generated: '2026-09-02' method: probed source: probe-security-programs.py plus direct probes of every Verily host, 2026-09-02 name: Verily Life Sciences — vulnerability disclosure program_found: false summary: >- No vulnerability disclosure program could be found on any Verily surface. This is an honest absence, and it is a real gap for a company handling clinical and genomic data: a researcher who finds a flaw in Verily Workbench has no published channel to report it to. probes: - url: https://verily.com/.well-known/security.txt status: 404 - url: https://workbench.verily.com/.well-known/security.txt status: 200 result: SPA HTML shell, not a security.txt - url: https://support.workbench.verily.com/.well-known/security.txt status: 404 - url: https://verily.com/security status: 404 - url: https://verily.com/security-trust status: 200 result: trust page present, but no vulnerability reporting section or security contact findings: security_txt: none bug_bounty: none found (no HackerOne, Bugcrowd or Intigriti program located for Verily) disclosure_page: none security_contact: >- None dedicated. The Security & Trust page routes all security correspondence to the general info@verily.com address. note_on_pointer: >- No `Security` pointer is emitted in apis.yml. security_disclosure asserts the provider publishes a disclosure channel, and Verily publishes none. caveat: >- Verily is an Alphabet company. No evidence was found that Verily domains are in scope for Google's Vulnerability Reward Program, and this profile does not assert that they are — an unverified inference about a security reporting channel would be worse than recording the gap.