generated: '2026-09-02' method: searched source: https://www.american-equity.com/security-disclosure name: American Equity Security Disclosure summary: >- American Equity publishes a public, unauthenticated Security Disclosure page that invites anyone to report a potential security issue found on an American Equity company website. Intake is a web form on that page — the company states it will review the submission and contact the reporter with further questions or information. program: published: true url: https://www.american-equity.com/security-disclosure http_status: 200 discovered_via: https://www.american-equity.com/sitemap.xml intake: web-form authentication_required: false scope_stated: >- "a potential security issue on an American Equity company website" — website scope only. No API, mobile, or infrastructure scope is enumerated. bug_bounty: false bounty_platform: null safe_harbor_stated: false pgp_key: null security_txt: false security_txt_note: >- /.well-known/security.txt returns 404 on every American Equity host, so the disclosure page is not machine-discoverable. Publishing an RFC 9116 security.txt pointing its Policy: field at https://www.american-equity.com/security-disclosure would make this existing program discoverable to automated scanners with no new process. response_commitment: >- "We will review and contact you with further questions or information." No SLA or triage window is stated. contacts: - purpose: security-disclosure method: web-form url: https://www.american-equity.com/security-disclosure - purpose: compliance-and-privacy method: email value: compliance@american-equity.com source: https://www.american-equity.com/privacy note: >- Published on the privacy policy for privacy/compliance matters, not designated as the security reporting channel. Recorded for completeness, not as a vulnerability contact. observations: - >- The disclosure form itself is client-side rendered — the served HTML for /security-disclosure contains the policy prose but no