Forsta · Vulnerability Disclosure

Forsta Vulnerability Disclosure

Vulnerability disclosure

Forsta runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Customer InsightsFeedbackMarket ResearchSurveysCustomer ExperienceEmployee ExperiencePanel ManagementData CollectionAnalyticsVoice of the Customer
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@pressganey.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-10'
method: searched
probe: true
source: >-
  https://www.forsta.com/legal-privacy/ links a "Responsible disclosure policy"; the policy itself
  is published by the parent company at https://www.pressganey.com/responsible-disclosure-policy/
domain_note: >-
  The policy lives on pressganey.com because Forsta is the PG Forsta brand of Press Ganey, which
  acquired Forsta in 2022 - the same corporate entity signs Forsta's own legal documents (see
  https://www.forsta.com/legal-privacy/pg-forsta-technical-and-organizational-measures/, titled
  "PG Forsta technical and organizational measures"), and forsta.com's legal-privacy page
  advertises the disclosure policy as its own.
policy:
  - https://www.pressganey.com/responsible-disclosure-policy/
contact:
  - security@pressganey.com
pgp: >-
  A PGP public key is offered on the policy page for encrypting reports; reports touching PHI or
  other confidential data are required to be encrypted.
bug_bounty: false
bug_bounty_note: >-
  No bounty is offered and no HackerOne, Bugcrowd or Intigriti program exists - hackerone.com/forsta,
  hackerone.com/pressganey and bugcrowd.com/forsta all returned 404.
security_txt: false
security_txt_note: >-
  No /.well-known/security.txt on any Forsta host (see well-known/forsta-well-known.yml) and none
  on pressganey.com either (404). A machine cannot discover this policy; only a human reading the
  legal page can.
defect:
  - >-
    forsta.com's own legal-privacy page links its disclosure policy to
    https://www.forsta.com/responsible-disclosure-policy/, which returns HTTP 404. The working copy
    is the pressganey.com URL above. Probed 2026-09-10.
evidence:
  - source: https://www.forsta.com/legal-privacy/
    kind: link to disclosure policy
    status: 200
  - source: https://www.forsta.com/responsible-disclosure-policy/
    kind: the link target that page names
    status: 404
  - source: https://www.pressganey.com/responsible-disclosure-policy/
    kind: responsible disclosure policy with a security@ contact
    status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/forsta-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.