generated: '2026-09-14' method: searched source: https://www.aig.com/home/about/cyber-and-information-security/vulnerability-disclosure scope_note: >- AIG Aerospace is a line of business inside American International Group, Inc. and runs no security program of its own. The disclosure program recorded here is AIG's enterprise program, which states its scope as AIG's "applications, services, products, websites, or systems" — language that covers the aig.com aerospace pages, the aerospace claims intake at www-249.aig.com and the myAIG broker portal. Recorded on this record for that reason, not because AIG Aerospace publishes a separate policy. program: present: true name: AIG Vulnerability Disclosure Program policy_url: https://www.aig.com/home/about/cyber-and-information-security/vulnerability-disclosure policy_status: 200 submission_channel: hackerone submission_url: https://hackerone.com/aig submission_status: 200 bounty: false bounty_note: >- The policy thanks researchers for contributions but names no monetary reward, so this is a disclosure program rather than a paid bug bounty. security_txt: false security_txt_note: >- No /.well-known/security.txt is served on any AIG host probed — see well-known/aig-aerospace-well-known.yml. The policy is discoverable only as an HTML page. contact_email: null contact_email_note: The policy page publishes no direct security mailbox; HackerOne is the only named channel. rules: - Do not engage in any activity that can stop or degrade AIG's services or assets. - Do not engage in any activity that violates federal or state laws or regulations, or the laws or regulations of any country. - Reports must carry enough detail for AIG to reproduce and validate the issue. safe_harbor: stated: false note: >- The page sets conditions of testing and says any testing or reporting constitutes agreement to its terms, but it does not publish an explicit safe-harbor or non-prosecution clause.