generated: '2026-09-04' method: searched probe: true source: https://www.welldoc.com/platform/security program: published: true type: coordinated-disclosure bug_bounty: false policy_url: https://www.welldoc.com/platform/security contact_email: security@welldocinc.com scope: >- "a potential security vulnerability in a Welldoc website" — the published policy names Welldoc web properties; it does not enumerate API hosts, because Welldoc publishes no public API surface. submission_requirements: - Location and impact of the finding quote: >- "Welldoc security vulnerability disclosure — At Welldoc, security is vital. If you are an external researcher or user who has discovered a potential security vulnerability in a Welldoc website ... Please send all suspected vulnerability reports to our dedicated Security Team: Email: security@welldocinc.com" security_txt: served: false note: >- No /.well-known/security.txt is served on welldoc.com, www.welldoc.com, welldocinc.com, webappaz.welldoc.com, helpdesk.welldoc.com or learn.welldoc.com — every path returned 404. The disclosure policy exists only as an HTML section on the platform security page, so an automated RFC 9116 discovery finds nothing. Publishing a security.txt pointing at https://www.welldoc.com/platform/security and security@welldocinc.com would make this program machine-discoverable. evidence: - source: https://www.welldoc.com/platform/security http_status: 200 kind: disclosure page keywords: - vulnerability disclosure - security@welldocinc.com - source: https://www.welldoc.com/.well-known/security.txt http_status: 404 kind: security.txt probe (absent)