generated: '2026-06-20' method: searched probe: true source: https://www.google.com/.well-known/security.txt policy: - https://g.co/vrp contact: - mailto:security@google.com - https://g.co/vulnz acknowledgments: - https://bughunters.google.com/ encryption: - https://services.google.com/corporate/publickey.txt bug_bounty: program: Google Vulnerability Reward Program (VRP) url: https://bughunters.google.com/ scope_includes_android: true evidence: - source: well-known/google-android-security.txt kind: security.txt fields: [Contact, Policy, Acknowledgments, Encryption] - source: https://bughunters.google.com/ kind: bug-bounty-portal notes: >- Google runs a single org-wide Vulnerability Reward Program covering Android, Google Play, and Google Cloud APIs. Android-specific rewards are documented at https://bughunters.google.com/about/rules/android-friends. Disclosure policy is published in the RFC 9116 security.txt served from www.google.com.