generated: '2026-07-25' method: searched probe: true program: false program_note: >- Canada Life runs no researcher-facing vulnerability disclosure program. There is no security.txt on any host, no bug bounty on HackerOne, Bugcrowd or Intigriti, no /responsible-disclosure or /vulnerability-disclosure page, and no safe-harbour language anywhere on canadalife.com. What does exist is a consumer-facing security and fraud reporting channel, recorded below so the distinction is explicit rather than implied. bug_bounty: null safe_harbour: false security_txt: false policy: - https://www.canadalife.com/internet-security.html contact: - corporateinvestigations@canadalife.com - '1-877-751-3417' - https://www.canadalife.com/contact-us/fraud-complaints/fraud-concerns/corporate-investigations.html channels: - name: Internet security url: https://www.canadalife.com/internet-security.html status: 200 kind: security-practices-page covers: >- Published security practices — SSL encryption on the online portals, 25-minute inactivity auto-logout, monitoring and anti-malware — plus instructions to report phishing, suspicious email, and fraudulent websites to the Corporate Investigations team. omits: >- No multi-factor authentication commitment, no named certification (SOC 2, ISO 27001, PCI DSS), no researcher disclosure process, no PGP key. - name: Contact Corporate Investigations url: https://www.canadalife.com/contact-us/fraud-complaints/fraud-concerns/corporate-investigations.html status: 200 kind: report-form contact_email: corporateinvestigations@canadalife.com contact_phone: '1-877-751-3417' accepts: General fraud-related concerns; submissions may be anonymous. published_caveat: >- "The security of email communication cannot be guaranteed at this time. Any person wishing to communicate or send information of a private or confidential nature to Canada Life is encouraged to do so by calling 1-877-751-3417." - name: Fraud prevention url: https://www.canadalife.com/fraud-prevention.html status: 200 kind: consumer-awareness - name: Benefits fraud tips line url: https://www.canadalife.com/fraud-prevention.html kind: confidential-tips-line note: >- Separate confidential line for health and dental benefits fraud or misuse, named on the Corporate Investigations form. incident_disclosure: practices_public_notification: true evidence: - url: https://www.canadalife.com/about-us/news-highlights/news/canada-life-recently-identified-a-cyber-incident.html date: '2026-04' note: Initial public notice of a cyber incident identified in mid-April 2026. - url: https://www.canadalife.com/about-us/news-highlights/news/update-on-recent-cyber-incident.html date: '2026-05' note: >- Follow-up notice. States the incident was fully contained with no evidence of ongoing unauthorized activity, that impacted individuals were notified, and that credit monitoring was offered at no cost. Reported publicly as unauthorized access through a single employee account. assessment: >- Canada Life does publish dated incident notices on its own newsroom, which is a real transparency signal. It is a breach-notification practice, not a vulnerability disclosure policy, and the two are recorded separately here. evidence: - source: https://www.canadalife.com/internet-security.html kind: security-page status: 200 keywords: [encryption, ssl, report, phishing, corporate investigations] - source: https://www.canadalife.com/contact-us/fraud-complaints/fraud-concerns/corporate-investigations.html kind: contact-form status: 200 keywords: [corporateinvestigations@canadalife.com, 1-877-751-3417] - source: https://api.canadalife.com/.well-known/security.txt kind: security.txt status: 404 - source: https://www.canadalife.com/.well-known/security.txt kind: security.txt status: 404