Beacon Health · Vulnerability Disclosure

Beacon Health Vulnerability Disclosure

Vulnerability disclosure

Beacon Health publishes a security contact and a security-issue reporting channel through its trust center at https://trust.beaconhealth.ai/. That is a real, provider-published intake path, so it is recorded as a verified hit. It is NOT a vulnerability disclosure policy: there is no published safe-harbour language, no scope statement, no response-time commitment, no bug bounty, and no /.well-known/security.txt on any Beacon Health host. What exists is a channel, not a policy — recorded that way rather than upgraded.

Beacon Health runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyHealthcarePrimary CareValue Based CareEHRArtificial IntelligenceAI AgentsWorkflow AutomationRisk AdjustmentPrior AuthorizationHIPAAY Combinator
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@beaconhealth.ai

Source

Vulnerability Disclosure

beacon-health-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://trust.beaconhealth.ai/
description: >-
  Beacon Health publishes a security contact and a security-issue reporting
  channel through its trust center at https://trust.beaconhealth.ai/. That is a
  real, provider-published intake path, so it is recorded as a verified hit. It
  is NOT a vulnerability disclosure policy: there is no published safe-harbour
  language, no scope statement, no response-time commitment, no bug bounty, and
  no /.well-known/security.txt on any Beacon Health host. What exists is a
  channel, not a policy — recorded that way rather than upgraded.
policy: []
policy_url: null
contact:
  - security@beaconhealth.ai
contact_source: >-
  Published as the security contact on the Beacon Health trust center
  (trust.beaconhealth.ai), read from the anonymous trust-page data endpoint.
reporting_channels:
  - kind: email
    value: security@beaconhealth.ai
    source: https://trust.beaconhealth.ai/
  - kind: web-form
    value: "Report a security issue (Oneleet trust-center form)"
    source: https://trust.beaconhealth.ai/
    note: >-
      The trust-center application ships a report-a-security-issue flow backed by
      POST /api/v1/tenants/{tenant}/report-trust-security-issue on the Oneleet
      platform. The form is Oneleet's; the destination is Beacon Health.
bug_bounty:
  program: none
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
security_txt:
  present: false
  hosts_probed:
    - {url: 'https://www.beaconhealth.ai/.well-known/security.txt', status: 404}
    - {url: 'https://api.beaconhealth.ai/.well-known/security.txt', status: 404}
    - {url: 'https://trust.beaconhealth.ai/.well-known/security.txt', status: 200, note: 'SPA catch-all returning the 604-byte HTML shell — not a security.txt'}
disclosure_pages_probed:
  - {url: 'https://www.beaconhealth.ai/responsible-disclosure', status: 404}
  - {url: 'https://www.beaconhealth.ai/security/responsible-disclosure', status: 404}
  - {url: 'https://www.beaconhealth.ai/vulnerability-disclosure', status: 404}
  - {url: 'https://www.beaconhealth.ai/security', status: 200, note: '307 redirect to https://trust.delve.co/beacon-health, which answers 429'}
supporting_controls:
  source: security/beacon-health-trust-center.yml
  note: >-
    The trust center reports these vulnerability-management controls as PASSING,
    which is the company asserting a program exists behind the contact above.
  controls:
    - Vulnerability management policy established
    - Vulnerabilities scanned
    - Penetration testing performed within the last 12 months
    - Penetration testing findings remediated
related_contacts:
  privacy: privacy@beaconhealth.ai
  legal: legal@beaconhealth.ai
  support: support@beaconhealth.ai
evidence:
  - source: https://trust.beaconhealth.ai/
    kind: trust-center
    fetched: '2026-08-15'
    http_status: 200
  - source: https://api.oneleet.com/api/v1/tenants/trust.beaconhealth.ai/trust
    kind: trust-center-data
    fetched: '2026-08-15'
    http_status: 200
    note: anonymous read of the trust page's own runtime data