generated: '2026-09-02' method: searched source: https://www.american-equity.com/security-disclosure name: American Equity Security Disclosure summary: >- American Equity publishes a public, unauthenticated Security Disclosure page that invites anyone to report a potential security issue found on an American Equity company website. Intake is a web form on that page — the company states it will review the submission and contact the reporter with further questions or information. program: published: true url: https://www.american-equity.com/security-disclosure http_status: 200 discovered_via: https://www.american-equity.com/sitemap.xml intake: web-form authentication_required: false scope_stated: >- "a potential security issue on an American Equity company website" — website scope only. No API, mobile, or infrastructure scope is enumerated. bug_bounty: false bounty_platform: null safe_harbor_stated: false pgp_key: null security_txt: false security_txt_note: >- /.well-known/security.txt returns 404 on every American Equity host, so the disclosure page is not machine-discoverable. Publishing an RFC 9116 security.txt pointing its Policy: field at https://www.american-equity.com/security-disclosure would make this existing program discoverable to automated scanners with no new process. response_commitment: >- "We will review and contact you with further questions or information." No SLA or triage window is stated. contacts: - purpose: security-disclosure method: web-form url: https://www.american-equity.com/security-disclosure - purpose: compliance-and-privacy method: email value: compliance@american-equity.com source: https://www.american-equity.com/privacy note: >- Published on the privacy policy for privacy/compliance matters, not designated as the security reporting channel. Recorded for completeness, not as a vulnerability contact. observations: - >- The disclosure form itself is client-side rendered — the served HTML for /security-disclosure contains the policy prose but no
element, so the intake fields exist only after script execution. - >- No bug bounty program was found on HackerOne, Bugcrowd or Intigriti under the American Equity, Eagle Life or American Equity Investment Life brands. evidence: - url: https://www.american-equity.com/security-disclosure status: 200 note: responsible-disclosure policy + reporting form - url: https://www.american-equity.com/security-disclosure/ status: 308 note: trailing-slash form 308s to the canonical path - url: https://www.american-equity.com/.well-known/security.txt status: 404 - url: https://register.american-equity.com/.well-known/security.txt status: 404 - url: https://api.american-equity.com/.well-known/security.txt status: 403