generated: '2026-07-25' method: searched probe: true scope: >- Legal & General publishes NO corporate vulnerability disclosure policy, no security.txt and no bug bounty programme. The only published security-reporting route found anywhere on its public surface is the SECURITY.md of the Canopy design-system repository in its GitHub organisation. That is what is recorded here, and its narrow scope is stated so it is not mistaken for a company-wide VDP. policy: - https://github.com/Legal-and-General/canopy/blob/master/docs/SECURITY.md contact: - CanopyDesignSystem@landg.com reporting_mechanism: >- Open a draft GitHub security advisory on Legal-and-General/canopy to discuss impact and remediation privately. For extenuating circumstances (e.g. needing a patch release on an older line) contact CanopyDesignSystem@landg.com. supported_versions: >- Mainline branch only. Security patches are fixed forward; consumers must upgrade to the latest version and may have to apply documented breaking changes. bug_bounty: present: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] note: no Legal & General programme found on any public bug-bounty platform security_txt: present: false probes: - {url: 'https://www.legalandgeneral.com/.well-known/security.txt', status: 404} - {url: 'https://group.legalandgeneral.com/.well-known/security.txt', status: 404} - {url: 'https://am.landg.com/.well-known/security.txt', status: 404} - {url: 'https://www.landg.com/.well-known/security.txt', status: 404} - {url: 'https://www.legalandgeneral.com/security.txt', status: 404} corporate_disclosure: present: false probes: - {url: 'https://www.legalandgeneral.com/responsible-disclosure', status: 404} - url: https://www.legalandgeneral.com/security/ status: 200 note: >- Customer-facing security information only — encryption in transit, email security, phishing awareness, third-party links, password guidance. No security@ address, no responsible-disclosure policy, no bug bounty and no certifications named. The only contact given is the general customer line 0800 096 6959. evidence: - source: https://github.com/Legal-and-General/canopy/blob/master/docs/SECURITY.md kind: repository security policy verbatim: security/legal-and-general-canopy-security-policy.md - source: https://www.legalandgeneral.com/security/ kind: customer security page (no disclosure route) - source: https://github.com/Legal-and-General/canopy/actions/workflows/codeql_analysis.yml kind: CodeQL analysis runs on the Canopy repository (badge on repo README)