League · Vulnerability Disclosure

League Vulnerability Disclosure

Vulnerability disclosure

League runs a coordinated vulnerability disclosure program on Hackerone.

CompanyHealthHealthcareDigital HealthHealth BenefitsInteroperabilityFHIRAgentsArtificial IntelligencePatient EngagementInsuranceSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

league-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-25'
method: probed
source: live probes 2026-08-25
name: League vulnerability disclosure
provider: League
present: false
summary: >-
  NO vulnerability disclosure program was found. This is a genuine gap for a company holding HITRUST,
  SOC 2 Type 2 and HIPAA obligations across 63M+ members: there is no security.txt, no responsible
  disclosure page, no published security contact, and no bug bounty on any major platform.
security_txt:
  present: false
  probed:
  - {url: 'https://league.com/.well-known/security.txt', status: 403}
  - {url: 'https://league.com/security.txt', status: 403}
  - {url: 'https://api.league.com/.well-known/security.txt', status: 404}
  - {url: 'https://app.league.com/.well-known/security.txt', status: 404}
  - {url: 'https://help.league.com/.well-known/security.txt', status: 404}
  note: >-
    league.com answers 403 for unrouted paths while serving /robots.txt at 200 from the same host, so
    these are true negatives rather than our client being blocked.
disclosure_page:
  present: false
  searched: [/security, /responsible-disclosure, /vulnerability-disclosure, trust centre summary page, SafeBase portal landing page]
  note: >-
    The league.com/league-trust-centre/ page documents certifications and safeguards but gives no
    reporting route for a researcher. The SafeBase portal landing page likewise names no security
    contact.
bug_bounty:
  present: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  note: No program found under the League Inc / league.com brand.
recommendation: >-
  Publishing an RFC 9116 /.well-known/security.txt with a Contact: and Policy: field would be the
  single cheapest security improvement available to League, and would close the one conspicuous hole
  in an otherwise strong compliance posture.
security_pointer_emitted: false
security_pointer_note: >-
  NO `Security` pointer is wired into apis.yml — the security_disclosure check must reflect a
  published disclosure route, and League publishes none.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/league-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.