Responsible disclosure
Cencora is committed to protecting the security and privacy of our customers, partners, patients, and employees. We welcome reports made in good faith from security researchers and members of the public who identify potential vulnerabilities in systems, applications, websites, or services owned by Cencora.
If you believe you have found a security vulnerability, report it using the form below. If the form is not available, email security-disclosures@cencora.com.
Our commitment
Cencora will confirm that we received your report, review and validate the issue, assess its risk, and coordinate remediation of verified vulnerabilities based on severity and business impact. We may ask you for more information, and we will provide status updates when appropriate. Remediation timelines vary based on the complexity of the issue, its impact, and the systems affected.
We treat the personal information you give us, including your name and contact details, as confidential. What you report may be shared with the people who need it to investigate and fix the issue.
Scope
Responsible research guidelines
Researchers must act in good faith, follow applicable laws, use only accounts and data they own or are authorized to use, and limit testing to the minimum needed to demonstrate a vulnerability. Do not disrupt services or degrade system availability. Do not establish persistence or pivot to other systems. Do not access, modify, download, retain, or disclose data belonging to Cencora or to a third party.
If you encounter sensitive information, stop testing immediately, do not retain or share the information, and notify Cencora. Do not publicly disclose a suspected vulnerability until Cencora has had a reasonable opportunity to investigate and address it. Coordinate any proposed disclosure with Cencora in advance.
Excluded submission types
The following submissions are generally outside the scope of this program unless you can demonstrate security impact:
- Informational findings, best-practice recommendations, or compliance observations without demonstrated security impact
- Automated scanner output without manual validation, reproduction steps, and evidence of exploitability
- Missing headers, certificate or TLS observations, version disclosure, DNS or email-authentication configuration, clickjacking, or similar hardening issues without a realistic attack scenario
- Denial-of-service, load, stress, or resource-exhaustion testing
- Social engineering, phishing, physical security testing, credential stuffing, brute-force testing, spam, or unsolicited bulk messaging
- Duplicate reports, publicly known issues already being remediated, and findings limited to unsupported browsers or software
- Findings affecting third-party systems or services not owned or operated by Cencora
Cencora determines the validity, severity, and applicability of each report based on technical impact, exploitability, affected data and systems, and organizational risk.
