bug-bounties
Top Programs
AAVE 💰
Abn Amro 💰
Acala 💰
Accellion 💰 🏅
Achmea 🎁
Acquia 🏅
Acronis 💰
Actility 💰
Adafruit 💰
Adobe 💰 🏅
Aera 💰
Aevo 💰
Affirm 💰
Agicap 💰
Ahold Delhaize 💰 🎁
Aion 💰
Air Miles Shop 🏅 🎁
Airbnb 💰 🏅
Airship 🏅
AirSwap 💰
Airtable 💰
AirVPN 💰
Aiven 💰
Alchemix 💰
Alcyon 🎁
Aleo 💰
ALEX 💰
Algolia 💰 🏅
Algorand 💰
Alibaba 💰 🏅
Aliexpress 💰 🏅
Allegro 💰
ALSCO 💰 🏅 🎁
Altera 💰
Altilly 💰
Amara 🏅
Amazon 💰 🎁
Android 💰 🏅
Ankr 💰
AOL 🏅
Apache 💰
AppFox 💰
Apple 💰 🏅
Apsis 💰
Aragon 💰
Arbitrum 💰
Ark 💰 🎁
Arkadiko 💰
Arkham 💰
Arm 💰
ARM mBed 💰 🏅
Arrival 🎁
Artsy 💰
Aruba Networks 💰 🏅
Asana 💰
ASN Bank 💰
Aspida 💰
Aster 💰
Asterisk 💰
AT&T 💰 🏅
ATG 💰
Athento 💰
Audere 🏅
Audible 💰
Augur 💰
Auth0 🏅
Autodesk 🎁
Automattic 💰 🏅 🎁
Automox 💰
Ava Labs 💰
Avail 💰
Avalara 🏅
Avast! 💰
Avira 💰 🏅
AVROTROS 🎁
AXIS OS 💰
Azimo 💰
Badoo 💰 🏅
Baidu 💰
Balancer 💰
Base 🏅
Basecamp 💰 🏅 🎁
BASF 🏅 🎁
Basilisk 💰
BBC 🏅 🎁
Beckhoff 🏅
Beets 💰
BENQI 💰
Bentley 💰 🏅 🎁
Better 💰
BiFi 💰
Bifrost 💰
Bime 💰 🏅
Binance 💰
Binary 💰 🏅
Bitfinex 💰
Bitflow 💰
Bitgo 💰 🏅
BitMEX 💰 🎁
Bitpay 💰
Bitski 💰
Bitsoffreedom 💰 🏅
Bitwala 💰
BitWall 🏅
Blockchain 💰 🏅
Blogger 💰 🏅
Bluehost 🏅
Bluesnap 💰
BMW 🏅
BookBeat 💰
Bosch 🏅
Bose 💰
Bpost 💰
Brave 💰 🏅 🎁
Brave Software 💰 🎁
BT Group 🏅
BtcTurk 💰
Buddy 🏅
Buffer 💰 🏅
Bugcrowd 💰 🏅
Bugify 🏅
BugPoC 💰 🏅
Bugv 💰
Bullish 💰
Bumba 💰
Bumble 💰 🏅
Bunq 💰 🎁
Burrow 💰
Bykea 💰
Bynder 🏅
Caffeine 💰
Canva 💰
CapyFi 💰
card.com 🏅
Cash App 💰
Casper 💰 🏅
Celer 💰
Centrify 💰 🏅
CERN 🏅
CERT/CC 🏅 🎁
CFP Time 🏅
Chainlink 💰 🏅
Chalk 🏅
Chameleon 💰 🏅
Charm 💰
Chaturbate 💰 🏅 🎁
Check 💰
Chime 💰
Circle 💰
CircleCi 💰 🎁
Citrix 💰
City-Data.com 💰 🏅
cLabs 💰
Clario 💰
Clause 💰 🏅
CLEAR 💰
Clenergy 💰
Clickup 💰
Clio 💰
Clipperz 🏅
Cloudapp 🏅
CloudFlare 💰 🏅
