Docs

How to read the index, and what it does not tell you.

An index of vulnerability disclosure and bug bounty programs, most of them self-hosted and absent from every platform listing. This page explains how to read it and what it does not tell you.

The filters

Four dropdowns above the results, plus TLD and free-text search. Each one maps to a single field, and the value in brackets is what it writes to the URL — so a filtered view is a link you can share.

DropdownFieldOptions
Hosting
Self-hosted
hosting Self-hosted — the policy names no bounty platform, so the organisation runs its own process. This is the default, because it is the set no platform dataset contains.
On a platform (platform) — a platform is named, so it is probably listed elsewhere too.
Any hosting — no filter.
Reward
Any reward
reward Ordered by what actually reaches you.
Pays money (monetary) — the policy states cash or an amount.
Swag (Gifts) (swag) — physical goods: a shirt, stickers, a package.
Hall of Fame (recognition) — credit or thanks, nothing posted to you.
No reward (none) — the policy mentions none. Most programs.
Status
Active
status Active — served, and any Expires date is still ahead. Default.
Expired (expired) — the organisation’s own Expires date has passed.
Retired (retired) — the file is no longer served. Kept as a record.
Safe harbour
Any harbour
safe_harbour Has harbour (stated) — the policy says it will not pursue good-faith research. A small minority of programs.
No harbour (not_stated) — we read the policy and found no such language. Not a prohibition.
Unknown (unknown) — no policy was reachable, so there is nothing to read either way.

Filters combine, and the state lives in the URL hash — #reward=monetary&harbour=stated is the shortlist worth starting from. Programs with no reachable contact are excluded throughout; the count is on the Stats page.

Finding new programs

A program found in the last seven days carries a green dot beside its domain. On a desktop browser, hovering it shows the date it first appeared.

A program that had already expired when it was first found gets no dot: the marker is for something worth looking at now, and an Expires date that passed months ago is not that. Those records are still added and are still findable under the Expired status.

Records are ordered alphabetically within a TLD rather than by date, so scanning for dots across every page is not practical. When there is anything to see, a green “N new” chip appears beside the counts above the results — click it to show only those, click again to clear. It clears the hosting and status filters as it goes, so the number on the chip is the number of records you get.

#new=1 does the same in a URL, and keeps whatever filters are already set — so #new=1&reward=monetary is new programs that pay, within the default self-hosted and active view.

The marker clears itself after seven days, so an empty result means nothing has been added this week rather than something being broken.

Why a program is expired or retired

active
Served, and any Expires date is still ahead. Many files set no Expires at all, which is not the same as a date in the future.
expired
The organisation’s own Expires date has passed, so it is telling you not to rely on the file. Nothing was withdrawn — it is still served and the contact may still work.
retired
The security.txt that was once here no longer resolves. That is a different fact from an expiry: the file is gone rather than stale, and the contact in it is unlikely to reach anyone. Whether it was withdrawn, moved or lost to a server change is not something the file can tell you. Kept rather than deleted, so the disappearance stays visible.

Limits

Companion tool: Bug-Bounty Dorks Automation

No index is complete. For targeted hunting of your own — a specific company, a region, a language — search-engine dorks go where a list cannot: 160 of them across six engines, in 26 languages.

Open the dorks tool →