
Bug bounty programs have become a solid staple to help turn hackers and computer security researchers away from any black hat activity while still providing an income avenue.
It makes the web and systems more secure as a whole, by effectively opening up red team work to anyone who can get the work done.
Some companies are not particularly pleased when a critical system is breached, so it’s important to know which companies are offering bounties open to everyone or only established researchers (normally through invite programs).
Responsible disclosure agreements ensure the company with the bug bounty program in place is protected, without hurting the lucky analyst’s bank account in any way.
There are multiple programs out there, and it’s difficult to keep track with such a large and dynamic list. We’ve taken the time here at Security Zap to provide a roundup of the publicly available bug bounty programs currently on offer.
Time to roll up the sleeves and hunt some bugs.
Name of the program | Bug Bounty Program Url | Rewards |
---|---|---|
Avira | https://bugcrowd.com/avira | $100 ? $2,500 per vulnerability |
Alvosec | https://firebounty.com/bug-bounty-program/766/alvosec | Minimum reward $5 |
Aspen | https://firebounty.com/bug-bounty-program/853/aspen | At this time, we are not awarding bounties or cash rewards for reported vulnerabilities. |
AlienVault | https://firebounty.com/bug-bounty-program/869/alienvault | / |
Ardour | https://ardour.org/support_expectations.html | / |
Aerohive | https://www.aerohive.com/support/security-center/ | / |
ActiveCampaign | https://www.activecampaign.com/security/bounty/ | / |
Abacus | https://bugcrowd.com/abacus | Points per vulnerability. |
Abn Amro | https://hackerone.com/abnamro | You might get a reword based on the issue you report |
Admiral | https://hackerone.com/getadmiral | Admiral will determine in its own discretion whether a reward should be granted and the amount of the reward |
AligeBits | https://hackerone.com/agilebits | / |
Algolia | https://hackerone.com/algolia | Minimum reward is $100 for security vulnerabilities |
Alibaba | https://hackerone.com/alibaba | / |
Aliexpress | https://hackerone.com/aliexpress | / |
Android | https://hackerone.com/android | Android provides rewards depending on the issue that is found, public recognition is included as well. Te reward is from $330 to $200,000 vulnerabilities |
Apache httpd | https://hackerone.com/ibb-apache | The rewrads go from $100-$3000 depending on the vulnerabilities |
Aptible | https://hackerone.com/aptible | Aptible awards security researchers cash and prizes for reporting vulnerabilities. You can send them an email |
Artsy | https://hackerone.com/artsy | Tipical reward is from $25. Some more severe issues can be $100. The maximum amount for any issue that the bug bounty program pays for single issue is of $250. |
Asana | https://hackerone.com/asana | Only 1 bounty will be awarded per vulnerability. Asana have no minimum/maximum amount; rewards are based on severity, impact, and report quality. |
AT&T | https://hackerone.com/att | The bounties range from $100 to $5,000 depending on the ranking of the Bug or Bug Reporter. |
BlaBlaCar | https://firebounty.com/bug-bounty-program/897/blablacar | $50 reward |
Avast! | https://hackerone.com/avast | You can submit bugs by email. The base payment is $400 per bug. Depending on the criticality of the bug (as well as its neatness) the bounty goes much higher (each bug is judged independently by a panel of Avast experts). Remote code execution bugs pay at least $6,000 ? $10,000 or more. |
Blend | https://firebounty.com/bug-bounty-program/776/blend | $100 reward |
Buildkite | https://firebounty.com/bug-bounty-program/787/buildkite | The rewards go from $50-$1000 |
Big Monocle | https://firebounty.com/bug-bounty-program/826/big-monocle | / |
Badoo | https://hackerone.com/badoo | Vulnerabilities will be ranked from category 5 (1000) to category 1 (100), depending on their severity. The Badoo jury determines the severity of the vulnerability. |
Barracuda Networks | https://hackerone.com/barracuda | Points per vulnerability |
Belastingdienst | https://hackerone.com/belastingdienst | / |
Bime | https://www.bimeanalytics.com/ | The bounty goes from $50 to $1000 |
Binary | https://hackerone.com/binary | Bounty from $10-$1000 |
Bitcoin de | https://hackerone.com/bitcoin_de | The rate depends on the size and relevance of the safety leaks. |
Bitdefender | https://hackerone.com/bitdefender | You can submit vulnerabilities by email. There si no fixed reward, the minimum is from $100 |
Bitnet | https://hackerone.com/bitnet | / |
Blackphone | https://hackerone.com/blackphone | The standard reward is $128.00 USD. eward amounts may vary depending upon the severity of the vulnerability reported. |
Blockstack | https://hackerone.com/blockstack | The reward goes from $25-$600 |
Blogger | https://hackerone.com/blogger | This application is covered under the Google Vulnerability Reward Program. The reward depnds from category.Rewards for qualifying bugs range from $100 to $31,337 |
Booking | https://hackerone.com/bookingcom | / |
Brave Software | https://hackerone.com/brave | / |
BrickFTP | https://hackerone.com/brickftp | BrickFTP pays from $100 to $5,000 forsignificant security vulnerability . |
Bugcrowd | https://hackerone.com/bugcrowd | Rewards go from $0 dollars if you submit a problem that is in P5 level and up to $10 000 for a vulnerabilitie that is in P1 level. |
Bugify | https://hackerone.com/bugify | Only 1 bounty will be awarded per vulnerability. No minimum/maximum amount; rewards are based on severity, impact, and report quality. |
Bumble | https://hackerone.com/bumble | Vulnerabilities will be ranked from category 5 (1000) to category 1 (100), depending on their severity. |
BuzzFeed | https://hackerone.com/buzzfeed | BuzzFeed, at its sole discretion, may provide rewards to researchers for confirmed and resolved qualifying vulnerability reports. |
CCM Benchmark Group | https://firebounty.com/bug-bounty-program/845/ccm-benchmark-group | Minimum, by a 50? and Hall of fame recognition |
Crowdstrike | https://firebounty.com/bug-bounty-program/875/crowdstrike | The rewards go from $250-$3000 |
Cupcake | https://cupcake.io/security | / |
CARD | https://hackerone.com/card | $50 ? $500 per vulnerability |
Chegg | https://hackerone.com/chegg | There is no information about this bug bounty program |
ChinaNetCloud | https://hackerone.com/chinanetcloud | You can submit a report on their email address. There is no information about bounty reward |
Chrome | https://hackerone.com/chromium | Rewards for qualifying bugs typically range from $500 to $100,000. |
Cobalt | https://hackerone.com/cobalt | / |
Cobinhood | https://hackerone.com/cobinhood | The price goes from $100-$4000 |
