Zocdoc · Vulnerability Disclosure

Zocdoc Vulnerability Disclosure

Vulnerability disclosure

Zocdoc runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

HealthcareAppointmentsBookingProvidersInsuranceTelehealthScheduling
Program: Hackerone

Disclosure Policy

Security Contact

Contact
{"note" => "A real, Zocdoc-published security reporting address — but published in DNS, where a researcher looking for a disclosure policy will not find it. It is an incident-reporting contact for certificate authorities (RFC 8659 iodef), not a vulnerability disclosure policy.", "source" => "DNS CAA iodef record on zocdoc.com", "value" => "action-informationsecurity@zocdoc.com"}

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-15'
method: probed
probe: true
program: none
policy: []
contact:
  - value: action-informationsecurity@zocdoc.com
    source: DNS CAA iodef record on zocdoc.com
    note: >-
      A real, Zocdoc-published security reporting address — but published in
      DNS, where a researcher looking for a disclosure policy will not find it.
      It is an incident-reporting contact for certificate authorities
      (RFC 8659 iodef), not a vulnerability disclosure policy.
evidence:
  - url: https://www.zocdoc.com/.well-known/security.txt
    status: 403
    finding: Bot challenge — no security.txt retrievable.
  - url: https://api-developer.zocdoc.com/.well-known/security.txt
    status: 404
  - url: https://auth.zocdoc.com/.well-known/security.txt
    status: 404
  - url: https://api-docs.zocdoc.com/.well-known/security.txt
    status: 404
  - url: https://hackerone.com/zocdoc
    status: 200
    finding: >-
      NOT a Zocdoc-run program. The page carries HackerOne's
      `spec-external-unclaimed` marker and describes itself as a
      "community-curated security page"; hackerone.com/zocdoc.json returns 404,
      confirming no claimed team exists.
  - url: https://bugcrowd.com/zocdoc
    status: 404
  - url: https://www.zocdoc.com/about/security/
    status: 403
    finding: Bot challenge — Zocdoc's own security page could not be read.
  - source: security/zocdoc-domain-security.yml
    kind: dns-caa
    finding: '0 iodef "mailto:action-informationsecurity@zocdoc.com"'
note: >-
  No published vulnerability disclosure program was verified. No security.txt on
  any host, no claimed HackerOne or Bugcrowd program, and Zocdoc's own security
  page is unreachable to any non-browser client. Recorded as an honest absence:
  NO `Security` or `VulnerabilityDisclosure` pointer is wired into apis.yml,
  because a pointer would assert a surface Zocdoc does not demonstrably serve.
  The one thing Zocdoc does publish machine-readably is the CAA iodef address
  above.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zocdoc-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.