CM.com 💰
Cobalt 🏅
Cobinhood 💰 🏅
Coda 💰
Code.org 💰
CodeChef 💰
Codefi 💰
Cofense 🏅
Coinbase 💰 🏅 🎁
Coindcx 💰
Coinhako 💰
CoinJar 💰
Coinpayments 💰 🏅
Coinspot 💰
Colined 💰
Compass 💰
Compose 🏅
Conclusion 🏅 🎁
Connext 💰
Copper 🏅
Coreum 💰
Cosmos 💰
Coursera 🏅 🎁
Cove 💰
cPanel 💰 🏅
Crowdstrike 💰 🏅
Crypto.com 💰 🎁
CS Money 💰
Curl 💰 🏅
Curve 💰
Cuvva 🏅
Cybrary 🏅
D66 💰
Dashlane 💰 🏅
DataCamp 💰
DATADOME 💰
DataStax 💰
Datto VDP 💰 🎁
DC3 🏅
Debricked 💰 🏅
deBridge 💰
Decred 💰 🏅
Deezer 💰
Defibox 💰
Deliveroo 💰 🏅
Dentrix 💰 🏅
Deribit 💰
DeskPro 💰 🏅
Deutsche Telekom 💰 🏅
dForce 💰
dfuse Platform 💰 🏅
dHEDGE 💰
Directly 💰
Discord 💰
Discourse 💰 🏅
Django 💰 🏅
DJI 💰 🏅
DNSimple 🏅
Doctolib 💰
DODO 💰
Doist 💰
Dokobit 💰
Dominos 🏅
DoorDash 💰
Doppler 💰
Dovecot 💰 🏅 🎁
Dozuki 💰 🏅
DPD 💰 🏅
DRACOON 💰
DragonEx 💰
Drips 💰
Droom 💰 🏅
Dropbox 💰 🏅
Drupal 🏅
Dstny 💰
DuckDuckGo 🏅 🎁
Dyson 💰
Easyname 💰
eazyBI 💰
eBay 🏅
EC-Council 💰 🏅
Eclipse 💰
Ecobee 🏅
Ed 🏅
Edmodo 💰 🎁
Eero 💰
Eggy 🏅
Elastic 💰
Eligible 💰
Elive 🏅
Ellucian 🏅
elmah.io 💰
Emma 💰
Empuls 💰
Enjin 💰 🎁
ENS 💰
Ensuro 💰
Envato 🏅
Eobot 💰 🏅
Epic Games 💰 🎁
Equifax 🏅 🎁
Eset 💰
Eslint 🏅
Eternal 💰
Ethena 💰
Ether.fi 💰
eToro 💰
Etsy 💰 🏅
Eurid 💰
Eurofins 🎁
Evernote 💰 🏅
Exactly 💰
Exness 💰 🎁
Exodus 💰
ExpressVPN 💰 🏅
Ezviz 💰
F Secure 💰
Facebook 💰 🏅
Fair 💰
FanDuel 💰 🏅 🎁
Fastly 🎁
FastMail 💰 🏅
FBTC 💰
Federacy 💰
Felix 💰
Fetlife 💰
Fig 💰
Figma 💰
Filecoin 💰
Files.com 💰 🏅 🎁
FileZilla 💰 🏅
Firebase 🎁
Fireeye 🏅
First 🏅
FIS 💰
Fitbit 💰 🏅
Fivetran 💰
Flickr 💰 🏅
Flipkart 💰
Flo 💰
FloorDAO 💰
FloQast 💰 🎁
Flourish 💰
Fluxiom 🏅
FOIL 💰
Fondy 💰
Fontys 🏅
Forage 🏅
Ford 💰 🏅 🎁
FormAssembly 🏅 🎁
Fountain 🏅
FoxyCart 💰
Freshworks 💰 🏅
Front 💰
Frontegg 💰
Fuga 🏅 🎁
FUSION 💰 🏅
g.cn 💰
Gamma 💰 🏅
Gcore 💰
Gear 💰
