Vulnerability disclosure and bug bounty programs, most self-hosted and absent from every platform listing.
Start here: programs with a policy we could read, that state they pay, and that state safe harbour › The strongest evidence this index holds, and a small fraction of it.
The filters
Each dropdown maps to one field. The bracketed value is what it writes to the URL, so a filtered view is a link you can share.
| Dropdown | Field | Options |
|---|---|---|
| Hosting Self-hosted |
hosting |
Self-hosted — no platform named. Default. On a platform ( platform) — likely
listed elsewhere too.Any hosting — no filter. |
| Reward Any reward |
reward |
Pays money (monetary) — cash stated.Swag (Gifts) ( swag) — physical goods.Hall of Fame ( recognition) — credit only.No reward ( none) — most programs. |
| Status Active |
status |
Active — the listing is current. Default. Expired ( expired) — the program set its
own end date and it has passed. Nothing was withdrawn, and the
contact often still works.Retired ( retired) — withdrawn, and kept
visible so the change stays on the record. The contact is
unlikely to reach anyone. |
The Policy column. policy links a
document setting out scope and rules. security.txt means no
policy document is published and the link opens the RFC 9116 file itself,
which usually carries a PGP key or an acknowledgements page beyond the
contact already in the row. The two are not the same thing, which is why
they are not labelled the same.
| Safe harbour Any harbour |
safe_harbour |
Has harbour (stated) — policy protects
good-faith research. A small minority.No harbour ( not_stated) — no such
language found. Not a prohibition.Unknown ( unknown) — no policy
reachable. |
| Researcher reports Any report history |
reported |
Researcher reported a payout (1) — a
researcher said publicly that this program paid them, with the
amount and how long the reply took. Reported at
bugbountyscam.com, not verified
here, and the only column on this site that is somebody's account
rather than a check. |
| Evidence Any evidence |
evidence |
What the entry actually proves. Policy confirmed ( policy) — a policy
page that opens, reads as one, and is not what the host returns
for every address.Contact only ( contact) — a
security.txt address and no policy document. Most
of the index.Could not verify ( unverified) — the
policy could not be read from here. Unknown, not weak.Not a policy ( not_policy) — it was
read, and it is something else. |
Limits
A green ✓ paid badge beside a domain means a researcher publicly reported being paid by that program, at bugbountyscam.com. Hover it for the amount and how long the reply took. It is the one thing here that was reported rather than checked, which is why it names its source: nothing on this site can tell you whether anybody answers, and only somebody who sent a report knows.
- The domain is not the scope. It is only where the policy is published. Read the policy for what is actually authorised, and never point a scanner at these domains.
- Being listed is not permission. It means an organisation published a contact address, nothing more.
- Reward and safe harbour are indicative, not a legal reading. Confirm both in the policy before relying on either.
- Where a policy could not be read in full, those values understate what is offered.
not statedis not a prohibition — the policy is simply silent.
What to expect when you report
- Often no reply at all. Silence usually means nobody triaged the mail, not that the report was rejected.
- No response times. Weeks is normal; months happens.
- No mediation. If a report is ignored or disputed, there is no third party to escalate to.
- Most do not pay. Even a stated reward is the organisation’s own wording, not a contract.
- A live listing is not a live programme. The index confirms the contact resolves and the policy is served — not that anyone reads the inbox.
The low competition is a direct consequence of the same informality. Worth knowing which trade you are making.
Companion tool: Bug-Bounty Dorks Automation
No index is complete. For targeted hunting of your own — a specific company, a region, a language — search-engine dorks go where a list cannot: 160 of them across six engines, in 26 languages.
Open the dorks tool →