generated: '2026-09-02' method: probed source: https://www.greatamericaninsurancegroup.com/.well-known/security.txt program: published: true type: vulnerability-disclosure-program name: GAIG Vulnerability Disclosure Program policy_url: https://vdp.gaig.com contact: vulnerability@gaig.com bug_bounty: false bounty_platform: null security_txt: served: true hosts: - www.greatamericaninsurancegroup.com - www.gaig.com path: /.well-known/security.txt file: well-known/american-financial-group-security.txt fields: Policy: https://vdp.gaig.com Contact: vulnerability@gaig.com missing_recommended_fields: - Expires - Preferred-Languages - Encryption note: >- RFC 9116 makes Expires REQUIRED. The served file carries only Policy and Contact, so it is a valid disclosure signal but not a fully conformant security.txt. evidence: - url: https://www.greatamericaninsurancegroup.com/.well-known/security.txt status: 200 content_type: text/plain - url: https://www.gaig.com/.well-known/security.txt status: 200 content_type: text/plain - url: https://vdp.gaig.com status: 200 note: HTML wrapper that embeds GAIG_VDP_v2.pdf — the policy itself is published as a PDF - url: https://www.afginc.com/.well-known/security.txt status: 403 note: edge policy answers Access Denied to non-browser clients on every path