Gearbox 💰
Genetec 💰
Geniebelt 🏅 🎁
Geotab 💰 🏅
Getbase 🏅
Gitcoin 💰
Github 💰 🏅
Gitlab 💰 🏅
Global 💰
GMX 💰
GO-JEK 💰
GoGoPool 💰
GOJEK 💰
Goldman Sachs 💰 🏅 🎁
GoodRx 💰
Google 💰
Google Chrome 💰 🏅
GovTech 💰
Grab 💰 🏅
Grammarly 💰 🏅
Greenhouse.io 💰 🏅
Grindr 💰
Grofers 💰 🏅
Groww 💰
GSMA 🏅
Guilded 🎁
Gusto 💰 🏅
Hack Me! 🏅
Hackerone 💰 🏅
Halodoc 💰 🏅
halp.com 💰
Harmony 🏅
Harvest 💰 🏅
Hashflow 💰
Haven1 💰
Hedera 💰
Helium 💰
Heroku 💰 🏅 🎁
Hex-Rays 💰
Hibachi 💰
HID 🏅
Hike 💰 🎁
Hilton 💰 🎁
Hitachi 🏅
HitBTC 💰
Hiver 🏅
Honest 💰
Hootsuite 💰 🏅 🎁
Horizen 💰
HotDoc 💰
HTC 💰
HubSpot 💰 🏅
Humo 💰
Hunter.io 💰 🏅
Hyatt 💰 🏅
Hyperledger 💰 🏅
HYPR 💰
IBM 🏅
Ibotta 💰
Iceline Hosting 🏅 🎁
Ichi 💰
Iconloop 💰 🏅
Idena 💰
iFixit 🏅
IHC 🏅
Ikea 💰
Imgur 💰 🏅 🎁
Immunefi 💰
Indeed 💰 🏅
Inditex 💰
INDmoney 💰
inDrive 💰
Infinex 💰
Informatica 🏅 🎁
Ing 💰
ING Bank 💰
ING NL 💰
Ingenico 🏅
InnoGames 💰 🏅
Insolar 💰
Instacart 💰 🏅
Instructure 💰 🏅
Integral 💰
IntegraXor (SCADA) 💰 🏅 🎁
Intel 💰 🏅
Intercom 💰 🏅
Interlay 💰
INTMAX 💰
InVision 💰 🏅
IOTA 💰 🏅
IOVLabs 💰
IPOR 💰
IpSwitch 🏅
IRCCloud 💰 🏅
iRobot 💰 🏅
Issuu 🏅 🎁
Ivanti 🎁
Izymes 💰
Jamieweb 🏅
JD Services 💰 🏅
JD.COM 💰
Jenkins 💰
Jisc 🏅
Jito 💰
Jivochat 💰
John Deere 🏅 🎁
Jora 💰
Judge.me 💰 🎁
Jumbo Privacy 💰 🏅
Jumo 🏅
JumpleAd 💰 🏅
K15t 💰
Kaleido 💰
Kamino 💰
Kaspersky 💰 🏅
Kayak 💰 🎁
Kayesa 🏅
Keeper Security 💰 🏅
Kelp DAO 💰
Keycloak 💰
KFC 💰 🏅
KHealth 💰
Kissflow 💰 🏅 🎁
Kiwi.com 💰 🎁
Klarna 💰
Klenty 🏅
KNB NL 🏅
Kohl's 💰
Koho 💰
Kong 💰
Kraden 💰
Kraken 💰 🏅
Krisp 💰
Kruidvat 💰
Kubernetes 💰 🏅
LastPass 💰 🏅
Leetcode 💰
Lenova 🏅
Letsbuild 🎁 🏅
Libelle 💰
Liberapay 💰 🏅
Librato 🏅
Lido 💰
LifeOmic 💰 🏅 🎁
Liferay 🏅
Lime 💰 🏅
LINE 💰 🏅
Linkedin 💰
Linksys 🏅
Linktree 💰
Lisk 💰
Livepeer 💰
Livestream 💰 🏅
Lob 💰 🏅
Localize 💰
LocalTapiola 💰 🏅