Coinbase | https://hackerone.com/coinbase | The price goes from $100-$50 000 |
CoinJar | https://hackerone.com/coinjar | CoinJar rewards one bounty per bug in Bitcoin |
Coinkite | https://hackerone.com/coinkite | / |
Contentful | https://hackerone.com/contentful | The vulnerabilities reported on all the other parts of the Contentful platform are currently not eligible for monetary reward. High-impact vulnerabilities outside of this scope might be considered on a case by case basis. |
cPanel | https://hackerone.com/cpanel | Money and public recognition |
Cryptocat | https://hackerone.com/cryptocat | Copycat rewards include money, stickers and t-shirts and mention on Wall of Unquestionable Greatness! |
Duolingo | https://firebounty.com/bug-bounty-program/846/duolingo | / |
Deconf | https://hackerone.com/deconf_com | At this time, we are not awarding bounties or cash rewards for reported vulnerabilities |
Dashlane | https://hackerone.com/dashlane | Minimum reward is $100 USD, but reward amounts may vary depending upon the severity of the vulnerability reported |
Data Processing (IBB) | https://hackerone.com/ibb-data | / |
De Nederlandsche Bank | https://hackerone.com/dnb_nl | / |
de Volksbank | https://hackerone.com/devolksbank | / |
Deliveroo | https://hackerone.com/deliveroo | Rewards go from $150-$2500 |
Deutsche Telekom | https://hackerone.com/deutschetelekom | There are several condition that needs to be followed to get a reward. |
DIRECTV | https://hackerone.com/directv | The bounties range from $250 to a potential maximum award of $20,000 |
Discourse | https://hackerone.com/discourse | The rewards go from $128-$512+ |
Django | https://hackerone.com/django | Bounty amounts are based on severity and will range from $250 to $3,000 USD. |
Dropbox | https://hackerone.com/dropbox | The rewards go from $12,167-$32,768 |
DuckDuckGo | https://hackerone.com/duckduckgo | / |
Dyson | https://www.dyson.com/en.html | Dyson doesn't pay for reports outside of Bug Bounty programme. |
Ecrom | https://bountyfactory.io/ercom/cryptobox-bug-bounty | |
Electroneum | https://hackerone.com/electroneum | Rewards go from $100-$1000 |
Electronic Frontier Foundation | https://hackerone.com/eff | Non-cash rewards |
Eobot | https://hackerone.com/eobotcom | The rewards go from $10 (Minimum bounty) |
Ethereum | https://hackerone.com/ethereum | The rewrads are ranged by points. One point corresponds to 1USD. The points goe from 500 to 25 000 |
Etsy | https://hackerone.com/etsy | The rewards go from$100-$1500 and you get to be on their hall of fame |
FormAssembly | https://firebounty.com/bug-bounty-program/765/formassembly | / |
F-Secure | https://hackerone.com/fsecure | The rewards go from $500-$15000 |
F. Hoffmann-La Roche Ltd. | https://hackerone.com/roche | / |
https://hackerone.com/facebook | The minimum reward is $500. | |
FlexiSPY | https://hackerone.com/flexispyltd | Rewards range from $100???$5,000 |
Fox-IT | https://hackerone.com/foxit | Minimum of a ?50 voucher. |
Ghostscript | https://hackerone.com/ghostscript | Accepted fixes for bugs at P1 and P2 pay a bounty of US$1000 each. Bugs at lower priorities and 'normal' importance pay US$500 per bug. Bugs designated with 'trivial' or 'minor' importance pay a negotiated amount, typically US$100 per bug. |
GitHub | https://hackerone.com/github | Rewards range from $200 up to $10000 |
GlassWire | https://hackerone.com/glasswire | GlassWire offers rewards for bugs but the amount is not speicified |
GoDaddy | https://hackerone.com/godaddy | / |
https://hackerone.com/google | Rewards for qualifying bugs range from $100 to $31,337 | |
Google Play Security Reward Program | https://developer.android.com/distribute/ | The rewards go from $1000-$5000. |
Grabtaxi Holdings Pte Ltd | https://hackerone.com/grab | The rewards go from $200-$10 000 |
Greenhouse io | https://hackerone.com/greenhouse | The rewards go from $100-$1000 |
Homebrew | https://firebounty.com/bug-bounty-program/794/homebrew | |
HackerOne | https://hackerone.com/security | The rewards go from $500-$15000 |
Harvest | https://hackerone.com/harvest | $100 minimum bounty |
HelloSign | https://hackerone.com/hellosign | You can report an issue by email |
Heroku | https://hackerone.com/heroku | $100 ? $1,500 per vulnerability |
Highrise HQ | https://hackerone.com/highrise_hq | / |
HireVue | https://hackerone.com/hirevue | Reward amounts will vary based upon the severity of the reported vulnerability, and eligibility is at our sole discretion. |
Hybrid Saas | https://hackerone.com/hybridsaas | / |
Hyperledger | https://hackerone.com/hyperledger | Our rewards are based on the impact of a vulnerability. The rewards go from $200-$1500 |
ICQ | https://firebounty.com/bug-bounty-program/830/icq | / |
Intercom New | https://firebounty.com/bug-bounty-program/774/intercom-new | Minimum of $100 |
Infogram | https://firebounty.com/bug-bounty-program/849/infogram | / |
Indeed | https://hackerone.com/indeed | $100 ? $5,000 per vulnerability |
Independer | https://hackerone.com/independer | The reward is minimum of a ? 50 |
Inflection | https://hackerone.com/inflection | From $0 for Low severity bugs to minimum $2000 for Critical severity bugs |
ING | https://hackerone.com/ing | You may get a reward. |
https://hackerone.com/instagram | The minimum reward is $500. | |
Instamojo | https://hackerone.com/instamojo | All bugs are awarded a bounty based on their impact. |
Instructure | https://hackerone.com/instructure | / |
Intel Corporation | https://hackerone.com/intel | The reward go from $2000-$10000 |
IRCCloud | https://hackerone.com/irccloud | Our minimum reward is $50 USD for minor issues, while we expect to reward $500+ USD for major vulnerabilities |
KAYAK | https://hackerone.com/kayak | / |
Keybase | https://hackerone.com/keybase | Reward amounts will vary based upon the severity of the reported vulnerability, and eligibility is at our sole discretion. |
Kraken | https://hackerone.com/krakenfx | For significant bugs, we offer reward and recognition on our Wall of Fame. |
Kyup | https://hackerone.com/kyupcloud | It may vary between $10 and $200 per bug. |
LaunchKey | https://hackerone.com/launchkey | The minimum bounty for a qualifying security vulnerability is $200 USD. There is no maximum bounty |
LINE | https://hackerone.com/line | The rewards go from $500-$10000 |
https://hackerone.com/linkedin | / | |
LocalTapiola | https://hackerone.com/localtapiola | Rewards may range from $50 up to $50,000. |
Lyst | https://hackerone.com/lyst | The rewards go from $100-$5000+ |
Monero | https://firebounty.com/bug-bounty-program/842/monero | |
Mail Ru | https://hackerone.com/mailru | The rewards go from $150-$10000 |
ManageWP | https://hackerone.com/managewp | / |
Mapbox | https://hackerone.com/mapbox | / |
