Legal & General · Vulnerability Disclosure

Legal And General Vulnerability Disclosure

Vulnerability disclosure

Legal & General runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

InsuranceUnited KingdomLife InsuranceHealth InsuranceEmployee BenefitsPensionsAnnuitiesAsset ManagementUnderwritingCarrierBrokerPartner GatedNo Public APIDesign SystemAgent SkillsOpen Source
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
CanopyDesignSystem@landg.com

Source

Vulnerability Disclosure

legal-and-general-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
scope: >-
  Legal & General publishes NO corporate vulnerability disclosure policy, no
  security.txt and no bug bounty programme. The only published security-reporting
  route found anywhere on its public surface is the SECURITY.md of the Canopy
  design-system repository in its GitHub organisation. That is what is recorded
  here, and its narrow scope is stated so it is not mistaken for a company-wide
  VDP.
policy:
- https://github.com/Legal-and-General/canopy/blob/master/docs/SECURITY.md
contact:
- CanopyDesignSystem@landg.com
reporting_mechanism: >-
  Open a draft GitHub security advisory on Legal-and-General/canopy to discuss
  impact and remediation privately. For extenuating circumstances (e.g. needing
  a patch release on an older line) contact CanopyDesignSystem@landg.com.
supported_versions: >-
  Mainline branch only. Security patches are fixed forward; consumers must
  upgrade to the latest version and may have to apply documented breaking
  changes.
bug_bounty:
  present: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  note: no Legal & General programme found on any public bug-bounty platform
security_txt:
  present: false
  probes:
  - {url: 'https://www.legalandgeneral.com/.well-known/security.txt', status: 404}
  - {url: 'https://group.legalandgeneral.com/.well-known/security.txt', status: 404}
  - {url: 'https://am.landg.com/.well-known/security.txt', status: 404}
  - {url: 'https://www.landg.com/.well-known/security.txt', status: 404}
  - {url: 'https://www.legalandgeneral.com/security.txt', status: 404}
corporate_disclosure:
  present: false
  probes:
  - {url: 'https://www.legalandgeneral.com/responsible-disclosure', status: 404}
  - url: https://www.legalandgeneral.com/security/
    status: 200
    note: >-
      Customer-facing security information only — encryption in transit, email
      security, phishing awareness, third-party links, password guidance. No
      security@ address, no responsible-disclosure policy, no bug bounty and no
      certifications named. The only contact given is the general customer line
      0800 096 6959.
evidence:
- source: https://github.com/Legal-and-General/canopy/blob/master/docs/SECURITY.md
  kind: repository security policy
  verbatim: security/legal-and-general-canopy-security-policy.md
- source: https://www.legalandgeneral.com/security/
  kind: customer security page (no disclosure route)
- source: https://github.com/Legal-and-General/canopy/actions/workflows/codeql_analysis.yml
  kind: CodeQL analysis runs on the Canopy repository (badge on repo README)