generated: '2026-07-25' method: searched probe: false source: https://www.empower.com/financial-professionals/about-empower/cybersecurity url: https://www.empower.com/financial-professionals/about-empower/cybersecurity note: >- The mechanical probe (0-working/probe-security-programs.py) found nothing: no trust. host, no security. host and no /trust or /compliance path on greatwestlifeco.com or empower.com. The group's published security and compliance posture instead lives on the Empower Cybersecurity page, which names a third-party attestation and three control frameworks explicitly. That page is recorded here as the group's trust surface, with the caveat that it belongs to the U.S. retirement subsidiary - Great-West Lifeco itself and Canada Life publish no equivalent. entity: Empower (U.S. retirement subsidiary of Great-West Lifeco) scope: subsidiary certifications: - name: SOC 2 Type 2 status: attested evidence: '"Unqualified SOC 2 Type 2 third-party attestation"' - name: ISO 27001 status: aligned evidence: '"Cybersecurity policies aligned with NIST 800-53, NIST CSF, and ISO 27001"' - name: NIST 800-53 status: aligned evidence: '"Cybersecurity policies aligned with NIST 800-53, NIST CSF, and ISO 27001"' - name: NIST CSF status: aligned evidence: '"Cybersecurity policies aligned with NIST 800-53, NIST CSF, and ISO 27001"' - name: OWASP status: aligned evidence: '"Application security testing (SAST/DAST) aligned to OWASP standards"' not_claimed: - PCI DSS - HITRUST - FedRAMP - CSA STAR - ISO 27017 - ISO 27018 governance: - Enterprise risk management framework - Information security policies reviewed at least once a year and approved by the Information Security Board, including the CISO and company leadership - Regulatory supervision and audit oversight (internal and external audit) - Annual risk assessments - Formal AI Governance Committee, AI Risk Management Policy and Standards, documented AI risk assessments related_pages: - name: Empower Security Center url: https://participant.empower-retirement.com/participant/#/articles/securityCenter detail: >- Consumer-facing security tips and the Empower security guarantee - account protection guidance, not a compliance artifact repository. - name: Great-West Lifeco Internet Security Statement url: https://www.greatwestlifeco.com/internet-security.html detail: >- Holding-company consumer statement covering encryption, cookies, 25-minute session timeouts and phishing. Names no certification and no security contact. evidence: - source: https://www.empower.com/financial-professionals/about-empower/cybersecurity keywords: [soc 2 type 2, iso 27001, nist 800-53, nist csf, owasp, penetration testing, independent audits] fetched: '2026-07-25' status: 200 transparency_gaps: - No downloadable or NDA-gated artifact repository (no SOC 2 report request flow published). - No sub-processor list. - No uptime/SLA commitment. - No vulnerability disclosure or bug bounty program - see security/great-west-lifeco-domain-security.yml and the well-known index.