Security
How to report a vulnerability, what good-faith research looks like, which CoreSignal surfaces are in scope, and how coordinated disclosure works.
Public policy target for /.well-known/security.txtEffective July 2026 | Last updated August 31, 2026 | CoreSignal Health
If you believe you have discovered a security vulnerability in CoreSignal Health, please tell us directly before disclosing it publicly. Reports may be sent to either address below. We aim to acknowledge reports promptly; response times may vary with severity and available evidence.
Include a clear description of the issue, steps to reproduce, the affected URL or endpoint, and any proof of concept. If the finding involves protected health information, redact patient data before sending and let us pull the full trace from our own logs.
CoreSignal welcomes good-faith security research. We will not pursue or support legal action, including under the Computer Fraud and Abuse Act or the Digital Millennium Copyright Act, against researchers who:
Some findings are not actionable and will be closed without remediation. This includes reports that rely on:
We publicly thank researchers who report valid, in-scope vulnerabilities and give us a chance to fix them before disclosure. When you report a finding, tell us how you want to be credited (name, handle, or organization; or credit declined).
No researchers listed yet. If you would like to be the first, follow the reporting instructions above.
Some regulated clinic workflows may involve protected health information. Do not send patient PHI by email.
Our RFC 9116 disclosure file is served at /.well-known/security.txt. It points to this page and includes its current expiry date.