Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document explains how to report security vulnerabilities or suspicious emails to Progressive. If you find a security issue, Progressive asks you to keep it confidential and submit a detailed report — including when you found it, how to reproduce it, and a Proof of Concept. Progressive will try to respond within 10 business days, though that is not a guarantee.
This document establishes Progressive's security vulnerability disclosure framework, setting out the obligations and expectations that govern security researchers and reporters who interact with Progressive. Progressive requires security reports to include specific detail — the date and time of discovery, reproduction steps, and a Proof of Concept — and asks that findings be kept confidential until remediation is complete, framing pre-remediation publication as a risk to personal information. Progressive offers PGP encryption as a secure submission channel, treats reporter identification as advisory rather than mandatory, and states it will attempt to respond to reports within 10 business days, a goal rather than a guaranteed commitment. A separate reporting channel is designated for suspected phishing emails.
For an individual user, this document primarily establishes where and how to report security concerns to Progressive. If you discover a security vulnerability, Progressive asks you to keep it confidential and submit a detailed report with specific information about the issue. If you receive a suspicious email that appears to be from Progressive, you can forward it directly to phishing@email.progressive.com. You are not required to include your name or contact information with a security report, as Progressive treats that as helpful but optional.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Progressive has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Pre-remediation publication puts data at risk and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.