Buoy Health · Vulnerability Disclosure

Buoy Health Vulnerability Disclosure

Vulnerability disclosure

Buoy Health runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

symptom-checkermedical-triagedigital-healthhealthcareclinical-aicare-navigationpatient-engagementdiagnosistelehealthoauth2
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@buoyhealth.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-08'
method: searched
probe: true
source: https://www.buoyhealth.com/security-and-privacy
summary: >-
  Buoy publishes a named security contact on its public Security and Privacy page ("Need to report a
  security issue or get in touch with our Security team? Contact security" linking to
  mailto:security@buoyhealth.com). There is no published responsible-disclosure policy document, no
  bug-bounty program on HackerOne/Bugcrowd/Intigriti, and no RFC 9116 security.txt on any Buoy host —
  so the contact exists but is not machine-discoverable.
policy: []
contact:
- mailto:security@buoyhealth.com
security_page: https://www.buoyhealth.com/security-and-privacy
bug_bounty:
  present: false
  platforms_checked: [hackerone, bugcrowd, intigriti]
security_txt:
  present: false
  hosts_checked:
  - https://www.buoyhealth.com/.well-known/security.txt
  - https://api.buoyhealth.com/.well-known/security.txt
  - https://api.sandbox.buoyhealth.com/.well-known/security.txt
  - https://auth.buoyhealth.com/.well-known/security.txt
  - https://auth.sandbox.buoyhealth.com/.well-known/security.txt
evidence:
- source: https://www.buoyhealth.com/security-and-privacy
  http_status: 200
  kind: security-page
  extract: 'mailto:security@buoyhealth.com'
  fetched: '2026-08-08'
- source: https://www.buoyhealth.com/.well-known/security.txt
  http_status: 404
  kind: security.txt
  fetched: '2026-08-08'
gaps:
- id: no-security-txt
  detail: >-
    A real security@ contact is published in HTML but not at /.well-known/security.txt, so scanners and
    agents cannot find it. Publishing RFC 9116 would close this with a five-line file.
- id: no-disclosure-policy
  detail: >-
    No safe-harbour / responsible-disclosure terms are published, so a researcher has no stated scope
    or legal assurance before reporting.