Massachusetts Institute of Technology | https://hackerone.com/mit | We are offering TechCASH as thanks. |
MasterCard | https://hackerone.com/mastercard | / |
Mega | https://hackerone.com/megaprivacy | We offer up to EUR 10,000 per bug |
Meraki | https://hackerone.com/meraki | Rewards for qualifying bugs range from $100 to $2,500 |
Microsoft | https://hackerone.com/microsoft | / |
Monaco | https://hackerone.com/monaco | The reward goes from $250-$7500 |
Mozilla | https://hackerone.com/mozilla | / |
Netgear | https://firebounty.com/bug-bounty-program/777/netgear | $150-$15000 |
N26 | https://hackerone.com/n26 | The ewrads go from $250-$2000 |
Naver Whale | https://hackerone.com/naver_whale | The reward goes from $500-$7500 |
NCSC-NL | https://hackerone.com/ncsc | / |
Nest | https://hackerone.com/nest | Nest uses Google reward program |
New Relic | https://hackerone.com/newrelic | The reward goes from $100-$5000+ |
Nextcloud | https://hackerone.com/nextcloud | The rewards go from $250-$5000 |
Nginx (IBB) | https://hackerone.com/ibb-nginx | The rewards go from $500-$3000 |
Nimiq | https://hackerone.com/nimiq | The rewards go from $500-$13337 |
Nintendo | https://hackerone.com/nintendo | The rewards go from $100-$2000 |
Node js | https://hackerone.com/nodejs | The rewards go from $500-$1500 |
Nuon | https://hackerone.com/nuon | / |
Outscale | https://firebounty.com/bug-bounty-program/769/outscale | The rewards go from $80-$800 |
OCCRP | https://firebounty.com/bug-bounty-program/876/occrp | / |
Oculus | https://hackerone.com/oculus | / |
ok ru | https://hackerone.com/ok | / |
Ola | https://hackerone.com/olacabs | The lowest reword is 5000 INR (74.4082 USD) and the highest is 3,00,000 INR (4,463.23 USD) |
Olark | https://hackerone.com/olark | The rewards go from $100-$300 for critical disclosures |
Onshape | https://hackerone.com/onshape | / |
OpenSSL (IBB) | https://hackerone.com/ibb-openssl | The rewards go from $500-$5000 |
Optimizely | https://hackerone.com/optimizely | / |
Outbound | https://hackerone.com/outbound | The reward goe from $50-$1000+ |
OV-chipkaart | https://hackerone.com/ovchipkaart | / |
OVH | https://hackerone.com/ovh-group | Minimum reward is ?50 and our maximum rewards is ?10,000. |
ownCloud | https://hackerone.com/owncloud | The reward goes from $250-$5000 |
Paragon Initiative Enterprises | https://hackerone.com/paragonie | The rewards go from $1-$200+ |
Parse | https://hackerone.com/parseit | / |
PasteCoin | https://hackerone.com/pastecoin | The minimum reward for eligible bugs is 0.2 BTC. Rewards over the minimum are at our discretion, but we will pay significantly more for particularly serious issues. Only one reward per bug. |
PayPal | https://hackerone.com/paypal | Wall of fame |
Paysafecard | https://hackerone.com/paysafecard | Minimum reward $50 |
Perl (IBB) | https://hackerone.com/ibb-perl | The reward goes from $500-$1500 |
Phabricator | https://hackerone.com/phabricator | Bounty Range: ~$300 - $3,000, based on severity. |
https://hackerone.com/pinterest | $100 ? $5,000 per vulnerability | |
Piwik | https://hackerone.com/piwik | The bounty for valid critical security bugs is a $555 (US) cash reward. The bounty for non-critical bugs is $242 (US), paid via Paypal. |
Plaid | https://hackerone.com/plaid | The reward goes from $250-$2500 |
Pornhub | https://hackerone.com/pornhub | Minimum bounty $50 maximum $15 000 |
PortSwigger Web Security | https://hackerone.com/portswigger | The reward go from $100-$10000 |
Prezi | https://hackerone.com/prezi | The reward goes from $500+ |
Project Sopris | https://hackerone.com/project-sopris | / |
PullString | https://hackerone.com/toytalk | Minimum reward $100, maximum $5000 |
Python (IBB) | https://hackerone.com/ibb-python | Minimum reward $100, maximum $1500 |
QIWI | https://hackerone.com/qiwi | Minimum bounty $50 |
Qualcomm | https://hackerone.com/qualcomm | The rewards go from $200-$15000 |
Quiver | https://hackerone.com/quiver | Reward amounts will vary based upon the severity of the reported vulnerability. |
Quora | https://hackerone.com/quora | The rewards go from $100-$3000. Bonus up to $7000 for valid Remote Code Execution vulnerability identified in Quora.com server code. |
Qwant | https://hackerone.com/qwant | Qwant will offer a minimum reward of 50?. There is no maximum reward. |
RBKmoney | https://hackerone.com/rbkmoney | There are no rewards |
Rabobank | https://hackerone.com/rabobank | In most cases you are eligible for reward |
Raise | https://hackerone.com/raise | The rewards go from $100-$2000 |
ReleaseWire | https://hackerone.com/releasewire | The minimum reward for a verified bug is $25.00 USD. The total amount of the reward is based on several factors such as the severity of the issue. Only one (1) reward will be issued for each bug or security vulnerability. |
Reverb | https://hackerone.com/reverb | Reward amounts will vary based upon the severity of the reported vulnerability |
Rijksoverheid | https://hackerone.com/rijksoverheid | / |
Riot Games | https://hackerone.com/riot | Researchers who successfully identify and report particularly severe security issues will receive an appropriate bounty and an invite to access this program. |
Ripple | https://hackerone.com/ripple | Vulnerabilities that are harmless on their own, but could form part of a critical exploit will usually receive a bounty. Full-blown exploits can receive much higher bounties. |
Risk io | https://hackerone.com/riskio | / |
Rockstar Games | https://hackerone.com/rockstargames | Our minimum bounty for successful vulnerability submissions is $150. Depending on the severity and complexity of the identified potential vulnerability, higher bounties may be paid out at our discretion. |
RSK | https://hackerone.com/rsksmart | The rewards go from $750-$7000 |
Ruby | https://hackerone.com/ruby | The rewards go from $500-$1500+ |
Ruby on Rails | https://hackerone.com/rails | Decision to award a bounty is entirely at the discretion of the Panel. |
RubyGems | https://hackerone.com/rubygems | The rewards go from $500-$1500+ |
Social Blade | https://firebounty.com/bug-bounty-program/771/social-blade | Social Blade is not currently providing monetary rewards |
Souq | https://firebounty.com/bug-bounty-program/785/souq-com | The rewards go from $50-$1500 |
Stellar | https://firebounty.com/bug-bounty-program/832/stellar-org | 1point correspondes to 1 USD. The points go from 500 to 25000 |
SEMrush | https://firebounty.com/bug-bounty-program/867/semrush | Our vulnerability-reward payouts will go up to $3,000 USD for the most impactful exploits. If we accept your report, our minimum bounty is $50. |
Samsung Mobile | https://hackerone.com/samsungmobile | / |
Samsung SmartTV | https://hackerone.com/samsungsmarttv | Offers monetary bounty |
