5 unchanged sentences
Our products and services reach billions of users and involve the collection, storage, processing, and transmission of a large amount of data.
−Removed: In addition, our business and operations span numerous geographies around the world, involve thousands of employees, contractors, vendors, developers, partners, and other third parties, and rely on software and hardware that is highly technical and complex.
+Added: In addition, our business and operations span numerous geographies around the world, involve thousands of employees, contractors, vendors, developers,
+Added: partners, and other third parties, and rely on software and hardware that is highly technical and complex.
+Added: Our cybersecurity environment continues to evolve, including as we develop and deploy AI models, tools, and other applications and increase our use of public cloud and other third-party services.
We maintain an information security program that is comprised of policies and controls designed to mitigate cybersecurity risk.
5 unchanged sentences
We also engage third-party security experts and consultants to assist with assessment and enhancement of our cybersecurity risk management processes, as well as benchmarking against industry practices.
−Removed: However, we may not be successful in fully addressing such areas for remediation or enhancement.
+Added: In addition, we operate a Bug Bounty program that invites independent cybersecurity researchers to investigate and explore potential security vulnerabilities in our products and report their findings to us.
+Added: However, we may not be successful in fully addressing any such areas for remediation or enhancement.
In addition, we maintain a privacy risk management program to assess privacy risks related to how we are collecting, using, sharing, and storing user data, which is subject to assessment by an independent, third-party privacy assessor.
Our internal audit function provides independent assessment and assurance on the overall operations of our cybersecurity and privacy programs and the supporting control frameworks.
−Removed: These processes
−Removed: support informed risk-based decision-making and prioritization of cybersecurity countermeasures and risk mitigation strategies.
+Added: These processes support informed risk-based decision-making and prioritization of cybersecurity countermeasures and risk mitigation strategies.
Our risk mitigation strategies include a broad variety of technical and operational measures, as well as annual cybersecurity and privacy training for all of our employees.
2 unchanged sentences
We also generally require third parties to, among other things, maintain security controls to protect our confidential information and data, and notify us of material data breaches that may impact our data.
−Removed: Our board of directors has oversight of our strategic and business risk management and has delegated cybersecurity risk management oversight to the audit & risk oversight committee of our board of directors (Audit & Risk Oversight Committee).
−Removed: Our Audit & Risk Oversight Committee is responsible for ensuring that management has processes in place designed to identify and evaluate cybersecurity risks to which the company is exposed and to implement processes and programs to manage cybersecurity risks and mitigate cybersecurity incidents.
−Removed: The privacy & product compliance committee of our board of directors (Privacy & Product Compliance Committee) oversees risks related to privacy and data use, including overseeing compliance with our comprehensive privacy program.
−Removed: Management is responsible for identifying, assessing, and managing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures, maintaining cybersecurity policies and procedures, and providing regular reports to our board of directors, including through the Audit & Risk Oversight Committee and Privacy & Product Compliance Committee.
−Removed: Our Chief Information Security Officer (CISO), Guy Rosen, leads our cybersecurity program and oversees teams across the company supporting our security functions of identify, prevent, detect, respond, and recover.
+Added: Our board of directors has oversight of our strategic and business risk management and has delegated cybersecurity risk management oversight to the Audit & Privacy Committee of our board of directors (Audit & Privacy Committee).
+Added: Our Audit & Privacy Committee is responsible for ensuring that management has processes in place designed to identify and evaluate cybersecurity risks to which the company is exposed and to implement processes and programs to manage cybersecurity risks and mitigate cybersecurity incidents.
+Added: In addition, the Audit & Privacy Committee oversees risks related to privacy and data use, including overseeing compliance with our comprehensive privacy program.
+Added: Management is responsible for identifying, assessing, and managing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures, maintaining cybersecurity policies and procedures, and providing regular reports to our board of directors, including through the Audit & Privacy Committee.
+Added: Our Chief Information Security Officer (CISO), Guy Rosen, leads our cybersecurity program and oversees teams across the company supporting core security capabilities.
These teams are comprised of personnel with a broad range of experience across the private and public sectors, the technology industry, and different geographic regions.
4 unchanged sentences
Our cybersecurity teams monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents through a variety of technical and operational measures, and regularly report to our CISO.
−Removed: Our CISO is part of the senior management team at the company and regularly updates the Audit & Risk Oversight Committee on the company’s cybersecurity program, including cybersecurity risks, incidents, and mitigation strategies.
+Added: Our CISO is part of the senior management team at the company and regularly updates the Audit & Privacy Committee on our cybersecurity program, including cybersecurity risks, incidents, and mitigation strategies.
In 2025, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
−Removed: However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced undetected cybersecurity incidents.
+Added: However, despite our efforts, we cannot
+Added: eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced undetected cybersecurity incidents.
For additional information about these risks, see Part I, Item 1A, "Risk Factors" in this Annual Report on Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.