Holmusk · Vulnerability Disclosure

Holmusk Vulnerability Disclosure

Vulnerability disclosure

Holmusk runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyHealthcareReal-World EvidenceBehavioral HealthMental HealthNeuropsychiatryClinical DataData AnalyticsLife SciencesHIPAA
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:disclosure@holmusk.com

Source

Vulnerability Disclosure

holmusk-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-22'
method: searched
probe: true
source: https://app.neuroblu.ai/.well-known/security.txt
contact:
- mailto:disclosure@holmusk.com
policy: []
note: >-
  Holmusk serves an RFC 9116 security.txt from the NeuroBlu application host only
  (https://app.neuroblu.ai/.well-known/security.txt — HTTP 200, text/plain, 73 bytes). It carries
  a Contact and an Expires field and nothing else: no Policy, no Encryption, no Preferred-Languages,
  no Canonical. The Expires value is 2025-12-31T00:00:00.000Z, which was in the past when probed on
  2026-08-22, so the document is STALE under RFC 9116 §2.5.4 even though it is served. The
  corporate site (www.holmusk.com) and the product site (www.neuroblu.ai) serve no security.txt
  (404 on both). No bug bounty program was found on HackerOne, Bugcrowd or Intigriti.
security_txt:
  url: https://app.neuroblu.ai/.well-known/security.txt
  status: 200
  file: well-known/holmusk-security.txt
  fields: [Contact, Expires]
  expires: '2025-12-31T00:00:00.000Z'
  expired: true
  last_modified: '2026-08-12T09:20:16Z'
bug_bounty: none-found
internal_program:
  documented: true
  source: https://policy.holmusk.com/
  detail: >-
    Holmusk publishes a vulnerability management policy: "External penetration testing is performed
    annually by a third party. Internal penetration testing is performed quarterly," with quarterly
    vulnerability report review through its Quality Management System. This is an internal testing
    program, not an external researcher disclosure program.
evidence:
- source: https://app.neuroblu.ai/.well-known/security.txt
  status: 200
  kind: security.txt
- source: https://www.holmusk.com/.well-known/security.txt
  status: 404
  kind: security.txt
- source: https://www.neuroblu.ai/.well-known/security.txt
  status: 404
  kind: security.txt
- source: https://policy.holmusk.com/
  status: 200
  kind: vulnerability-management-policy

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/holmusk-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.