Waystar · Vulnerability Disclosure
Waystar Vulnerability Disclosure
Vulnerability disclosure
Waystar publishes a responsible-disclosure page on its main website naming a security contact. It is a minimal policy - a contact address and a statement of intent. There is no bug bounty, no safe-harbor language, no scope definition, no PGP key, no structured reporting form, and no RFC 9116 /.well-known/security.txt on any Waystar or ZirMed host (every host probed returned 404 - see well-known/waystar-well-known.yml). A researcher has an address to write to and nothing else.
Waystar runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
HealthcareRevenue Cycle ManagementRCMClearinghouseHealthcare PaymentsMedical BillingX12 EDIEligibilityClaimsRemittance
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
security@waystar.com
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.