Metriport · Vulnerability Disclosure
Metriport Vulnerability Disclosure
Vulnerability disclosure
Metriport publishes a vulnerability disclosure policy, but only in the open-source repository — there is no security.txt on any host (every /.well-known/security.txt probe returned 403 on the API hosts and 404 on the marketing and documentation hosts, see well-known/metriport-well-known.yml). The policy is short and covers both the source code and the hosted API.
Metriport runs a coordinated vulnerability disclosure program on Hackerone.
HealthcareMedical RecordsFHIRHealth DataWearablesOpen-Source
Program: Hackerone