Manulife’s mission is to make decisions easier and lives better. We are putting customers first and improving how our customers interact with us to ensure we exceed their expectations. We’re focused on delivering solutions that are simple, intuitive, and fast, and we are using digitization and innovation to do so. Protecting our systems and information is at the foundation of achieving this mission.
If you have information related to security vulnerabilities of our systems or services, please submit a report in accordance with the guidelines below. Thank you for your support in protecting Manulife, our customers, our employees, and our shareholders.
Response Targets
Manulife will make a best effort to meet the following response targets for hackers participating in our program:
| Type of Response | SLA in business days |
|---|
| First Response | 2 business days |
| Time to Triage | 10 business days |
| Time to Resolution | depends on severity and complexity |
We’ll try to keep you informed about our progress throughout the process.
Disclosure Policy
- We do not publicly disclose reports at this time.
- We ask that you do not discuss the contents of reports you may have submitted (even resolved ones) outside of the program without express consent from Manulife.
- Follow HackerOne's disclosure guidelines.
Program Rules
- Please provide detailed reports with reproducible steps.
- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
- Social engineering (e.g. phishing, vishing, smishing) is prohibited.
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with the explicit permission of the account holder.
In Scope
- Security vulnerabilities that are identified in Manulife products or in website domains owned, operated, or controlled by Manulife are in scope, excluding those listed as out of scope.
Out of scope vulnerabilities
When reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) security impact of the bug. The following issues are considered out of scope:
- Clickjacking on pages with no sensitive actions
- Unauthenticated/logout/login CSRF.
- Attacks requiring MITM or physical access to a user's device.
- Previously known vulnerable libraries without a working Proof of Concept.
- Comma Separated Values (CSV) injection without demonstrating a vulnerability.
- Missing best practices in SSL/TLS configuration.
- Any activity that could lead to the disruption of our service (DoS).
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
Safe Harbor
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep Manulife and our users safe!