You and I know this, but if you're not a security practitioner, you might not know. It might as well then be behind a door for a room with a sign that says "Beware of the Leopard."
I understand some scrappy startups like Google don't have the resources to have someone review security incident reports that come through a web form, but maybe they should if they want to be a legit cloud provider?
Googling "report google cloud security issue" does not turn up productive results. Compare to what you get when you google "report aws security issue."