Logitech 💰
Looker 🏅
Luminor 🎁
Luno 💰 🏅
Lyft 💰
Lyra 💰
Lyst 💰 🏅
Magento 💰 🏅
Magic Leap Cloud 💰 🏅
MagicLeap Device 💰 🏅
Magisto 💰
Magix AG 🏅
Mailgun 💰 🏅
Make 💰
Malwarebytes 💰 🏅
ManageWP 💰 🏅
Mapbox 💰 🏅
Maple 💰
MariaDB 🏅
Marinade 💰
Marriott 💰 🏅 🎁
Mastercard 💰 🏅
Matomo 💰 🏅 🎁
Mattermost 💰 🏅
Maximum 💰 🏅
McKinsey 🏅
Mediamarktsaturn 💰 🏅
Medium 💰 🏅
Meesho 💰
Meituan 💰
Mergify 💰 🎁
MetaMask 💰 🎁
Mimecast 🏅
Mobikwik 💰 🏅
Mobile Vikings 💰 🏅 🎁
Mollie 💰 🏅
Monero 🏅 🎁
Monetha 💰 🏅
Moneybird 💰 🏅
Moneytree KK 💰 🏅
MongoDB 💰 🏅
Monolith 💰
Moodle 🏅
MoonPay 💰
Mozilla 💰 🏅 🎁
Mt Pelerin 💰 🏅
MuJS 💰 🏅
Mural 💰 🏅
MUX 💰
Myntra 🏅
Myob 🏅
MyStuff2 App 🎁 🏅
N26 💰
Narkasa 💰
Nasdaq 🏅
Naspers 🏅
Navan 💰
Naver Whale 💰 🏅
NBX 💰
NCSC UK 🏅
NCSC-NL 💰 🎁
Neon 💰
Neophotonics 💰 🏅
Netflix 💰 🏅
Netgear 💰
Netlify 💰 🎁
Neutron 💰
New Relic 💰 🏅
Newegg 💰
Nextcloud 💰 🏅
Nextiva 💰
NFTfi 💰
Nginx 💰 🏅
ngrok 💰
Nintendo 💰 🏅
no.de 💰
Nokia 🏅
NordVPN 💰
NOS 💰
Notion 💰
Nozbe 💰
Nubank 💰
Nucleus 💰
Nutshell 🏅
Nvidia 💰 🏅
NWB Bank 💰 🏅
Nykaa 🏅
Oasis 💰
Observu 🏅
Obyte 💰
Octopus 💰 🏅
Octopus Deploy 💰 🎁
Oda 💰
OFZA 💰
OKG 💰
Okta 💰 🏅
Okto 💰
OLA 💰
OLAcabs 💰 🏅
Olark 💰 🏅 🎁
Olx 🏅
Olympus 💰
Omise 💰 🏅
Omron 💰
ON2IT 💰
Ondeck 🏅
One Plus 💰 🎁
OneDoc 💰
OneLogin 🏅
OneTrust 💰
Onfido 🎁
Onfo 💰
Online Seminar 💰 🏅
OOCRP 🏅
OpenAI 💰
OpenSea 💰
OpenSSL 💰 🏅
OpenText 🏅
Opera 🏅
Opire 💰
Oppo 💰 🎁
Opsgenie 💰
Optimism 💰
Optimizely 💰 🏅
Orca 💰
Orkut 💰 🏅
Oro 💰
OVH 💰
OVHcloud 💰
OWASP ZAP 💰 🏅
OwnCloud 💰
Paladin 💰
Palantir 💰 🎁
Pantheon 💰 🏅
Pantos 💰
Panzura 🏅
Parabol 💰
Paradex 💰
Parallel 💰
Paribus 💰
Parity 💰
Passit 🏅
PasteCoin 💰 🏅
Pathao 💰
Paymill 🏅
Payoneer 💰
Paypal 💰 🏅 🎁
PayTm 💰 🏅
Perl 💰 🏅
Personio 💰
Pexels 💰
Pfizer 🎁
PGGM 💰
Phabricator 💰 🏅
Philips 🏅
PHP 💰 🏅
