Bug bounty programme
A programme in which an organisation rewards researchers who find security flaws within set rules and scope and report them responsibly.
- 01
Why it matters
The different perspectives of many researchers can find flaws a single test team might miss, and payment is made only for real findings. The programme, however, needs a team able to assess and fix incoming reports quickly. Launching one before basic security testing means paying a high price for easy findings.
- 02
Example
An app first closes its basic flaws through a penetration test, then launches a programme covering only the main site. A researcher reports that coupon codes can be reused repeatedly and receives a reward; the flaw is fixed within two days.
- 03
Common mistake
Opening a programme without written scope and rules. Unclear rules lead both to researchers running tests that disrupt service and to disputes over rewards.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.