Schuberg Philis | https://hackerone.com/schubergphilis | T-shirt, donation to Room To Read,a bottle of Champagne |
SEMrush | https://hackerone.com/semrush | The rewards go from $150-$3000 |
Sentry | https://hackerone.com/sentry | / |
Shopify | https://hackerone.com/shopify | Minimum bounty $500-$10 000 |
Showmax | https://hackerone.com/showmax | Minimum reward $100, maximum reward $1000 |
Silent Circle | https://hackerone.com/silentcircle | The standard reward is $128.00 USD. Reward amounts may vary depending upon the severity of the vulnerability reported |
Simple | https://hackerone.com/simple | / |
SimplyBuilt | https://hackerone.com/simplybuilt | / |
Slack | https://hackerone.com/slack | The rewards go from $50-$1500 |
Snapchat | https://hackerone.com/snapchat | The rewards go from $2000-$15000 |
Sourcegraph | https://hackerone.com/sourcegraph | Rewards for open bounties range from $10 to $4,000 |
Spotify | https://hackerone.com/spotify | Minimum bounty $250 |
Starbucks | https://hackerone.com/starbucks | The rewards go from $100-$4000 |
StatusPage io | https://hackerone.com/statuspageio | $100 ? $1,500 per vulnerability |
Stripe | https://hackerone.com/stripe | Minimum reward of $100 |
Sunrise | https://hackerone.com/sunrise | / |
Swisscom | https://hackerone.com/swisscom | / |
Symphony | https://hackerone.com/symphony-3 | / |
Synology | https://hackerone.com/synology | Qualified reports will be rewarded between US$50 and $10,000. Web Services in Scope Qualified reports will be rewarded between US $50 and $2,000. |
Tarsnap | https://hackerone.com/tarsnap | The rewrads go from $1-$2000 |
Telegram | https://hackerone.com/telegram | / |
Tencent | https://hackerone.com/tencent | / |
Teradici | https://hackerone.com/teradici | Currently Teradici does not offer bounty at this moment. |
Tesla | https://hackerone.com/teslamotors | Hall of Fame. You may also be considered for an award if you are the first researcher to report one of the top 3 confirmed vulnerabilities in a calendar quarter. |
The Internet | https://hackerone.com/internet | |
Tinfoil Security | https://hackerone.com/tinfoilsecurity | / |
Tor | https://hackerone.com/torproject | The rewards go from $100-$4000 |
Trello | https://hackerone.com/trello | Our minimum reward is currently $256 USD, and we expect to pay $4096+ for major vulnerabilities. |
trivago | https://hackerone.com/trivago | / |
TTS Bug Bounty | https://hackerone.com/tts | The rewards go from $250-$5000 |
Tweakers | https://hackerone.com/tweakers | / |
Twilio | https://hackerone.com/twilio | $100 ? $5,000 per vulnerability |
https://hackerone.com/twitter | Minimum bounty $140, maximum bounty $20000+ | |
Uber | https://hackerone.com/uber | The awards go from $0-$10000 depends on the issue |
Ubiquiti Networks | https://hackerone.com/ubnt | Ubiquiti Networks doesn't specify the monetary awards |
Udemy | https://hackerone.com/udemy | $50 minimum bounty |
Unikrn | https://hackerone.com/unikrn | Unikrn offers monetary rewards. The amount depends on the reported vulnerability. |
United Airlines | https://hackerone.com/united | Maximum payout in award miles: From 50000-1000000 |
Upserve | https://hackerone.com/upserve | The awards go from $100-$2500 |
USAA | https://hackerone.com/usaa | / |
Valve | https://hackerone.com/valve | The rewards go from $200-$3000 |
Van Lanschot | https://hackerone.com/vanlanschot | / |
Vanilla | https://hackerone.com/vanilla | The rewards go from $150-$600 |
Veridu | https://hackerone.com/veridu | At our discretion, we may set the reward amount based on the creativity or severity of the bugs. |
VHX | https://hackerone.com/vhx | Bounty amounts are determined by a panel based on the type, severity, exposure, difficulty to exploit, quality of report and other factors. |
Vimeo | https://hackerone.com/vimeo | Not specified |
VK com | https://hackerone.com/vkcom | The minimum reward is $100. |
WakaTime | https://firebounty.com/bug-bounty-program/831/wakatime | / |
Wamba | https://hackerone.com/wamba | The reward goes from $100-$3000 depending on the issue |
We Do Trash | https://hackerone.com/we_do_trash | / |
Websecurify | https://hackerone.com/websecurify | The award value varies depending on the severity and creativity of your finding. |
WePay | https://hackerone.com/wepay | Minimum bounty $100 |
Werken Bij Defensie | https://hackerone.com/werkenbijdef | / |
Western Union | https://hackerone.com/westernunion | $100 ? $5,000 per vulnerability |
WHMCS | https://hackerone.com/whmcs | / |
WINK | https://hackerone.com/wink_jq3al | Minimum $100 |
WordPoints | https://hackerone.com/wordpoints | We offer small bounties for valid bugs. We may award larger bounties if we think the bug is more serious. |
Xiaomi | https://hackerone.com/xiaomi | Rewards are limited to vulnerabilities that are being reported for the first time to the Xiaomi Security Center. |
Yahoo! | https://hackerone.com/yahoo | Rewarrds go up to $15000 |
Yammer | https://hackerone.com/yammer | Qualified submissions are eligible for a minimum payment of $500 USD up to a maximum of $15,000 USD. |
Yandex | https://hackerone.com/yammer | The rewrads go from $160-$3000 |
YouPorn | https://hackerone.com/youporn | The rewards go from $250-$15000 |
YouTube | https://hackerone.com/youtube | Google Vulnerability Reward Program |
ZOHO | https://firebounty.com/bug-bounty-program/839/zoho | Not specified |
Zapier | https://hackerone.com/zapier | Not specified |
Zendesk | https://hackerone.com/zendesk | The rewards go from $100-$3000+ |
Zopim | https://hackerone.com/zopim | The rewards go from $100-$3000+ |
Anghami | https://hackerone.com/anghami | / |
Binary.com Cashier | Program suspended | |
Block io | https://hackerone.com/blockio | The minimum payout is $10 for reporting a previously unknown security vulnerability of sufficient severity with possibility for direct exploitation. There is no maximum reward But the program is disabled |
Blockchain | https://www.blockchain.com/ | From $50- <$1600 |
Boozt Fashion AB | https://hackerone.com/boozt | Our security bug bounty reward budget is between 50$ and 500$, lowest being minor security issues and highest being severe bugs like SQL injection or remote code execution. Boozt Fashion AB is taking a break and is not accepting new submissions. |
Coin.Space | https://hackerone.com/coinspace | The minimum payout is $125 for reporting a previously unknown security vulnerability of sufficient severity with possibility for direct exploitation. There is no maximum reward Coin.Space has been disabled. |
drchrono | https://hackerone.com/drchrono | Our minimum reward for reports that demonstrate leaked or modified doctor or patient data is $50 USD. There is no maximum.For reports that demonstrate PHI exposure from outside of the owner's account (does not require malicious staff), we will award a minimum of $200. For large-scale PHI exposure from outside the account, we will award a minimum of $500. drchrono has been disabled |
