generated: '2026-08-13' method: probed probe: true source: https://www.google.com/.well-known/security.txt note: >- No PageSpeed API host serves a security.txt (all 404 — see well-known/google-pagespeed-well-known.yml). Google serves an RFC 9116 security.txt at the apex of google.com, the parent registrable domain of developers.google.com, and it covers Google properties generally, including the PageSpeed Insights API. The automated probe (probe-security-programs.py) missed this because it only walks the API/portal hosts named in apis.yml. policy: - https://g.co/vrp contact: - mailto:security@google.com - https://g.co/vulnz acknowledgments: - https://bughunters.google.com/ encryption: - https://services.google.com/corporate/publickey.txt expires: '2030-04-01T00:00:00Z' bug_bounty: program: Google Vulnerability Reward Program (VRP) url: https://bughunters.google.com/ self_hosted: true platform: null note: Google runs its own bug bounty platform rather than HackerOne/Bugcrowd/Intigriti. evidence: - {source: https://www.google.com/.well-known/security.txt, http_status: 200, content_type: text/plain, kind: security.txt} - {source: https://bughunters.google.com/, http_status: 200, kind: bug-bounty-program} - {source: https://developers.google.com/.well-known/security.txt, http_status: 404, kind: negative} - {source: https://pagespeedonline.googleapis.com/.well-known/security.txt, http_status: 404, kind: negative} maintainers: - FN: Kin Lane email: kin@apievangelist.com