PHP (Bug Bounty) 💰 🏅
Pillar 💰
Ping 💰
Pinterest 💰 🏅
Pinto 💰
Piwik 🏅
Pixabay 💰
Pixiv 💰
Plaid 💰 🏅
PlanetHoster 💰 🏅
Playstation 💰 🎁
Playtika 💰
Plisio 💰
pm.me 💰
Polygon 💰
Pon Cat 💰
Porkbun 💰
PornBox 💰
Pornhub 💰 🏅
PortSwigger Web Security 💰 🏅 🎁
Postmark 🏅 🎁
Postmates 💰 🏅
PostNL 🏅 🎁
PowerDNS 💰 🏅
Practo 🏅
Prezi 💰
Priceline 💰 🏅
Privy (Bounty) 💰 🎁
Prosus 💰
Proton 💰
PTC 🏅
PUBG 🎁
Puppet 🏅
PureVPN 💰 🏅
Python 💰 🏅
Rabobank 💰
Range 💰 🏅
Rapyd 💰 🏅
Rarible 💰
Raydium 💰
Razer 💰
Razorpay 💰 🏅 🎁
RBS Help 💰 🏅
RealSelf 💰 🏅
Recargapay 💰 🏅
Recorded Future 💰 🏅 🎁
Reddit 💰 🏅
RedHat 🏅
Redox 💰 🏅
Refereum 💰 🏅
REI BBP 💰
Relaso 💰
Remitano 💰
Remitly 💰 🎁
RenoFi 💰
Repl.it 🏅
Reserve 💰
Resmed 🎁
Resolv 💰
Resonate 💰
RevenueCat 💰 🏅
Revest 💰
Rhino.fi 💰
Ribose 🏅 🎁
Ricoh 💰
Ring 💰
Riot Games 💰 🏅
Ripe NCC 💰 🏅
Ripio 💰
Ripple 💰
Roadie 🎁
Roblox 💰
Rocket.Chat 🏅 🎁
Rockset 💰
RSK 💰 🏅
Rubic 💰
Rubrik 🏅
Ruby 💰 🏅
Ruby on Rails 💰 🏅
RubyGems 💰 🏅
S-Pankki 💰
Sailthru 💰
SAP 🏅
SaveDroid 💰 🏅
SBAB 🏅
Scopely 💰
Scraping Hub 💰 🏅
Scroll 💰
SecNews 💰
Secura 🏅
SecureDrop 💰 🏅
SEEK 💰 🏅
Seek.com 💰
Segment 💰 🏅
Sei 💰
Selify 🏅
Selz 💰
Semmle 💰 🏅
SEMRush 💰 🏅 🎁
Sendbird 💰
SendSafely 💰 🏅
Sentry 🏅
Serai 💰
Shakepay 💰
Shapeshift 💰 🏅
Sheer 💰
SHEIN 💰
Sherlock 💰
Shipt 💰 🏅
Shopify 💰 🏅 🎁
Showmax 💰 🏅
Sidefx 💰 🏅
sidn 🎁
Siemens 🏅
Signal 💰
SignalFX 💰 🏅
Signup 🏅
Simple 💰 🏅
SimScale 💰
SkateFi 💰
Sky 💰
Sky TV 🏅
Skyscanner 💰 🏅
Slack 💰 🏅
Smartsheet 💰 🏅
SMTP2GO 💰
Smule 🏅
Snapchat 💰 🏅
SNS Bank 💰
Snyk 💰 🏅
Socrata 💰 🏅
Sogexia 💰
SolarEdge 💰 🏅
Solidus 🏅
Sony 🏅 🎁
Sophos 💰 🏅
SORA 💰
Sorare 💰
SoundCloud 💰 🏅
SpaceX 💰
Spark 💰
Sphero 💰 🎁
Spokeo 💰 🏅 🎁
SPOT 💰
Spotify 💰 🏅
Spreaker 💰
Sqills 🏅
Square 💰 🏅
Stacks 💰
Staked 💰
Standard 🏅
Starbucks 💰 🏅
Stargate 💰
StarkEx 💰
