CoreSignalHealth
ProductFor MenFor ClinicsFor WomenFAQ
Report securely

Security

Responsible disclosure

How to report a vulnerability, what good-faith research looks like, which CoreSignal surfaces are in scope, and how coordinated disclosure works.

Public policy target for /.well-known/security.txt
CoreSignalCoreSignal
Back to CoreSignal

Security

Effective July 2026 | Last updated August 31, 2026 | CoreSignal Health

Reporting a vulnerability

If you believe you have discovered a security vulnerability in CoreSignal Health, please tell us directly before disclosing it publicly. Reports may be sent to either address below. We aim to acknowledge reports promptly; response times may vary with severity and available evidence.

  • security@coresignal.health
  • braiden@coresignal.health

Include a clear description of the issue, steps to reproduce, the affected URL or endpoint, and any proof of concept. If the finding involves protected health information, redact patient data before sending and let us pull the full trace from our own logs.

Safe harbor

CoreSignal welcomes good-faith security research. We will not pursue or support legal action, including under the Computer Fraud and Abuse Act or the Digital Millennium Copyright Act, against researchers who:

  • Report the issue promptly and privately to the contacts above.
  • Make a good-faith effort to avoid privacy violations, degradation of user experience, disruption of production systems, and destruction or modification of data.
  • Use only accounts you own or have explicit permission from the account holder to access.
  • Do not access, download, or exfiltrate patient health information beyond the minimum needed to demonstrate the issue.
  • Give us a reasonable window to remediate before any public disclosure. Ninety days is our default; we can move faster on coordinated disclosure.

Out of scope

Some findings are not actionable and will be closed without remediation. This includes reports that rely on:

  • Rate limiting or brute-force claims without a working PoC.
  • Missing HTTP response headers on non-sensitive endpoints.
  • Publicly accessible files that are intentionally public (marketing pages, robots.txt, sitemap.xml, security.txt itself).
  • Automated scanner output without a proof of exploit.
  • Social engineering, phishing, or physical attacks against our team or vendors.

Acknowledgments

We publicly thank researchers who report valid, in-scope vulnerabilities and give us a chance to fix them before disclosure. When you report a finding, tell us how you want to be credited (name, handle, or organization; or credit declined).

No researchers listed yet. If you would like to be the first, follow the reporting instructions above.

HIPAA and healthcare data

Some regulated clinic workflows may involve protected health information. Do not send patient PHI by email.

Machine-readable policy

Our RFC 9116 disclosure file is served at /.well-known/security.txt. It points to this page and includes its current expiry date.

CoreSignalHealth

One context system for individuals and clinics. Symptoms lead. Context stays attached. Clinical judgment stays clinical.

Explore

  • Product tour
  • CoreSignal Men
  • For Clinics
  • CoreSignal Women
  • FAQ

Company

  • About
  • Health library
  • Editorial policy
  • Support
  • Contact

Legal & privacy

  • Privacy policy
  • Terms of use
  • Security
  • Privacy choices
Questions about a pilot or partnership?Talk directly with CoreSignal Health.
hello@coresignal.health→
© 2026 CoreSignal HealthHuntsville, AlabamaEducational software · Not medical advice · Not for emergenciesDo Not Sell or Share My Personal Information