SmithRx · Vulnerability Disclosure

Smithrx Vulnerability Disclosure

Vulnerability disclosure

SmithRx runs a coordinated vulnerability disclosure program on Hackerone.

CompanyHealth CarePharmacyPharmacy Benefit ManagementPrescription DrugsEmployee BenefitsClaimsInsuranceHealth Technology
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

smithrx-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-02'
method: searched
probe: true
source: https://smithrx.com/security
policy:
- https://smithrx.com/security
contact: []
intake:
  type: web-form
  url: https://smithrx.com/security
  fields:
  - Name
  - Email Address
  - Please describe the vulnerability
  - URL where the security event occured
  note: 'Verbatim page copy: "If you''ve identified a potential security vulnerability,
    please report it using this form." No dedicated security@ mailbox, PGP key, safe-harbour
    language, response SLA or scope statement is published alongside the form.'
bug_bounty:
  program: none
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
  result: no public program found
security_txt:
  published: false
  probed:
  - url: https://smithrx.com/.well-known/security.txt
    status: 404
  - url: https://smithrx.com/security.txt
    status: 404
  - url: https://api.mysmithrx.com/.well-known/security.txt
    status: 404
evidence:
- source: https://smithrx.com/security
  kind: disclosure-page
  http_status: 200
  fetched: '2026-08-02'
  matched:
  - Report a Security Vulnerability
  - potential security vulnerability
  - report it using this form
gaps:
- No RFC 9116 /.well-known/security.txt — machine discovery of the disclosure channel
  is not possible.
- No published safe-harbour / non-retaliation statement, scope, or acknowledgement
  timeline.
- No named security contact address; the form is the only channel.