No they aren't.
They disclose vulnerabilities to US government agencies first and stil to this day have no transparency about what information they share with governments.
They disclose vulnerabilities to US government agencies first and stil to this day have no transparency about what information they share with governments.