Legal & General · Vulnerability Disclosure

Legal And General Vulnerability Disclosure

Vulnerability disclosure

Legal & General runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

InsuranceUnited KingdomLife InsuranceHealth InsuranceEmployee BenefitsPensionsAnnuitiesAsset ManagementUnderwritingCarrierBrokersPartner GatedNo Public APIDesign SystemAgent SkillsOpen-Source
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
CanopyDesignSystem@landg.com

Source

Vulnerability Disclosure

legal-and-general-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
scope: >-
  Legal & General publishes NO corporate vulnerability disclosure policy, no
  security.txt and no bug bounty programme. The only published security-reporting
  route found anywhere on its public surface is the SECURITY.md of the Canopy
  design-system repository in its GitHub organisation. That is what is recorded
  here, and its narrow scope is stated so it is not mistaken for a company-wide
  VDP.
policy:
- https://github.com/Legal-and-General/canopy/blob/master/docs/SECURITY.md
contact:
- CanopyDesignSystem@landg.com
reporting_mechanism: >-
  Open a draft GitHub security advisory on Legal-and-General/canopy to discuss
  impact and remediation privately. For extenuating circumstances (e.g. needing
  a patch release on an older line) contact CanopyDesignSystem@landg.com.
supported_versions: >-
  Mainline branch only. Security patches are fixed forward; consumers must
  upgrade to the latest version and may have to apply documented breaking
  changes.
bug_bounty:
  present: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  note: no Legal & General programme found on any public bug-bounty platform
security_txt:
  present: false
  probes:
  - {url: 'https://www.legalandgeneral.com/.well-known/security.txt', status: 404}
  - {url: 'https://group.legalandgeneral.com/.well-known/security.txt', status: 404}
  - {url: 'https://am.landg.com/.well-known/security.txt', status: 404}
  - {url: 'https://www.landg.com/.well-known/security.txt', status: 404}
  - {url: 'https://www.legalandgeneral.com/security.txt', status: 404}
corporate_disclosure:
  present: false
  probes:
  - {url: 'https://www.legalandgeneral.com/responsible-disclosure', status: 404}
  - url: https://www.legalandgeneral.com/security/
    status: 200
    note: >-
      Customer-facing security information only — encryption in transit, email
      security, phishing awareness, third-party links, password guidance. No
      security@ address, no responsible-disclosure policy, no bug bounty and no
      certifications named. The only contact given is the general customer line
      0800 096 6959.
evidence:
- source: https://github.com/Legal-and-General/canopy/blob/master/docs/SECURITY.md
  kind: repository security policy
  verbatim: security/legal-and-general-canopy-security-policy.md
- source: https://www.legalandgeneral.com/security/
  kind: customer security page (no disclosure route)
- source: https://github.com/Legal-and-General/canopy/actions/workflows/codeql_analysis.yml
  kind: CodeQL analysis runs on the Canopy repository (badge on repo README)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/legal-and-general-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.