Responsible disclosure

Cencora is committed to protecting the security and privacy of our customers, partners, patients, and employees. We welcome reports made in good faith from security researchers and members of the public who identify potential vulnerabilities in systems, applications, websites, or services owned by Cencora.

If you believe you have found a security vulnerability, report it using the form below. If the form is not available, email security-disclosures@cencora.com.

Our commitment

Cencora will confirm that we received your report, review and validate the issue, assess its risk, and coordinate remediation of verified vulnerabilities based on severity and business impact. We may ask you for more information, and we will provide status updates when appropriate. Remediation timelines vary based on the complexity of the issue, its impact, and the systems affected.

We treat the personal information you give us, including your name and contact details, as confidential. What you report may be shared with the people who need it to investigate and fix the issue.

Scope

This program applies to internet-accessible systems, applications, websites, and services that Cencora owns and operates. Systems operated by a third party or a partner are out of scope unless Cencora explicitly identifies them as eligible. If you are not sure who owns a system, send the report anyway and explain why you believe it is connected to Cencora.

Responsible research guidelines

Researchers must act in good faith, follow applicable laws, use only accounts and data they own or are authorized to use, and limit testing to the minimum needed to demonstrate a vulnerability. Do not disrupt services or degrade system availability. Do not establish persistence or pivot to other systems. Do not access, modify, download, retain, or disclose data belonging to Cencora or to a third party.

If you encounter sensitive information, stop testing immediately, do not retain or share the information, and notify Cencora. Do not publicly disclose a suspected vulnerability until Cencora has had a reasonable opportunity to investigate and address it. Coordinate any proposed disclosure with Cencora in advance.

Excluded submission types

The following submissions are generally outside the scope of this program unless you can demonstrate security impact:

  • Informational findings, best-practice recommendations, or compliance observations without demonstrated security impact
  • Automated scanner output without manual validation, reproduction steps, and evidence of exploitability
  • Missing headers, certificate or TLS observations, version disclosure, DNS or email-authentication configuration, clickjacking, or similar hardening issues without a realistic attack scenario
  • Denial-of-service, load, stress, or resource-exhaustion testing
  • Social engineering, phishing, physical security testing, credential stuffing, brute-force testing, spam, or unsolicited bulk messaging
  • Duplicate reports, publicly known issues already being remediated, and findings limited to unsupported browsers or software
  • Findings affecting third-party systems or services not owned or operated by Cencora

Cencora determines the validity, severity, and applicability of each report based on technical impact, exploitability, affected data and systems, and organizational risk.

Good-faith safe harbor

Cencora supports security research conducted in good faith and in accordance with this program. When research is consistent with these guidelines, Cencora will consider it authorized for purposes of this program and will not initiate legal action based solely on that research. If a third party initiates legal action, Cencora may clarify that the activity was conducted in accordance with this program. This safe harbor does not authorize activity involving systems or data owned by third parties. It also does not waive any applicable legal rights.

Report a vulnerability

Use the form alongside to report a vulnerability. Required fields are marked.