An index of vulnerability disclosure and bug bounty programs, most of them self-hosted and absent from every platform listing. This page explains how to read it and what it does not tell you.
The filters
Four dropdowns above the results, plus TLD and free-text search. Each one maps to a single field, and the value in brackets is what it writes to the URL — so a filtered view is a link you can share.
| Dropdown | Field | Options |
|---|---|---|
| Hosting Self-hosted |
hosting |
Self-hosted — the policy names no bounty platform, so
the organisation runs its own process. This is the default, because
it is the set no platform dataset contains. On a platform ( platform) — a platform is
named, so it is probably listed elsewhere too.Any hosting — no filter. |
| Reward Any reward |
reward |
Ordered by what actually reaches you. Pays money ( monetary) — the policy states
cash or an amount.Swag (Gifts) ( swag) — physical goods: a
shirt, stickers, a package.Hall of Fame ( recognition) — credit or
thanks, nothing posted to you.No reward ( none) — the policy mentions
none. Most programs. |
| Status Active |
status |
Active — served, and any Expires date is
still ahead. Default.Expired ( expired) — the organisation’s
own Expires date has passed.Retired ( retired) — the file is no
longer served. Kept as a record. |
| Safe harbour Any harbour |
safe_harbour |
Has harbour (stated) — the policy says it
will not pursue good-faith research. A small minority of programs.No harbour ( not_stated) — we read the
policy and found no such language. Not a prohibition.Unknown ( unknown) — no policy was
reachable, so there is nothing to read either way. |
Filters combine, and the state lives in the URL hash
— #reward=monetary&harbour=stated is the
shortlist worth starting from. Programs with no reachable contact are
excluded throughout; the count is on the Stats page.
Finding new programs
A program found in the last seven days carries a green dot beside its domain. On a desktop browser, hovering it shows the date it first appeared.
A program that had already expired when it was first found gets no dot:
the marker is for something worth looking at now, and an Expires
date that passed months ago is not that. Those records are still added and are
still findable under the Expired status.
Records are ordered alphabetically within a TLD rather than by date, so scanning for dots across every page is not practical. When there is anything to see, a green “N new” chip appears beside the counts above the results — click it to show only those, click again to clear. It clears the hosting and status filters as it goes, so the number on the chip is the number of records you get.
#new=1 does the same in a URL, and
keeps whatever filters are already set — so
#new=1&reward=monetary is new programs that pay, within the
default self-hosted and active view.
The marker clears itself after seven days, so an empty result means nothing has been added this week rather than something being broken.
Why a program is expired or retired
- active
- Served, and any
Expiresdate is still ahead. Many files set noExpiresat all, which is not the same as a date in the future. - expired
- The organisation’s own
Expiresdate has passed, so it is telling you not to rely on the file. Nothing was withdrawn — it is still served and the contact may still work. - retired
- The
security.txtthat was once here no longer resolves. That is a different fact from an expiry: the file is gone rather than stale, and the contact in it is unlikely to reach anyone. Whether it was withdrawn, moved or lost to a server change is not something the file can tell you. Kept rather than deleted, so the disappearance stays visible.
Limits
- The domain is not the scope. It is only where the policy is published. What is in scope is whatever that policy says — often other hosts, sometimes named applications and nothing else, sometimes explicitly not the marketing site the file sits on. Never point a scanner at these domains; open the policy and read what it authorises.
- Being listed is not permission. A record here means an organisation published a contact address, nothing more.
- Reward and safe harbour are indicative, not a legal reading. They come from the wording of the policy, so confirm both in the document before you rely on either.
- Where a policy could not be read in full, its reward and safe-harbour values understate what is really offered. Absence of a value is not absence of an offer.
- Safe harbour is the field to check first. Most programs state none at
all, and
not statedis not the same as prohibited — it means the policy is silent on whether good-faith research will be pursued.
Companion tool: Bug-Bounty Dorks Automation
No index is complete. For targeted hunting of your own — a specific company, a region, a language — search-engine dorks go where a list cannot: 160 of them across six engines, in 26 languages.
Open the dorks tool →