American Equity Investment Life Holding · Vulnerability Disclosure
American Equity Investment Life Holding Vulnerability Disclosure
Vulnerability disclosure
American Equity Investment Life Holding runs a coordinated vulnerability disclosure program on Hackerone.
Financial-ServicesInsuranceAnnuitiesFixed Indexed AnnuityRetirementLife InsuranceFortune 1000
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-02'
method: searched
source: https://www.american-equity.com/security-disclosure
name: American Equity Security Disclosure
summary: >-
American Equity publishes a public, unauthenticated Security Disclosure page that invites
anyone to report a potential security issue found on an American Equity company website.
Intake is a web form on that page — the company states it will review the submission and
contact the reporter with further questions or information.
program:
published: true
url: https://www.american-equity.com/security-disclosure
http_status: 200
discovered_via: https://www.american-equity.com/sitemap.xml
intake: web-form
authentication_required: false
scope_stated: >-
"a potential security issue on an American Equity company website" — website scope only.
No API, mobile, or infrastructure scope is enumerated.
bug_bounty: false
bounty_platform: null
safe_harbor_stated: false
pgp_key: null
security_txt: false
security_txt_note: >-
/.well-known/security.txt returns 404 on every American Equity host, so the disclosure
page is not machine-discoverable. Publishing an RFC 9116 security.txt pointing its
Policy: field at https://www.american-equity.com/security-disclosure would make this
existing program discoverable to automated scanners with no new process.
response_commitment: >-
"We will review and contact you with further questions or information." No SLA or
triage window is stated.
contacts:
- purpose: security-disclosure
method: web-form
url: https://www.american-equity.com/security-disclosure
- purpose: compliance-and-privacy
method: email
value: compliance@american-equity.com
source: https://www.american-equity.com/privacy
note: >-
Published on the privacy policy for privacy/compliance matters, not designated as the
security reporting channel. Recorded for completeness, not as a vulnerability contact.
observations:
- >-
The disclosure form itself is client-side rendered — the served HTML for
/security-disclosure contains the policy prose but no <form> element, so the intake
fields exist only after script execution.
- >-
No bug bounty program was found on HackerOne, Bugcrowd or Intigriti under the
American Equity, Eagle Life or American Equity Investment Life brands.
evidence:
- url: https://www.american-equity.com/security-disclosure
status: 200
note: responsible-disclosure policy + reporting form
- url: https://www.american-equity.com/security-disclosure/
status: 308
note: trailing-slash form 308s to the canonical path
- url: https://www.american-equity.com/.well-known/security.txt
status: 404
- url: https://register.american-equity.com/.well-known/security.txt
status: 404
- url: https://api.american-equity.com/.well-known/security.txt
status: 403
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/american-equity-investment-life-holding-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.