Primerica · Vulnerability Disclosure

Primerica Vulnerability Disclosure

Vulnerability disclosure

Primerica publishes a Responsible Disclosure Practice with a dedicated intake mailbox. The page is live and reachable without credentials, but it is not linked from any /.well-known/security.txt and is buried under /public/privacy/, which is why an automated security.txt-first probe misses it.

Primerica runs a coordinated vulnerability disclosure program on Hackerone.

InsuranceFinancial ServicesLife InsuranceIdentityAuthenticationOpenID ConnectAPI Gateway
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

primerica-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-14'
method: searched
source: https://www.primerica.com/public/privacy/primerica-responsible-disclosure-practice.html
specification: API Commons Vulnerability Disclosure
specificationVersion: '0.1'
provider: Primerica
providerId: primerica
description: >-
  Primerica publishes a Responsible Disclosure Practice with a dedicated intake mailbox. The page is
  live and reachable without credentials, but it is not linked from any /.well-known/security.txt and
  is buried under /public/privacy/, which is why an automated security.txt-first probe misses it.
present: true
program:
  name: Primerica Responsible Disclosure Practice
  url: https://www.primerica.com/public/privacy/primerica-responsible-disclosure-practice.html
  http_status: 200
  contact_email: responsible.disclosure@primerica.com
  contact_verbatim: Please email your message and any attachments to responsible.disclosure@primerica.com
  intake: email
  required_report_contents:
    - A description of the issue and where it is located.
    - A description of the steps required to reproduce the issue.
  scope_statement: >-
    "If you believe you've found a security issue in one of our products or services, please send it to
    us" — product and service scope is stated in prose only; no asset list, in-scope domain list or
    out-of-scope list is published.
  safe_harbor:
    offered: false
    verbatim: >-
      "Please note that this should not be construed as encouragement or permission to perform any of the
      following activities: Hack, penetrate, or otherwise attempt to gain unauthorized access to Primerica
      applications, systems, or data in violation of applicable law; Download, copy, disclose or use any
      proprietary or confidential Primerica data, including customer data; and Adversely impact Primerica
      or the operation of any Primerica applications or systems. Primerica does not waive any rights or
      claims with respect to such activities."
    note: >-
      The policy explicitly declines to grant safe harbour and reserves all rights and claims. This is a
      disclosure intake channel, not an authorised-testing programme.
  bug_bounty:
    offered: false
    platform: null
    note: No HackerOne, Bugcrowd or Intigriti programme was found for primerica.com.
  pgp_key: null
  response_sla: null
  hall_of_fame: false
gaps:
  - id: no-security-txt
    detail: >-
      https://www.primerica.com/.well-known/security.txt returns the site's soft-200 catch-all error page.
      Publishing an RFC 9116 security.txt naming responsible.disclosure@primerica.com and this policy URL
      would make the programme machine-discoverable; the contact already exists.
  - id: no-safe-harbor
    detail: >-
      Researchers are asked to report but given no legal assurance, which measurably suppresses reports.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/primerica-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.