
John Hancock
External Program
Submit bugs directly to this organization


External Program
Submit bugs directly to this organization
John Hancock’s mission is to make decisions easier and lives better. We are putting customers first and improving how our customers interact with us to ensure we exceed their expectations. We’re focused on delivering solutions that are simple, intuitive, and fast, and we are using digitization and innovation to do so. Protecting our systems and information is at the foundation of achieving this mission.
If you have information related to security vulnerabilities of our systems or services, please submit a report in accordance with the guidelines below. Thank you for your support in protecting John Hancock, our customers, our employees, and our shareholders.
John Hancock will make a best effort to meet the following response targets for hackers participating in our program:
| Type of Response | SLA in business days |
|---|---|
| First Response | 2 business days |
| Time to Triage | 10 business days |
| Time to Resolution | depends on severity and complexity |
We’ll try to keep you informed about our progress throughout the process.
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep John Hancock and our users safe!