key is published on the policy page for encrypted submissions. bug_bounty: false bug_bounty_note: 'Stated verbatim on the policy page: Sibel Health neither provides financial compensation for disclosing vulnerabilities nor engages in a bug bounty program.' security_txt: false security_txt_note: No /.well-known/security.txt is served on sibelhealth.com (probed 2026-08-27, HTTP 404). The policy is published as an HTML page only, so RFC 9116 discovery does not work. commitments: - Acknowledgement of receipt of a report within 7 business days. - Assess and verify the legitimacy and severity of the reported vulnerability. - Develop a remediation plan with an estimated timeline. - Treat each report confidentially and not disclose it to third parties without consent. - Include vulnerability details in update release notes. report_should_include: - Detailed description of the vulnerability, including product or service name, URL, and affected versions - Operating system and environment details - Steps to reproduce - Proof-of-concept code where available - Impact assessment - Preferred disclosure timeline out_of_scope: - Reports of missing security headers that do not lead to significant impact - Issues arising only from outdated platforms - Social engineering - Physical security vulnerabilities - Vulnerabilities in third-party services evidence: - url: https://sibelhealth.com/security/ status: 200 note: Full coordinated-disclosure policy with named security contact, response SLA and scope. - url: https://sibelhealth.com/.well-known/security.txt status: 404 note: No RFC 9116 file; WordPress 404 page returned.