7 Total
2 High severity
1 Medium severity
4 Low severity

Key Facts

What may publication of security research findings prior to remediation of the issue put at risk?
Progressive states that publication of security research findings prior to remediation of the issue may put personal information at risk.
What does Progressive ask security researchers to do with their findings?
Progressive asks security researchers to keep their findings confidential.
What does Progressive require security issue reports to include?
Progressive requires security issue reports to include specific detail, such as the date and time the issue was first discovered, details needed to reproduce the issue, and a Proof of Concept.
What option does Progressive offer to submit security reports securely?
Progressive offers the option to use PGP encryption with Progressive's Public PGP Key to submit security reports securely.
What does Progressive state is helpful for reporters to include with each security report?
Progressive states that it is helpful for reporters to include their name and contact information with each security report.
Where does Progressive ask recipients of suspicious emails purportedly from Progressive to forward those emails?
Progressive asks recipients of suspicious emails purportedly from Progressive to forward those emails to phishing@email.progressive.com.
Stay ahead of the changes
Track Progressive and get the diff the day its terms change.
Summary

This document explains how to report security vulnerabilities or suspicious emails to Progressive. If you find a security issue, Progressive asks you to keep it confidential and submit a detailed report — including when you found it, how to reproduce it, and a Proof of Concept. Progressive will try to respond within 10 business days, though that is not a guarantee.

Analysis

This document establishes Progressive's security vulnerability disclosure framework, setting out the obligations and expectations that govern security researchers and reporters who interact with Progressive. Progressive requires security reports to include specific detail — the date and time of discovery, reproduction steps, and a Proof of Concept — and asks that findings be kept confidential until remediation is complete, framing pre-remediation publication as a risk to personal information. Progressive offers PGP encryption as a secure submission channel, treats reporter identification as advisory rather than mandatory, and states it will attempt to respond to reports within 10 business days, a goal rather than a guaranteed commitment. A separate reporting channel is designated for suspected phishing emails.

What this means for you

For an individual user, this document primarily establishes where and how to report security concerns to Progressive. If you discover a security vulnerability, Progressive asks you to keep it confidential and submit a detailed report with specific information about the issue. If you receive a suspicious email that appears to be from Progressive, you can forward it directly to phishing@email.progressive.com. You are not required to include your name or contact information with a security report, as Progressive treats that as helpful but optional.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity
Featured, Low severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

7 provisions
7 featured
3 clause types
2 high severity
Restricted or Prohibited Content/Industries 1 1 high
Stay ahead of the changes

Monitoring

Progressive has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Pre-remediation publication puts data at risk and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:23 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000599
Version ID CA-V-001272
SHA-256 065d1594cbae0d7723b4288e55c5d261d71a8f0ed12e30cebcc51236761f790d
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans