Early access: the directory is still filling out, and every rating here is a reported experience.
GO

Self-hosted security programme

Google

Google runs Bug Hunters, its own reporting and reward platform, covering Google, Chrome, Android and the open source it maintains. There is no profile to claim here.

Rewards are set by a panel against a published table, and the amount turns on report quality as much as severity: a clear reproduction routinely lands higher than the same bug described loosely.

Direct How to report
In-house Triage
Panel Reward decisions
Bug Hunters Where credit lands

Featured write-up

The Program with Massive Surface Area, Fair Triage, and Great Scope Alignment

“Majorly I participate in Google VRP mostly as a casual and daily user rather than doing dedicated, aggressive bug hunting. Most of the security flaws I have reported came from normal day to day usage of Google products rather than active deep scanning. The sheer size of the target surface means anyone with a security mindset can spot imp…”

SS SSP
Read the write-up ★★★★★ · August 2026

Getting credit

Report to Google, claim it here

Credit publishes in Google’s own advisories, often months after the report. We index those, so it is waiting for you, including recognitions that carry no CVE and appear nowhere else.

Google

Internet services · USA

google.com →

Found a vulnerability?

Google runs its own vulnerability reporting process. Here are your two ways to report it. We recommend the first.

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Programs