StarkNet 💰
StarLeaf 💰
Starlink 💰 🏅
StatusPage.io 💰 🎁 🏅
Stellar 💰 🏅 🎁
Strala 🏅
Stripe 💰
Studo 💰
Superbet 💰
SureVine 🏅
Surf 🎁
Swapcard 💰
Sweatco 🏅
Swell 💰
Swiggy 💰
Swisscom 💰
Syfe 💰
Synack 🏅
Synology 💰 🏅
szns 💰
T-Mobile 💰
Takeaway.com 💰 🏅
Tamedia 💰
Tarsnap 💰
TD Bank 🎁
TechGig 🏅 🎁
TECNO 💰 🎁
Tele2 🏅
Telegram 💰
Telekom 💰 🏅
Telenet 💰 🏅
Telenor 💰
Teleport 💰
Temu 💰
Tenable 🏅
Tencent 💰
TermMax 💰
Tesla 💰 🏅
Tetu 💰
Thinkful 🏅
Threema 💰
TIAA 🏅
TIDAL 💰
Tide 💰
TikTok 💰
Tinder 💰
Tinyman 💰
Tlon Corp 💰 🏅
TomTom 🏅 🎁
Tor 💰 🏅 🎁
Torfs 💰
Toyota 🏅
TransferWise 💰 🏅
TransIP 🏅
Trello 💰 🏅
Trendyol 💰
Trezor 💰 🏅
Trip.com 💰
Tropykus 💰
Trouw 💰
Trovisio 🏅
Truecaller 💰 🎁
TruFin 💰
Trustpilot 💰 🏅
TryHackMe 💰 🎁
TTS 💰 🏅 🎁
Tube8 💰 🏅
Tuenti 🏅
Tumblr 💰 🏅
Tuple 💰
Tweakers 💰
Twilio 💰 🏅
Twitch 🏅
Twitter 💰 🏅
Twizo 🏅
tZERO 🏅
Uber 💰 🏅
Ubiquiti 💰 🎁
Udemy 💰
UiPath 🏅
UMA Project 💰 🏅
Umbraco 🏅
UNDER ARMOUR 💰 🏅
Unikrn 💰 🏅
Unilever 🏅
UnionPay 💰 🎁
Upfort 💰
Upgrade 🏅
Uphold 💰
Upserve 💰 🏅
Upstox 💰
Upwork 💰 🏅
Urban Company 💰 🎁
USAA 💰 🏅
USDN 💰
USDT0 💰
USX 💰
Utix 💰
UXCam 💰
Valve 💰 🏅 🎁
Vanilla 💰 🏅
VeChain 💰
Venly 💰
Veracode 🏅
Verisign 💰
Vesper 💰
Vesu 💰
Vfs 💰
VHX 💰 🏅
Via 💰
Viadeo 🏅
Viator 💰 🏅
VICE 🏅
Vimeo 💰 🏅
Virtru 🏅
Visma 💰 🏅
Vivo 💰
Vivy 🏅
Volkis 💰 🎁
Vonage 🏅
Voys 🏅
VPNArea 💰
VRT 💰
VTM GO 💰
Vultr 💰
Vyond 🏅
Wagwalking 💰 🏅 🎁
Wakatime 🏅
Walmart 💰
Wamba 💰
Watsons 💰
WEB.DE 💰
Weblate 🏅
Wedbio 🏅
Wefact 💰 🏅
WePiggy 💰
Western Union 💰 🏅
Westjet 🏅
WeVPN 💰
Whatbox 💰
Whatnot 💰
Whmcs 💰 🏅
Wickr 💰
Wikimint 🏅
Winni 💰 🏅
Wise 💰
Withings 💰
Wolt 💰
WOOFi 💰
Wormhole 💰
WP Engine 💰 🏅
Zabbix 💰 🎁
Zaful 💰
Zano 💰
Zapier 💰 🏅
ZEIT 🏅
Zendesk 💰 🏅
Zenlink 💰
Zenly 💰
Zerion 💰
Zerodha 💰
Zilliqa 💰 🏅
Zimbra 🏅
Zivver 💰
zkSync 💰
zkVerify 💰
