generated: '2026-08-29' method: probed source: direct probes of G2's security, legal and well-known surfaces provider: G2 providerId: g2 checked: '2026-08-29' program_published: false summary: >- No public vulnerability disclosure program was found. G2 serves no security.txt on any host, publishes no /security page, and has no listing on the two largest bug bounty platforms. A researcher has no published, non-sales channel to report a vulnerability. probes: - url: https://www.g2.com/.well-known/security.txt status: 404 - url: https://data.g2.com/.well-known/security.txt status: 404 - url: https://documentation.g2.com/.well-known/security.txt status: 404 - url: https://company.g2.com/.well-known/security.txt status: 404 - url: https://company.g2.com/security status: 404 - url: https://legal.g2.com/security status: 404 - url: https://hackerone.com/g2 status: 404 - url: https://bugcrowd.com/g2 status: 404 partial: trust_center: https://trust.g2.com/ note: >- A trust center exists and lists certifications (security/g2-trust-center.yml), but it is a compliance-evidence portal, not a disclosure policy. No Contact, Policy or Encryption directive is published anywhere, so no Security pointer is emitted in apis.yml — the pointer would assert a disclosure surface G2 does not serve. maintainers: - FN: Kin Lane email: kin@apievangelist.com