Wider Circle · Vulnerability Disclosure

Wider Circle Vulnerability Disclosure

Vulnerability disclosure

Wider Circle runs a coordinated vulnerability disclosure program on Hackerone.

CompanyHealthcareHealth PlansMedicare AdvantageMedicaidPopulation HealthSocial Determinants of HealthMember EngagementCare CoordinationCommunity Health
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

wider-circle-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-04'
method: probed
source: DNS CAA record for widercircle.com (RFC 8659 iodef) + the public Incident
  Response Policy published at https://policy.widercircle.com/
program: none
bug_bounty: false
security_txt: false
note: >-
  Wider Circle publishes NO /.well-known/security.txt and runs NO bug-bounty or
  coordinated-disclosure program on HackerOne, Bugcrowd or Intigriti. It does,
  however, publish a security reporting address in DNS: the widercircle.com CAA
  record carries an RFC 8659 iodef property naming security@widercircle.com. Its
  public policy site additionally documents an Incident Response Policy and a Breach
  Policy with named reporting channels and a stated 4-hour customer breach
  notification window. Those are the only published routes for reporting a security
  issue that a member of the public can find; there is no researcher-facing safe
  harbour, scope statement, or disclosure timeline.
contacts:
- address: security@widercircle.com
  channel: dns-caa-iodef
  evidence: 'dig CAA widercircle.com -> 0 iodef "mailto:security@widercircle.com"'
  verified: '2026-09-04'
- address: privacy@widercircle.com
  channel: incident-response-policy
  evidence: https://policy.widercircle.com/
  verified: '2026-09-04'
policies:
- name: Incident Response Policy
  url: https://policy.widercircle.com/
  status: 200
  note: Names the Security Incident Response Team (SIRT) and the identification /
    containment / eradication / recovery / follow-up phases, and lists the channels a
    workforce member or customer may use to report an incident.
- name: Breach Policy
  url: https://policy.widercircle.com/
  status: 200
  note: 'States customer notification "no later than 4 hours after the discovery of
    the breach" and includes a sample customer notification letter.'
- name: Vulnerability Scanning Policy
  url: https://policy.widercircle.com/
  status: 200
- name: IDS Policy
  url: https://policy.widercircle.com/
  status: 200
probes:
- url: https://www.widercircle.com/.well-known/security.txt
  status: 404
- url: https://widercircle.com/.well-known/security.txt
  status: 404
- url: https://policy.widercircle.com/.well-known/security.txt
  status: 403
gaps:
- No RFC 9116 security.txt at any host.
- No public vulnerability disclosure policy addressed to external researchers.
- No bug bounty or VDP platform listing found.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/wider-circle-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.