Enter | https://hackerone.com/enter | The minimum payout is $250 for reporting a previously unknown security vulnerability of sufficient severity with possibility for direct exploitation. There is no maximum reward. No longer taking new submissions |
Flash (IBB) | / | |
Flox | / | |
Gratipay | https://hackerone.com/gratipay | Not Active anymore |
itBit Exchange | https://hackerone.com/itbit | Reward amounts may vary depending upon the severity of the vulnerability reported.CRITICAL (Awarded at or above $2,000)HIGH (Awarded at $1,000 +/- depending on impact)MEDIUM/LOW (Awarded up to $500)No longer taking new submissions |
LeaseWeb | https://hackerone.com/leaseweb | Minimum of $50 No longer taking new submissions |
Legal Robot | https://hackerone.com/legalrobot | The rewrads go from $20-??? No longer taking new submissions |
MapsMarker.com e.U. | https://hackerone.com/mapsmarker_com_e_u | The rewrads go from $10-$100 No longer taking new submissions |
Mixmax | https://hackerone.com/mixmax | If you find a severe security vulnerability such that you can access or modify another Mixmax user's data, you'll be rewarded with a free Mixmax Professional account for a year ($288 value!) No longer taking new submissions |
MS-DOS | / | The bounty program has come to an end |
Munzee | https://hackerone.com/munzee | / |
Openfolio | https://hackerone.com/openfolio | / |
SecNews | https://hackerone.com/secnews | The monetary reward is from 50? - 3000?. But also there are things like Recognition on the website etc. No longer taking new submissions |
Square Open Source | https://hackerone.com/square-open-source | / |
Sucuri | https://hackerone.com/sucuri | minimum reward is $250 USD. But right now Sucuri is not taking any more submissions |
VLC | https://hackerone.com/vlc | The rewards go from $250-$5000 No longer taking new submissions |
WebSummit | https://hackerone.com/websummit | Websummit is no longer taking submissions |
Whisper | https://hackerone.com/whisper | Whisper is no longer taking new submissions No longer taking new submissions |
withinsecurity | https://hackerone.com/withinsecurity | withinsecurity has been disabled |
WP API | https://hackerone.com/wp-api | No longer taking new submissions |
Cisco | https://www.cisco.com/c/en/us/about/security-center/security-vulnerability-policy.html | / |
Magento | https://bugcrowd.com/magento | $100 ? $10,000 per vulnerability |
PHP | https://hackerone.com/ibb-php | The rewards go from $500-$1500+ |
Word Press | https://hackerone.com/wordpress | / |
Weblate | https://firebounty.com/bug-bounty-program/835/weblate | / |
Zomato | https://hackerone.com/zomato/ | The minimum reward for severe bugs like Remote Code Execution or User Personal Information Access is $1000 USD. |
123 Contact Form | https://www.123formbuilder.com/security-acknowledgements/?pagetype=htmlandingpages | / |
Acquia | https://www.acquia.com/how-report-security-issue | Hall of fame |
ebay | https://pages.ebay.com/securitycenter/security_researchers.html | Public thank you. |
AVG | https://bugcrowd.com/avgtechnologies | $50 ? $1,000 per vulnerability |
Buffer | https://buffer.com/security | Monetary bounty. |
Ubuntu | https://help.ubuntu.com/lts/serverguide/reporting-bugs.html#reporting-bugs-apport-cli | / |
Tumbler | https://tumblr.zendesk.com/hc/en-us/articles/234583348-Bug-Bounty-Program | Rewards may range from Tumblr-branded swag to monetary rewards up to $5,000 USD |
Sony | https://hackerone.com/sony | / |
Netflix | https://bugcrowd.com/netflix | $100 ? $15,000 per vulnerability |
NASA | https://firebounty.com/bug-bounty-program/589/nasa | / |
Medium | https://help.medium.com/hc/en-us/articles/213481308-Bug-Bounty-Disclosure-Program | Based on severity of the bug the rewards can go up to $1000 |
Huawei | https://firebounty.com/bug-bounty-program/139/huawei | / |
Humble Bundle | https://bugcrowd.com/humblebundle | Hall of fame |
Hootsuite | https://hootsuite.com/security/response | / |
Freelancer | https://www.freelancer.com/about/security | Hall of fame |
Apple | https://support.apple.com/en-au/HT201220 | / |
Amazon | https://aws.amazon.com/security/vulnerability-reporting/ | / |
Airbnb | https://hackerone.com/airbnb/ | Maximum bounty is $15,000 USD based on the issue |
Adobe | https://hackerone.com/adobe | / |
HTC | https://www.htc.com/us/terms/product-security/ | / |
MailChimp | https://hackerone.com/mailchimp | / |
Opera | https://www.opera.com/security/policy | / |
Soundcloud | https://hackerone.com/soundcloud | / |
AOL | https://contact.security.aol.com/ | / |
Linksys | https://hackerone.com/linksys | / |
Malwarebytes | https://www.malwarebytes.com/secure/ | he amount awarded for these bugs is between $100 and $1000 depending on the bug severity and exploitability. Hall of fame |
McAfee | https://www.mcafee.com/us/threat-center/product-security-bulletins.aspx#=tab-1 | / |
PubNub | https://firebounty.com/bug-bounty-program/764/pubnub | Monetary bounty. |
Okta | https://firebounty.com/bug-bounty-program/752/okta | The rewards go from $50-up to $15000 |
Smarsheet | https://firebounty.com/bug-bounty-program/754/smartsheet | / |
HubSpot | https://firebounty.com/bug-bounty-program/750/hubspot-responsible-disclosure | / |
SecureDrop | https://firebounty.com/bug-bounty-program/745/securedrop | / |
Circle | https://firebounty.com/bug-bounty-program/746/circle-mobile-apps | $50 dollar reward |
U.S. Dept Of Defense | https://firebounty.com/bug-bounty-program/742/u-s-dept-of-defense | Hall of fame |
Terapeak | https://firebounty.com/bug-bounty-program/741/terapeak | Monetary bounty. |
Pushwoosh | https://firebounty.com/bug-bounty-program/739/pushwoosh | Hall of fame |
Mindoktor | https://firebounty.com/bug-bounty-program/734/mindoktor | Minimum reward is $100 USD, maximum reward $10000 |
CoderzWar | https://firebounty.com/bug-bounty-program/732/coderzwar | Hall of fame |
Moneybird | https://hackerone.com/moneybird | Monetary bounty. |
OLX | https://firebounty.com/bug-bounty-program/722/olx | The rewards don't include monetary bounty |
Skyliner | https://firebounty.com/bug-bounty-program/710/skyliner | / |
Instacart | https://firebounty.com/bug-bounty-program/712/instacart | Hall of fame |
Kaspersky Lab | https://firebounty.com/bug-bounty-program/714/kaspersky-lab | Monetary bounty. |
Yelp | https://firebounty.com/bug-bounty-program/704/yelp | Our vulnerability-reward payouts will go up to $15,000 USD for the most impactful exploits. If we accept your report, our minimum bounty is $100. |
Sophos Responsible Disclosure | https://firebounty.com/bug-bounty-program/698/sophos-responsible-disclosure | Awards are granted entirely at the discretion of Sophos. |
