Docs

How to read the index, and what it does not tell you.

Vulnerability disclosure and bug bounty programs, most self-hosted and absent from every platform listing.

Start here: programs with a policy we could read, that state they pay, and that state safe harbour › The strongest evidence this index holds, and a small fraction of it.

The filters

Each dropdown maps to one field. The bracketed value is what it writes to the URL, so a filtered view is a link you can share.

DropdownFieldOptions
Hosting
Self-hosted
hosting Self-hosted — no platform named. Default.
On a platform (platform) — likely listed elsewhere too.
Any hosting — no filter.
Reward
Any reward
reward Pays money (monetary) — cash stated.
Swag (Gifts) (swag) — physical goods.
Hall of Fame (recognition) — credit only.
No reward (none) — most programs.
Status
Active
status Active — the listing is current. Default.
Expired (expired) — the program set its own end date and it has passed. Nothing was withdrawn, and the contact often still works.
Retired (retired) — withdrawn, and kept visible so the change stays on the record. The contact is unlikely to reach anyone.

The Policy column. policy links a document setting out scope and rules. security.txt means no policy document is published and the link opens the RFC 9116 file itself, which usually carries a PGP key or an acknowledgements page beyond the contact already in the row. The two are not the same thing, which is why they are not labelled the same.

Safe harbour
Any harbour
safe_harbour Has harbour (stated) — policy protects good-faith research. A small minority.
No harbour (not_stated) — no such language found. Not a prohibition.
Unknown (unknown) — no policy reachable.
Researcher reports
Any report history
reported Researcher reported a payout (1) — a researcher said publicly that this program paid them, with the amount and how long the reply took. Reported at bugbountyscam.com, not verified here, and the only column on this site that is somebody's account rather than a check.
Evidence
Any evidence
evidence What the entry actually proves.
Policy confirmed (policy) — a policy page that opens, reads as one, and is not what the host returns for every address.
Contact only (contact) — a security.txt address and no policy document. Most of the index.
Could not verify (unverified) — the policy could not be read from here. Unknown, not weak.
Not a policy (not_policy) — it was read, and it is something else.

Limits

A green ✓ paid badge beside a domain means a researcher publicly reported being paid by that program, at bugbountyscam.com. Hover it for the amount and how long the reply took. It is the one thing here that was reported rather than checked, which is why it names its source: nothing on this site can tell you whether anybody answers, and only somebody who sent a report knows.

What to expect when you report

The low competition is a direct consequence of the same informality. Worth knowing which trade you are making.

Companion tool: Bug-Bounty Dorks Automation

No index is complete. For targeted hunting of your own — a specific company, a region, a language — search-engine dorks go where a list cannot: 160 of them across six engines, in 26 languages.

Open the dorks tool →