Zoho 💰 🏅
Zomato 💰 🏅
Zoom 💰 🏅
Zooplus 💰
ZTE 💰 🏅
About
The objective of this repo is to provide a centralized listing of public bounty programs, along with contact details and rewards. Which can either be browsed via the website or integrated into your workflow using MCP server or API.
We maintain a directory of independently-run programs in independent-programs.yml, and we also aggregate data from public sources (such as HackerOne, Bugcrowd, Intigriti, YesWeHack, Federacy, Disclose, etc), which is then normalized, deduplicated, validated against a schema, and merged into platform-programs.yml.
graph LR
A[Public Sources] -->|fetch| B[Normalize & Dedup]
B --> C1[Validate]
C1 --> D[platform-programs.yml]
G[Community Submissions] -->|issue form| C2[Validate]
C2 --> H[independent-programs.yml]
D --> I[API + MCP]
H --> I
D --> F[Website]
H --> F
D --> E[README]
H --> E
style A fill:#8037e0,stroke:#360a70,color:#fff
style G fill:#8037e0,stroke:#360a70,color:#fff
style B fill:#334155,stroke:#1e293b,color:#fff
style C1 fill:#3bc964,stroke:#185c2b,color:#0c121a
style C2 fill:#3bc964,stroke:#185c2b,color:#0c121a
style D fill:#fdc500,stroke:#9e7b06,color:#0c121a
style H fill:#fdc500,stroke:#9e7b06,color:#0c121a
style E fill:#2ebdfa,stroke:#0f6b8f,color:#0c121a
style F fill:#2ebdfa,stroke:#0f6b8f,color:#0c121a
style I fill:#2ebdfa,stroke:#0f6b8f,color:#0c121aSubmitting a Program
To include a new self-managed CVD or bug bounty program to the website, add it to independent-programs.yml (in alphabetical order by company name).
Either, fork the repo add you entry(s) and then open a PR, or just open an issue or fill in this form, and we will add it for you.