Manalyzer | https://firebounty.com/bug-bounty-program/688/manalyzer | A maximum of two bounties will be awarded per person. |
ProtonMail | https://firebounty.com/bug-bounty-program/611/protonmail | Minimm bounty $50, maximum bounty $500 |
HP | https://firebounty.com/bug-bounty-program/4/hp | / |
Imgur | https://firebounty.com/bug-bounty-program/1/imgur | Recognition on our Hall of Fame,minimum of $50,an Imgur t-shirt |
Groupon | https://firebounty.com/bug-bounty-program/496/groupon | / |
Bitcasa | https://firebounty.com/bug-bounty-program/35/bitcasa | Site can't be reached |
Bing | https://firebounty.com/bug-bounty-program/34/bing | / |
Dato Capital | https://firebounty.com/bug-bounty-program/78/dato-capital | Hall of fame |
Gliph | https://firebounty.com/bug-bounty-program/125/gliph | / |
Honeywell | https://firebounty.com/bug-bounty-program/136/honeywell | / |
Meldium | https://firebounty.com/bug-bounty-program/195/meldium | / |
Panasonic | https://firebounty.com/bug-bounty-program/232/panasonic | / |
Twitch | https://firebounty.com/bug-bounty-program/320/twitch | / |
DPD | https://firebounty.com/bug-bounty-program/447/dpd | Hall of fame |
Gallery | https://firebounty.com/bug-bounty-program/448/gallery | Monetary bounty from $100-$1000 |
You Need a Budget (YNAB) | https://bugcrowd.com/ynab | $100 ? $1,500 per vulnerability |
Volusion V1 | https://bugcrowd.com/volusion | $25 ? $500 per vulnerability |
TYPO3 | https://typo3.org/community/teams/security/ | / |
Tuenti | https://corporate.tuenti.com/en/dev/security | / |
Trend Micro | https://success.trendmicro.com/vulnerability-response | Hall of fame |
Transloadit | https://transloadit.com/security/ | Hall of fame |
Telenet Belgium | http://binaries.telenet.be/onlinesupport/pdf/responsible_disclosure_policy_en.pdf | / |
Team Unify | https://www.teamunify.com/swim-team-management-software/security/ | / |
Spokeo | https://www.spokeo.com/bug-bounty | The minimum bounty amount for a validated bug submission is $50 USD and the maximum bounty for a validated bug submission is $5,000 USD. |
Splitwise | https://blog.splitwise.com/about/responsible-disclosure-special-thanks/ | Hall of fame |
Alcyon | https://www.alcyon.nl/responsible-disclosure/ | / |
Altervista | https://en.altervista.org/credits.php | Hall of fame |
Amara | https://amara.org/en/security | |
Appcelerator | https://www.appcelerator.com/privacy/responsible-disclosure-of-security-vulnerabilities/ | Hall of fame |
ARM mbed | https://tls.mbed.org/bug-bounty-program | Minimum payout is 250 EURO |
Atlassian | https://bugcrowd.com/atlassian | $100 ? $3,000 per vulnerability |
Automattic | https://hackerone.com/automattic | Monetary bounty |
Base | https://getbase.com/security/ | / |
Basecamp | https://basecamp.com/about/policies/security | Hall of fame |
BitPay | https://support.bitpay.com/hc/en-us/articles/204229369-BitPay-Bug-Bounty-Program | / |
BitWall | http://www.bitwall.io/security | Hall of fame |
Blinksale | https://bugcrowd.com/blinksale?utm_source=the-list&utm_medium=list-link&utm_campaign=blinksale | Points per vulnerability |
Box | https://www.box.com/about-us/security | / |
Envato | https://webuild.envato.com/helpful-hacker/ | Hall of fame |
Internetwache | https://en.internetwache.org/security/ | Hall of fame |
Juniper | https://www.juniper.net/us/en/security/report-vulnerability/ | / |
MobiKwik | https://www.mobikwik.com/bug-bounty | minimum reward or bounty is ?1000. |
Motorola | https://www.motorolasolutions.com/en_us/about/security-vulnerability.html | Monetary bounty and hall of fame |
Myntra | https://www.myntra.com/security/whitehat | Hall of fame |
Own Cloud | https://owncloud.org/security/ | / |
Pidgin | http://pidgin.im/security/ | / |
Digital Ocean | https://www.digitalocean.com/security/ | / |
Braintree | https://www.braintreepayments.com/developers/disclosure | Hall of fame |
Blackboard | http://www.blackboard.com/footer/security-policy.html | / |
Coupa | https://success.coupa.com/Trust/Security_Policies/Vulnerability_Reporting_Policy | No compensation |
Detectify | https://blog.detectify.com/2013/12/03/detectify-responsible-disclosure-program/ | Hall of fame |
Eclipse | http://www.eclipse.org/security/ | / |
Acorns LLC | https://bugcrowd.com/acorns | $25 ? $500 per vulnerability |
ActiveProspect | https://activeprospect.com/security/ | Hall of fame |
ActiVPN | https://bugcrowd.com/activpn?utm_source=the-list&utm_medium=list-link&utm_campaign=activpn | Points per vulnerability |
Apptentive | https://www.apptentive.com/privacy/ | / |
Asterisk | https://wiki.asterisk.org/wiki/display/AST/Asterisk+Bug+Bounties | / |
Atlassian - JIRA/Confluence Cloud | https://bugcrowd.com/atlassian | $100 ? $3,000 per vulnerability |
Auth0 | https://auth0.com/whitehat | Hall of fame |
Beanstalk | https://support.beanstalkapp.com/article/890-responsible-disclosure-policy | Hall of fame, T-shirt, no monetary reward |
Bithunt | https://hackerone.com/bithunt | No monetary reward |
Bosch | https://psirt.bosch.com/en/responsibleDisclosurePolicy.html | / |
BTX Trader | https://www.btxtrader.com/bugbounty.html#/bugbounty | / |
Caffeine | https://bugcrowd.com/caffeine | $100 ? $3,000 per vulnerability |
Centrify | https://bugcrowd.com/centrify | $100 ? $3,000 per vulnerability |
Chargify | https://bugcrowd.com/chargify?utm_source=the-list&utm_medium=list-link&utm_campaign=chargify | Points per vulnerability |
Chronobank | https://blog.chronobank.io/chronobank-bug-bounty-program-269d97b9a5b1 | / |
CircleCi | https://circleci.com/security/ | Hall of fame |
CloudFlare | https://hackerone.com/cloudflare | Hall of fame |
Code Climate | https://codeclimate.com/security | Hall of fame |
Codeigniter | https://hackerone.com/codeigniter | Hall of fame |
Coin Space BTC | https://hackerone.com/coinspace | The minimum payout is $125 for reporting a previously unknown security vulnerability of sufficient severity with possibility for direct exploitation. There is no maximum reward. |
Commonsware | https://commonsware.com/bounty.html | / |
Compose | https://www.compose.com/security | Hall of fame |
Constant Contact | https://bugcrowd.com/constantcontact | Points per vulnerability |
Coursera | https://hackerone.com/coursera | Hall of fame |
CrowdShield | https://crowdshield.com/bug-bounty-list.php?bug_bounty_program=crowdshield | / |
Customer Insight | https://customerinsight.ca/CI/security-statement/ | No compensation |
Dash Digital Cash | https://bugcrowd.com/dashdigitalcash | $100 ? $10,000 per vulnerability |
Dash Messaging | https://bugcrowd.com/dashmessaging | Points per vulnerability |
Debian Security Tracker | https://www.debian.org/Bugs/ | / |
Dell | http://www.dell.com/learn/us/en/04/campaigns/report-vulnerability | / |
