generated: '2026-09-14' method: searched source: https://www.primerica.com/public/privacy/primerica-responsible-disclosure-practice.html specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Primerica providerId: primerica description: >- Primerica publishes a Responsible Disclosure Practice with a dedicated intake mailbox. The page is live and reachable without credentials, but it is not linked from any /.well-known/security.txt and is buried under /public/privacy/, which is why an automated security.txt-first probe misses it. present: true program: name: Primerica Responsible Disclosure Practice url: https://www.primerica.com/public/privacy/primerica-responsible-disclosure-practice.html http_status: 200 contact_email: responsible.disclosure@primerica.com contact_verbatim: Please email your message and any attachments to responsible.disclosure@primerica.com intake: email required_report_contents: - A description of the issue and where it is located. - A description of the steps required to reproduce the issue. scope_statement: >- "If you believe you've found a security issue in one of our products or services, please send it to us" — product and service scope is stated in prose only; no asset list, in-scope domain list or out-of-scope list is published. safe_harbor: offered: false verbatim: >- "Please note that this should not be construed as encouragement or permission to perform any of the following activities: Hack, penetrate, or otherwise attempt to gain unauthorized access to Primerica applications, systems, or data in violation of applicable law; Download, copy, disclose or use any proprietary or confidential Primerica data, including customer data; and Adversely impact Primerica or the operation of any Primerica applications or systems. Primerica does not waive any rights or claims with respect to such activities." note: >- The policy explicitly declines to grant safe harbour and reserves all rights and claims. This is a disclosure intake channel, not an authorised-testing programme. bug_bounty: offered: false platform: null note: No HackerOne, Bugcrowd or Intigriti programme was found for primerica.com. pgp_key: null response_sla: null hall_of_fame: false gaps: - id: no-security-txt detail: >- https://www.primerica.com/.well-known/security.txt returns the site's soft-200 catch-all error page. Publishing an RFC 9116 security.txt naming responsible.disclosure@primerica.com and this policy URL would make the programme machine-discoverable; the contact already exists. - id: no-safe-harbor detail: >- Researchers are asked to report but given no legal assurance, which measurably suppresses reports. maintainers: - FN: Kin Lane email: kin@apievangelist.com