Color · Vulnerability Disclosure

Color Vulnerability Disclosure

Vulnerability disclosure

Color runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyHealthHealthcareGenomicsOncologyCancer CarePreventive HealthEligibilityVirtual CareDiagnosticsLaboratoryEmployee Benefits
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsecurity@color.com
Contact
methodmailto
Contact
sourceThe trust centre's own "Report a vulnerability" button — mailto:security@color.com?subject=SafeBase Responsible Disclosure Report for Color

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-15'
method: searched
source: https://security.color.com/
program:
  published: true
  name: Responsible Disclosure
  maturity: full
  where: >-
    Published as a control inside Color's SafeBase-hosted trust centre at
    https://security.color.com/ (App Security > Responsible Disclosure). It is not
    published on color.com itself and there is no /.well-known/security.txt on any
    Color host.
  statement: >-
    "We appreciate your help in reporting bugs and have set up a bug bounty program
    to reward your efforts. Please visit our homepage
    ([link](https://www.color.com/security/vulnerability-reporting)) to report a bug."
contact:
  email: security@color.com
  method: mailto
  source: >-
    The trust centre's own "Report a vulnerability" button —
    mailto:security@color.com?subject=SafeBase Responsible Disclosure Report for Color
bounty:
  claimed: true
  platform: null
  note: >-
    The trust centre asserts a bug bounty program and flags a HackerOne
    integration as allowed, but no public program page was found: HackerOne
    /color returns 404 and no Bugcrowd program page exists for Color. Treat the
    reward claim as unverified.
defects:
  - id: dead-reporting-link
    severity: medium
    detail: >-
      The reporting URL the trust centre points at,
      https://www.color.com/security/vulnerability-reporting, is a soft-404: it
      answers HTTP 200 but renders the Color Health homepage (<title>Home - Color
      Health</title>). A researcher following the published link lands on
      marketing copy with no reporting form. The mailto: contact still works.
  - id: no-security-txt
    severity: low
    detail: >-
      No RFC 9116 /.well-known/security.txt is served on color.com,
      www.color.com, api.color.com, docs.color.com or home.color.com, so the
      disclosure channel is not machine-discoverable.
evidence:
- url: https://security.color.com/
  status: 200
  found: Responsible Disclosure control, maturity "full", mailto security@color.com
- url: https://www.color.com/security/vulnerability-reporting
  status: 200
  found: soft-404 — renders the Color Health homepage, no reporting content
- url: https://hackerone.com/color
  status: 404
- url: https://color.com/.well-known/security.txt
  status: 502
- url: https://api.color.com/.well-known/security.txt
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/color-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.