Twin Health · Vulnerability Disclosure

Twin Health Vulnerability Disclosure

Vulnerability disclosure

Twin Health runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyHealthcareMetabolic HealthDigital TwinDiabetesChronic CareArtificial IntelligenceHealth PlansEmployer Benefits
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
responsibledisclosure@twinhealth.com

Source

Vulnerability Disclosure

twin-health-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-21'
method: searched
probe: true
source: https://usa.twinhealth.com/legal/twin-health-responsible-disclosure-policy
policy:
- https://usa.twinhealth.com/legal/twin-health-responsible-disclosure-policy
contact:
- responsibledisclosure@twinhealth.com
scope:
  in:
  - Twin Health web and mobile applications and infrastructure
  - Systems and APIs under *.twinhealth.com
  - Authentication, authorization, and data-protection vulnerabilities
  out:
  - Third-party vendors
  - Social engineering
  - Denial-of-service testing
  - UI/UX issues
  - Demo system testing
safe_harbor: true
bug_bounty:
  program: self-hosted
  note: Twin Health states it may offer public recognition or a monetary reward
    for valid, high-impact findings, with amounts determined by severity, impact,
    and quality of the report. No HackerOne/Bugcrowd/Intigriti program found.
security_txt: false
evidence:
- source: https://usa.twinhealth.com/legal/twin-health-responsible-disclosure-policy
  kind: responsible-disclosure-page
  notes: Fetched 2026-07-21; names responsibledisclosure@twinhealth.com, safe-harbor
    commitment, in/out-of-scope lists, and discretionary rewards.
- source: https://usa.twinhealth.com/.well-known/security.txt
  kind: security.txt
  status: 404