Bug Bounty
A bug bounty programme is a structured way to receive vulnerability reports from external researchers. The non-negotiables are: a public policy with safe-harbour language, a clear scope (what to test, what is off-limits), an SLA for triage, and a payout table tied to severity. Without these, you get noise and unhappy researchers.
A minimal bug bounty policy template
EXAMPLE
# Vulnerability Disclosure & Bug Bounty Policy ## Safe Harbour We will not pursue legal action against researchers who: - Stay within the scope listed below. - Avoid privacy violations, destruction of data, and service disruption. - Give us reasonable time to remediate before public disclosure. ## In Scope - Production web app: https://app.example.com - Public API: https://api.example.com/v1/* - Marketing site: https://example.com ## Out of Scope - Staging, sandbox, and *.dev.example.com hosts - Third-party services (Stripe, Auth0, SendGrid) — report to them directly - Social engineering of staff or customers - Physical attacks on offices - Denial-of-service, volumetric testing, or rate-limit bypass at scale ## How to Report Email security@example.com with PGP key 0xABCD1234. Include: steps to reproduce, impact, and any PoC code. We acknowledge within 2 business days. ## Severity & Reward Bands (AUD) | Severity | Examples | Reward | |-----------|--------------------------------------------------|--------------| | Critical | RCE, auth bypass to any account, mass PII export | $5,000-15,000 | | High | Stored XSS w/ auth, IDOR exposing other users | $1,500-5,000 | | Medium | Reflected XSS, CSRF on sensitive action | $500-1,500 | | Low | Self-XSS, missing headers, info disclosure | $100-500 | ## Triage SLA - Acknowledge: 2 business days - Triage decision: 5 business days - Fix critical: 14 days; high: 30 days; medium/low: 90 days ## Disclosure Coordinated. We credit researchers in our hall of fame on resolution.
Why it matters
Scope discipline is what makes a programme sustainable. A vague "all of example.com" invites reports about marketing typos and DNS misconfigurations; a tight, named scope concentrates effort on assets you actually want pressure-tested.
Tip: Tweak the snippet with Try it Yourself », then sit the quiz at the bottom of the page.
Example
Example
// Start with a vulnerability-disclosure policy (security.txt). // Scale up via HackerOne / Bugcrowd / Intigriti when ready.Try it Yourself »
Discussion
Loading…