Health Gorilla Vulnerability Disclosure
Health Gorilla publishes a security.txt document naming a dedicated security contact address, an OpenPGP encryption key and a policy URL. The finding worth recording is the delivery: the document exists and its content is a valid RFC 9116 field set, but it is served as an HTML page at /home/security-txt rather than as text at /.well-known/security.txt, so no automated scanner or agent following RFC 9116 will ever find it. Its Expires field also lapsed on 2025-12-31, which under RFC 9116 makes the document formally stale.
Health Gorilla runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.