Public-Programs

Docs

How to read the index, and what it does not tell you.

Vulnerability disclosure and bug bounty programs, most self-hosted and absent from every platform listing.

Start here: programs with a policy we could read, that state they pay, and that state safe harbour › The strongest evidence this index holds, and a small fraction of it.

The filters

Each control in the rail maps to one field — hosting is a set of radio buttons, the rest are dropdowns. The bracketed value is what it writes to the URL, so a filtered view is a link you can share.

DropdownFieldOptions
Hosting
All programs
hosting All programs — no filter. Default.
Self-hosted (self_hosted) — no platform named, and the bulk of this index.
Platform-hosted (platform) — likely listed elsewhere too.
Reward
Any reward
reward Pays money (monetary) — cash stated.
Swag (Gifts) (swag) — physical goods.
Hall of Fame (recognition) — credit only.
No reward (none) — most programs.
Status
Any status
status Any status — no filter. Default.
Active (active) — the listing is current.
Expired (expired) — the program set its own end date and it has passed. Nothing was withdrawn, and the contact often still works.
Retired (retired) — withdrawn, and kept visible so the change stays on the record. The contact is unlikely to reach anyone.

Policy and security.txt. Both live in a program's record, which opens from its row. Read the program policy goes to a document setting out scope and rules. View security.txt appears when no policy document is published, and opens the RFC 9116 file itself, which usually carries a PGP key or an acknowledgements page beyond the contact. The two are not the same thing, which is why they are not labelled the same.

Safe harbour
Any harbour
safe_harbour Has harbour (stated) — policy protects good-faith research. A small minority.
No harbour (not_stated) — no such language found. Not a prohibition.
Unknown (unknown) — no policy reachable.
Researcher reports
Any report history
reported Researcher reported a payout (1) — a researcher said publicly that this program paid them, with the amount and how long the reply took. Reported at bugbountyscam.com, not verified here, and the only column on this site that is somebody's account rather than a check.
Evidence
Any evidence
evidence What the entry actually proves.
Policy confirmed (policy) — a policy page that opens, reads as one, and is not what the host returns for every address.
Contact only (contact) — a security.txt address and no policy document. Most of the index.
Could not verify (unverified) — the policy could not be read from here. Unknown, not weak.
Not a policy (not_policy) — it was read, and it is something else.

Limits

A green reported paid mark under a domain means a researcher publicly reported being paid by that program, at bugbountyscam.com. Hover it for the amount and how long the reply took. It is the one thing here that was reported rather than checked, which is why it names its source: nothing on this site can tell you whether anybody answers, and only somebody who sent a report knows.

What to expect when you report

The low competition is a direct consequence of the same informality. Worth knowing which trade you are making.

Companion tool: Bug-Bounty Dorks Automation

No index is complete. For targeted hunting of your own — a specific company, a region, a language — search-engine dorks go where a list cannot: 160 of them across six engines, in 26 languages.

Open the dorks tool →