generated: '2026-08-30' method: searched source: https://www.aig.com/home/about/cyber-and-information-security/vulnerability-disclosure provider: AIG providerId: aig program: exists: true name: AIG Vulnerability Disclosure Program policy_url: https://www.aig.com/home/about/cyber-and-information-security/vulnerability-disclosure policy_status: 200 platform: HackerOne submission_url: https://hackerone.com/aig submission_status: 200 scope_statement: >- "If you believe you've found a security issue in one of AIG's applications, services, products, websites, or systems, please submit a report following program rules and guidelines through the AIG HackerOne platform." — AIG's Vulnerability Disclosure Program page, fetched 2026-08-30. bug_bounty: unknown bounty_note: >- AIG's own page describes a structured disclosure framework and does not state whether awards are paid; the HackerOne program page is the authority and was not parsed for bounty terms. security_txt: false security_txt_note: >- /.well-known/security.txt returns HTTP 403 on www.aig.com — the edge denies every /.well-known path — so the program is discoverable only through the site page and HackerOne, not through RFC 9116 machine-readable discovery. Publishing a security.txt pointing at https://hackerone.com/aig would close that gap. contact_page: https://www.aig.com/home/about/cyber-and-information-security related: - url: https://www.aig.com/home/about/cyber-and-information-security title: AIG Cyber and Information Security status: 200