DigitalSellz | https://hackerone.com/digitalsellz | / |
DNN Corporation | http://www.dnnsoftware.com/platform/share/bug-reporting | / |
DNSimple | https://dnsimple.com/security | Hall of fame |
DPD | https://getdpd.com/security/ | Hall of fame, and monetary reward |
eero | https://bugcrowd.com/eero | Points & Swag per vulnerability |
EMC | https://www.emc.com/products/security/product-security-response-center.htm | / |
Envoy | https://hackerone.com/envoy | Minimum reward $100 |
Eventbrite | https://www.eventbrite.com/security/ | / |
Event Espresso | https://eventespresso.com/report-a-security-vulnerability/ | / |
Evernote | https://evernote.com/security/ | / |
Expatistan | https://www.expatistan.com/security | Hall of fame |
ExpressionEngine | https://hackerone.com/expressionengine | / |
Factlink | https://hackerone.com/factlink | Hall of fame |
Fiat Chrysler Automobiles | https://bugcrowd.com/fca | $150 ? $1,500 per vulnerability |
Fireeye | https://www.fireeye.com/company/security.html | / |
Fitbit | https://bugcrowd.com/fitbit | $100 ? $2,500 per vulnerability |
Foursquare | https://foursquare.com/about/security | Hall of fame |
FoxyCart | https://bugcrowd.com/foxycart?utm_source=the-list&utm_medium=list-link&utm_campaign=foxycart | $25 ? $500 per vulnerability |
Freshbooks | https://www.freshbooks.com/policies/responsible-disclosure | Hall of fame |
GateCoin | https://gatecoin.com/bugBounty/ | Only one bounty will be awarded per vulnerability. |
Gemfury | https://gemfury.com/security | / |
General Motors | https://hackerone.com/gm | / |
GO-JEK | https://bugcrowd.com/gojek | $200 ? $5,000 per vulnerability |
Grok Learning | https://groklearning.com/security/ | Hall of fame |
Hack the Pentagon | https://www.hackerone.com/resources/hack-the-pentagon | Minimum $100, maximum $15000 |
Harmony | http://get.harmonyapp.com/security/ | Hall of fame |
Hex-Rays | https://www.hex-rays.com/bugbounty.shtml | Hex-Rays will pay a 3000 USD bounty for certain security bugs. |
IBM | https://www.ibm.com/security/secure-engineering/report.html | / |
ICEcoder | https://bugcrowd.com/icecoder?utm_source=the-list&utm_medium=list-link&utm_campaign=icecoder | Points per vulnerability |
Inflectra | https://www.inflectra.com/Company/Responsible-Disclosure.aspx | Hall of fame |
Informatica | https://hackerone.com/informatica | / |
IntegraXor (SCADA) | https://www.integraxor.com/integraxor-hmi-scada-bug-bounty-program/ | Reward points |
InVision | https://bugcrowd.com/invision | $100 ? $1,500 per vulnerability |
(ISC)ý | https://bugcrowd.com/isc2?utm_source=the-list&utm_medium=list-link&utm_campaign=isc2 | Points per vulnerability |
Issuu | https://issuu.com/responsible-disclosure | Hall of fame |
itBit Exchange | https://hackerone.com/itbit | The reward can go up to $2000+ |
iwantmyname | https://bugcrowd.com/iwantmyname?utm_source=the-list&utm_medium=list-link&utm_campaign=iwantmyname | Points per vulnerability |
Jet com | https://bugcrowd.com/jet?utm_source=the-list&utm_medium=list-link&utm_campaign=jet | $100 ? $15,000 per vulnerability |
JRuby | http://jruby.org/security | / |
Jumplead | https://jumplead.com/about/security | Hall of fame |
Keming Labs | https://keminglabs.com/security_disclosure/ | / |
Kenna Security | https://bugcrowd.com/kennasecurity | $50 ? $1,500 per vulnerability |
Khan Academy | https://hackerone.com/khanacademy | Hall of fame |
LastPass | https://bugcrowd.com/lastpass?utm_source=the-list&utm_medium=list-link&utm_campaign=lastpass | $10 ? $5,000 per vulnerability |
Localize | https://hackerone.com/localize | Localize has been disabled. |
Logentries | https://docs.logentries.com/docs/security/ | Hall of fame |
Magix AG | http://research.magix.com/ | Hall of fame |
Mattermost | https://about.mattermost.com/report-security-issue/ | Hall of fame |
Mavenlink | https://hackerone.com/mavenlink | Hall of fame + small bounties |
Maximum | https://hackerone.com/maximum | This reward will vary depending on the seriousness of the issue and the quality of the report. |
Mobile Vikings | https://hackerone.com/mobilevikings | Hall of fame |
Moodle | https://moodle.org/mod/forum/view.php?f=996&showall=1 | Broken link |
NetApp | https://security.netapp.com/contact/ | / |
Nvidia | https://www.nvidia.com/en-us/product-security/ | / |
OnePageCRM | https://bugcrowd.com/onepagecrm?utm_source=the-list&utm_medium=list-link&utm_campaign=onepagecrm | Points per vulnerability |
Open Xchange | https://hackerone.com/open-xchange | Minimum reward of $100 for vulnerabilities we consider to be serious, up to a maximum of $5000 for the most severe vulnerabilities |
Pantheon | https://bugcrowd.com/pantheon?utm_source=the-list&utm_medium=list-link&utm_campaign=pantheon | Points per vulnerability |
Panzura | https://panzura.com/support/panzura-security-policy/ | / |
Rackspace | https://www.rackspace.com/information/legal/rsdp | Hall of fame |
Relaso | http://relaso.com/disclosure | No compensation |
Segment io | https://segment.com/docs/legal/security/ | Hall of fame |
Sellfy | https://sellfy.com/security/ | Hall of fame |
SendSafely | https://bugcrowd.com/sendsafely?utm_source=the-list&utm_medium=list-link&utm_campaign=sendsafely | Points per vulnerability |
SiteGround | https://www.siteground.com/term/92.htm | Hall of afame |
Smart Budget | https://www.sbudget.com/people.pl | Hall of fame |
Socrata | https://bugcrowd.com/socrata?utm_source=the-list&utm_medium=list-link&utm_campaign=socrata | $25 ? $1,500 per vulnerability |
Solvinity | https://www.solvinity.com/responsible-disclosure | / |
SplashID | https://bugcrowd.com/splashid?utm_source=the-list&utm_medium=list-link&utm_campaign=splashid | Points per vulnerability |
Sprout Social | https://bugcrowd.com/sproutsocial?utm_source=the-list&utm_medium=list-link&utm_campaign=sprout_social | Points per vulnerability |
Tapatalk | https://tapatalk.com/security.php | / |
Unitag | https://www.unitag.io/security | Hall of fame |
Zynga | https://www.zynga.com/security/whitehats | Hall of fame |
Yesware | https://www.yesware.com/security/ | Hall of fame |
Xen | https://www.xenproject.org/security-policy.html | / |
Volcanic Pixels | https://www.volcanicpixels.com/security | / |
Viadeo | http://www.viadeo.com/en/securite | Hall of fame |
Symantec | https://www.symantec.com/en/uk/security-center/vulnerability-management | / |
Skuid | https://www.skuid.com/security/ | / |
Skoodat | http://www.skoodat.com/security | No compensation |
Sifter | https://sifterapp.com/policies/security/ | Hall of fame |
Riskalyze | https://www.riskalyze.com/legal#security-response | Hall of fame |
Red Hat | https://access.redhat.com/articles/66234 | Hall of fame |
https://help.getpocket.com/article/870-pocket-security-overview | Hall of fame | |
