Security · Concept

Bug bounty

A standing offer from a company to reward independent security researchers who find weaknesses in its products and report them privately, within published rules.

Testing and research · Paid · updated

How it works

A programme publishes a policy: which domains and apps are in scope, what is off limits (denial-of-service, social engineering, other users' data), how to report, and how much each severity pays. Researchers test within those rules and send reports; the company or the platform's triage team reproduces each one, rejects duplicates, and pays a bounty once a finding is confirmed. A safe harbour clause promises not to take legal action against researchers who follow the rules.

A vulnerability disclosure programme (VDP) is the unpaid version: a clear, safe way to report problems, often announced in a security.txt file at /.well-known/security.txt, a format standardised as RFC 9116. Many companies start with a VDP and add rewards later. Programmes can be private, with invited researchers only, or public.

Large companies such as Google, Microsoft and Apple run their own programmes, while HackerOne, Bugcrowd, Intigriti and YesWeHack host programmes for others and handle triage and payments. Researchers join the platforms free, and their testing is authorised only for what each programme's policy allows.

Bug bounty pros and cons

Pros

  • You pay for confirmed findings rather than for time
  • Many testers with different skills look at the product
  • Runs continuously, so new features are tested soon after release
  • Gives researchers a clear, legal route to report what they find

Cons

  • Platform fees plus bounties can add up quickly
  • Many duplicate, low-value or automated reports to triage
  • Needs fast replies and fixes, or researchers move on
  • Coverage is uneven, because researchers chase what pays

When to use Bug bounty

Pick it when

  • The product has had a pentest and the obvious issues are fixed
  • Someone can triage reports and ship fixes within days
  • A large or fast-changing attack surface, such as many apps and APIs

Skip it when

  • The basics are not in place yet, so bounties would pay for easy bugs
  • You need a dated, scoped report for a customer or auditor

Bug bounty pricing

Paid

HackerOne, Bugcrowd and Intigriti quote platform fees on request, and you pay a bounty for each valid bug on top. Researchers join free. HackerOne is free for eligible open-source projects, plus a 5% fee on bounties.

Bug bounty pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost

Bug bounty vs the alternatives

More in Security

Testing and research

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.