generated: '2026-09-02' method: searched source: https://www.aig.com/home/about/cyber-and-information-security/vulnerability-disclosure provider: American International Group (AIG) providerId: american-international program: exists: true name: AIG Vulnerability Disclosure Program policy_url: https://www.aig.com/home/about/cyber-and-information-security/vulnerability-disclosure policy_status: 200 platform: HackerOne submission_url: https://hackerone.com/aig submission_status: 200 scope_statement: >- "If you believe you've found a security issue in one of AIG's applications, services, products, websites, or systems, please submit a report following program rules and guidelines through the AIG HackerOne platform." — AIG Vulnerability Disclosure Program page, fetched 2026-09-02. rules_published: true rules_summary: - Do not engage in any activity that can stop or degrade AIG's services or assets. - >- Do not engage in any activity that violates federal or state laws or regulations, or the laws of any country where the data, assets or systems reside, where traffic is routed, or where the researcher is conducting research. bug_bounty: unknown bounty_note: >- AIG's own page describes a structured disclosure framework and does not state whether awards are paid. The HackerOne program page is the authority on bounty terms and was not parsed here. security_txt: false security_txt_note: >- /.well-known/security.txt returns HTTP 403 on www.aig.com and on commercial.api.aig.com — the edge denies the whole /.well-known/ prefix — so the program is discoverable only through the website page and HackerOne, never through RFC 9116 machine-readable discovery. Publishing a security.txt with `Policy:` and `Contact: https://hackerone.com/aig` would close that gap at essentially zero cost. contact_page: https://www.aig.com/home/about/cyber-and-information-security related: - url: https://www.aig.com/home/about/cyber-and-information-security title: AIG Cyber and Information Security status: 200