Paymill | https://developers.paymill.com/guides/security/security-standards | Hall of fame, monetary reward |
Paychoice | http://www.paychoice.com.au/security/#security-researchers | Hall of fame |
OpenText | https://www.opentext.com/who-we-are/copyright-information/security-acknowledgements | Hall of fame |
Offensive Security | https://www.offensive-security.com/bug-bounty-program/ | The rewards go from $200-$1000 based on the issue |
Foxycart | https://www.foxy.io/security-contact?redirected=true | Hall of fame |
Fog Creek | http://www.fogcreek.com/security/ | Hall of fame |
Fluxiom | https://www.fluxiom.com/security | Hall of fame |
Engineyard | https://www.engineyard.com/policies/privacy | Hall of fame |
Coindrawer | https://www.coindrawer.com/whitehat/ | The reward is determined based upon the severity of the bug discovered. Rewards are paid in BTC to the email address of a Coindrawer account holder. Plus Hall of fame |
Under Armour | https://bugcrowd.com/underarmour | Points per vulnerability |
Credit Karma | https://bugcrowd.com/creditkarma | $200 ? $3,000 per vulnerability |
Concur | https://bugcrowd.com/concur | Points per vulnerability |
Multicraft | https://bugcrowd.com/multicraft | $25 ? $750 per vulnerability |
NolimitVPN | https://bugcrowd.com/nolimitvpn | Points per vulnerability |
Marktplaats | https://hackerone.com/marktplaats | A typical bounty will vary from SWAG (goodies, gifts, presents) up to a bug-bounty of ?350,-. (based on the probability and the damage impact of exploitatio |
Robinhood | https://hackerone.com/robinhood | The minimum payout is $100 USD |
Paytm | https://bugbounty.paytm.com/ | The minimum reward for eligible bugs is the equivalent of 1000 INR. Only one reward per bug. |
Android Free Apps | https://www.google.com/about/appsecurity/android-rewards/ | The rewards go from $330 up to $200 000 |
Certly | https://hackerone.com/certly | Hall of fame |
Doorkeeper | https://www.doorkeeper.jp/responsible_disclosure?locale=en | Hall of fame |
Firebase | https://firebase.google.com/support/#section-security | / |
MCProHosting | https://bugcrowd.com/mcprohostings?utm_source=the-list&utm_medium=list-link&utm_campaign=mcprohostings | Points per vulnerability |
Solve360 | https://solve360.com/security-response/ | Hall of fame |
Monetha | https://www.monetha.io/bounty | The rewards go from $100-$10 000 |
Ledger | https://www.ledger.fr/bounty-program/ | The amount of each bounty is based on the classification and sensitivity of the data impacted. Bounties will be paid directly to the researcher using Bitcoin. |
https://hackerone.com/whatsapp | Facebook White Hat program | |
Tinder | https://www.gotinder.com/security | Tinder?s bug bounty program is private and inclusion is by invite only. |
McDelivery | https://www.mcdelivery.co.in/bugBounty | Monetary reward for each valid bug reported would be based on criticality of the issue. |
ExpressVPN | https://www.expressvpn.com/features/bug-bounty | ExpressVPN offers financial rewards and recognizes your contribution to the security of our services |
PureVPN | https://firebounty.com/bug-bounty-program/250/purevpn | / |
Hunter | https://hunter.io/security-bounty-program | Our reward system is flexible and doesn?t have any strict upper or lower limit. |
Razer US | https://hackerone.com/razer_us | / |
GoCD | https://firebounty.com/bug-bounty-program/720/gocd | / |
Projectplace | https://firebounty.com/bug-bounty-program/621/projectplace | Our minimum reward is $20 USD; our maximum is $1000 USD. Rewards are completely at the discretion of Projectplace. |
Clef | https://firebounty.com/bug-bounty-program/429/clef | The minimum reward offered to whitehat researchers is $32 USD (paid in Bitcoin or USD, your choice). |
ClickUp | https://clickup.com/bug-bounty | No minimum or maximum reward. |
Aircloak | https://aircloak.com/compliance/attack-challenge/ | Hall of fame, $5000 reward |
Ancient Brain | https://ancientbrain.com/bugs.php | ? 20 for a minor bug. ? 100 for a major bug. ? 200 for a critical bug. |
C2FO | https://hackerone.com/c2fo | Hall of fame, no monetary reward. |
Cayan | https://cayan.com/developers/knowledge-base/faqs/does-cayan-have-a-bug-bounty-program | You can receive a reward of at least $250. |
CS:GO (2) | https://csgoblackjack.com/bug-bounty | No maximum and no minimum reward |
Drupal | https://www.drupal.org/node/101494 | Hall of fame |
Garmin | https://www.garmin.com/de-DE/legal/security#report | / |
MacKeeper | https://firebounty.com/bug-bounty-program/696/mackeeper | Monetary reward. |
Mimecast | https://www.mimecast.com/responsible-disclosure/ | Hall of fame |
Odoo | https://www.odoo.com/de_DE/page/responsible-disclosure | Hall of fame |
Phillips | https://www.philips.com/a-w/security/coordinated-vulnerability-disclosure.html | / |
Recorded Future | https://www.recordedfuture.com/security/ | Hall of fame T-Shirt |
Rocket-Chat | https://rocket.chat/docs/contributing/security/ | Hall of fame |
Spreaker | https://www.spreaker.com/security | Rewards for qualifying bugs range from $100 to $1,000, sent to your PayPal account |
ChargeOver | http://help.chargeover.com/article/show/38302-bug-bounty-program | Payouts range from $25 USD to $1000 USD depending on the severity of the issue found. |
Webmini | https://www.webmini.com/de/responsible-disclosure/ | WebMini |
StarLeaf | https://www.starleaf.com/c/bug-bounty-program/ | The rewards go from $50-$1000+ |
Parity Technologies | https://paritytech.io/bug-bounty/ | The minimum reward for eligible bugs is the equivalent of 100 USD in ETH/BTC. |
LiveAgent | https://www.ladesk.com/liveagent-bug-bounty-program/ | The regular bounty reward is $50 per bounty submitted and verified by our dev team. |
Artifex | https://artifex.com/developers-bug-bounty-program/ | Accepted fixes for bugs at P1 and P2 pay a bounty of US$2,000 each. Bugs at lower priorities and ?normal? importance pay US$1,000 per bug. Bugs designated with ?trivial? or ?minor? importance pay a negotiated amount, typically US$200 per bug |
Request Network | https://blog.request.network/request-network-bug-bounty-live-ee3297e46695 | The rewrards go fro $500-$20000 |
Yatra | https://www.yatra.com/online/bug-bounty | Wall of fame |
TenX | https://www.tenx.tech/whitehat.html | The rewards go from $1000-$10000 |
FIRST | https://www.first.org/about/bugs | Hall of fame |
Make My Trip | https://www.makemytrip.com/pwa-hlp/mmtbb/report | Hall of fame |
WhatRuns | https://www.whatruns.com/bug-bounty | Rewards range from $100 up to $5000 and are determined at our discretion based on numerous factors. |
Nano | https://medium.com/@nanocurrency/nano-bug-bounty-program-e45acd888eb3 | Monetary reward |
Windows | https://blogs.technet.microsoft.com/msrc/2017/07/26/announcing-the-windows-bounty-program/ | The reward can go up to $250 000 |