Home / Knowledge hub / Bug bounty
Knowledge hub
Bug bounty
Paying outside researchers for vulnerabilities they report responsibly.
What it means
A bug bounty pays outside researchers for vulnerabilities they find and report responsibly. You publish a scope and a reward table, and anyone may look.
It puts you in front of people who are very good at this and are not on your payroll. That is an unusual thing to be able to buy.
Most companies start smaller, with a page saying where to send a report and a promise not to sue the person who sends one.
Why it matters
The catch is that it reacts. You learn about a problem when somebody chooses to tell you, and the people who choose not to are not in the programme. Reports arrive as a stream you have to triage, and that triage time costs more than the payouts.
Duplicates are the other tax. Popular programmes receive the same finding many times over, and somebody on your side reads each report before anyone can tell.
A bounty also tells you only what somebody outside chose to look at, on their timetable. It says nothing about the internal tools and administrative screens nobody found worth their time.
How it shows up
Programmes work best once the findable problems have gone. Suppose the first week brings missing security headers and an administrative page anyone can open. You are paying strangers to run a checklist you could have run yourself, in engineer attention as well as cash.
Fix the findable things first, then open the door. A disclosure policy costs nothing and is the sensible first step. It also gives a researcher somewhere to send a report when they find something anyway.
Questions people ask
Bug bounty, answered
We are a small company. Can we afford to run one?
The payouts are rarely what stops people. The triage is. Every report needs somebody technical to read it, reproduce it and reply, including the many that turn out to be nothing.
If nobody owns that queue, start with a private programme and a handful of invited researchers, or with a disclosure page and no money at all.
How much should we pay for a finding?
Set a table by severity and publish it before you open. Researchers decide whether to spend a weekend on you by reading that table.
Paying too little is worse than paying nothing, because it reads as bad faith and gets discussed in public. If the budget is not there yet, offer credit, thanks and a fast reply instead, and say so plainly.
Could a researcher break something on our live system?
Yes. It happens, usually by accident, and usually through automated scanning pointed at production. Somebody fills a table with test records, or triggers thousands of emails to real customers.
Say in the rules what is out of bounds, offer a test environment if you can, and keep a contact who answers quickly when something goes wrong.
Should we just publish a disclosure policy instead?
For most companies, yes, and first. A page saying where to send a report, what you promise in return, and that you will not pursue somebody acting in good faith costs nothing to run.
Add a security.txt file at the well-known path on your site as well. RFC 9116 defines it, and it is where a researcher looks before looking anywhere else.
Why do companies close their programmes down again?
Volume, mostly. A public programme attracts a steady stream of low-value and automated reports, and a small team ends up reading them instead of fixing things. Several well-known projects have shut theirs for that reason.
The lesson is not that bounties fail. It is that a bounty is a running commitment rather than a purchase, so the capacity to answer has to exist before the door opens.
Sources
Where this comes from
Related
Terms that sit next to this one
Vulnerability disclosure
Telling an organisation about a flaw, and the policy that makes it safe.
Penetration test
A time-boxed engagement where skilled people attack your systems by hand.
Vulnerability management
The loop of finding, prioritising, fixing and checking the fix held.
Remediation
The actual work of fixing a finding: the change, the review, the release.
Red team
A simulated adversary given a goal and left to reach it however they can.
Ready to pay strangers for findings?
A bounty works better once the findable issues have gone. We test one application across ten vulnerability classes first, with proof for each finding. A 30 day pilot costs $199.
Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.