Required fields are company and url, all others are optional
Field | Type | Required | Description |
| string | Yes | Company or program owner name |
| URL | Yes | Canonical program or security page URL |
| string | No | Contact URL ( |
| array | No | Reward types: |
| string | No | Short program description (max 500 chars) |
| enum | No |
|
| enum | No |
|
Scope | |||
| array | No | In-scope domains (flat list shorthand) |
| array | No | Structured targets: |
| array | No | Explicitly excluded targets or categories |
Payouts | |||
| number | No | Minimum payout amount |
| number | No | Maximum payout amount |
| string | No | Payout currency code (for example |
| object | No | Per-severity max amounts: |
Rules | |||
| URL | No | Link to full testing rules |
| array | No | Forbidden techniques such as |
| boolean | No | Whether testing requires an account |
Disclosure | |||
| enum | No |
|
| boolean | No | Whether researchers may publish findings |
| number | No | Coordinated disclosure window in days |
| number | No | Committed acknowledgment time in business days |
Legal & Recognition | |||
| URL | No | Link to participation terms |
| URL | No | Link to researcher acknowledgments page |
| string | No | Description of swag offered (max 200 chars) |
| URL | No | Submission endpoint if different from |
Communication | |||
| string | No | URL to PGP key |
| string | No | Preferred report languages |
| array | No | Standards followed, for example |
Bare Minimum:
- company: Example Corp
url: https://example.com/securityFull:
- company: Example Corp
url: https://example.com/security
contact: mailto:security@example.com
rewards:
- '*bounty'
program_type: bounty
status: active
min_payout: 100
max_payout: 10000
currency: USD
payout_table:
critical: 10000
high: 5000
medium: 1000
low: 100
safe_harbor: full
allows_disclosure: true
disclosure_timeline_days: 90
response_sla_days: 3
scope:
- target: '*.example.com'
type: web
- target: Example Mobile App
type: mobile
out_of_scope:
- Third-party services
- Staging environments
excluded_methods:
- dos
- social_engineering
- phishing
hall_of_fame_url: https://example.com/security/thanks
preferred_languages: English
standards:
- ISO 29147
description: Short description of the program scope and rules.Using the Data
Raw - Download the latest JSON archive from the Releases Page
API - Access data programmatically via REST using
bug-bounties.as93.net/apiMCP - Integrate the feed into your AI tooling with
npx bug-bounties-mcpWeb - Browse and view all VDP/bounty programs at bug-bounties.as93.net
Mirror
A mirror of this repo and all data is published to CodeBerg, at: codeberg.org/alicia/bug-bounties
Developer Usage
Start by clone the repo with git clone git@github.com:Lissy93/bug-bounties.git && cd bug-bounties
Data Aggregation
make install- Setup environment and install dependencies (fromrequirements.txt)make populate- Fetch the latest directory of programs, format, and write toplatform-programs.ymlmake validate- Verify and validateplatform-programs.ymlandindependent-programs.ymlagainst theschema.jsonmake readme- Generate and insert a summarized list of programs into theREADME.md
Website
cd webto navigate into theweb/directorynpm ito install dependenciesnpm run devto start the development servernpm run buildto build the production site
Deployment
Option 1) Upload the content of
web/dist/into any web server, static hosting provider or CDNOption 2) Import the project into Vercel or Netlify directly, where it will be automatically deployed
Option 3) For Docker, run
docker run -p 8080:8080 ghcr.io/lissy93/bug-bounties:latest
Alternatively, all the above tasks can be run directly using GitHub Actions. Simply fork the project, and trigger the workflow(s).
Credits
Sponsors
Huge thanks to the following kind people, for their ongoing support in funding this, and other of my projects via GitHub Sponsors
Contributors
Attributions
Data Sources
arkadiyt/bounty-targets-data - HackerOne, Bugcrowd, Intigriti, YesWeHack, Federacy
disclose/diodb - Disclose.io vulnerability disclosure database
projectdiscovery/public-bugbounty-programs - ProjectDiscovery/Chaos
trickest/inventory - Trickest asset inventory
Core Dependencies
PyYAML - YAML parsing
jsonschema - schema validation
rapidfuzz - fuzzy deduplication
requests - HTTP client
License
Lissy93/Bug-Bounties is licensed under MIT © Alicia Sykes 2023 - 2026. For information, see TLDR Legal > MIT
The MIT License (MIT)
Copyright (c) Alicia Sykes <alicia@omg.com>
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sub-license, and/or sell
copies of the Software, and to permit persons to whom the Software is furnished
to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included install
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANT ABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NON INFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Lissy93/bug-bounties'
If you have feedback or need assistance with the MCP directory API, please join our Discord server