Canada Life · Vulnerability Disclosure

Canada Life Vulnerability Disclosure

Vulnerability disclosure

Canada Life runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

InsuranceCanadaLife InsuranceHealth InsuranceEmployee BenefitsGroup RetirementCarrierACORDPartner GatedNo Public API
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
corporateinvestigations@canadalife.com
Contact
1-877-751-3417
Contact
https://www.canadalife.com/contact-us/fraud-complaints/fraud-concerns/corporate-investigations.html

Source

Vulnerability Disclosure

canada-life-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
program: false
program_note: >-
  Canada Life runs no researcher-facing vulnerability disclosure program. There is no
  security.txt on any host, no bug bounty on HackerOne, Bugcrowd or Intigriti, no
  /responsible-disclosure or /vulnerability-disclosure page, and no safe-harbour
  language anywhere on canadalife.com. What does exist is a consumer-facing security
  and fraud reporting channel, recorded below so the distinction is explicit rather
  than implied.
bug_bounty: null
safe_harbour: false
security_txt: false
policy:
- https://www.canadalife.com/internet-security.html
contact:
- corporateinvestigations@canadalife.com
- '1-877-751-3417'
- https://www.canadalife.com/contact-us/fraud-complaints/fraud-concerns/corporate-investigations.html
channels:
- name: Internet security
  url: https://www.canadalife.com/internet-security.html
  status: 200
  kind: security-practices-page
  covers: >-
    Published security practices — SSL encryption on the online portals, 25-minute
    inactivity auto-logout, monitoring and anti-malware — plus instructions to report
    phishing, suspicious email, and fraudulent websites to the Corporate Investigations
    team.
  omits: >-
    No multi-factor authentication commitment, no named certification (SOC 2, ISO
    27001, PCI DSS), no researcher disclosure process, no PGP key.
- name: Contact Corporate Investigations
  url: https://www.canadalife.com/contact-us/fraud-complaints/fraud-concerns/corporate-investigations.html
  status: 200
  kind: report-form
  contact_email: corporateinvestigations@canadalife.com
  contact_phone: '1-877-751-3417'
  accepts: General fraud-related concerns; submissions may be anonymous.
  published_caveat: >-
    "The security of email communication cannot be guaranteed at this time. Any person
    wishing to communicate or send information of a private or confidential nature to
    Canada Life is encouraged to do so by calling 1-877-751-3417."
- name: Fraud prevention
  url: https://www.canadalife.com/fraud-prevention.html
  status: 200
  kind: consumer-awareness
- name: Benefits fraud tips line
  url: https://www.canadalife.com/fraud-prevention.html
  kind: confidential-tips-line
  note: >-
    Separate confidential line for health and dental benefits fraud or misuse, named on
    the Corporate Investigations form.
incident_disclosure:
  practices_public_notification: true
  evidence:
  - url: https://www.canadalife.com/about-us/news-highlights/news/canada-life-recently-identified-a-cyber-incident.html
    date: '2026-04'
    note: Initial public notice of a cyber incident identified in mid-April 2026.
  - url: https://www.canadalife.com/about-us/news-highlights/news/update-on-recent-cyber-incident.html
    date: '2026-05'
    note: >-
      Follow-up notice. States the incident was fully contained with no evidence of
      ongoing unauthorized activity, that impacted individuals were notified, and that
      credit monitoring was offered at no cost. Reported publicly as unauthorized access
      through a single employee account.
  assessment: >-
    Canada Life does publish dated incident notices on its own newsroom, which is a real
    transparency signal. It is a breach-notification practice, not a vulnerability
    disclosure policy, and the two are recorded separately here.
evidence:
- source: https://www.canadalife.com/internet-security.html
  kind: security-page
  status: 200
  keywords: [encryption, ssl, report, phishing, corporate investigations]
- source: https://www.canadalife.com/contact-us/fraud-complaints/fraud-concerns/corporate-investigations.html
  kind: contact-form
  status: 200
  keywords: [corporateinvestigations@canadalife.com, 1-877-751-3417]
- source: https://api.canadalife.com/.well-known/security.txt
  kind: security.txt
  status: 404
- source: https://www.canadalife.com/.well-known/security.txt
  kind: security.txt
  status: 404