0% found this document useful (0 votes)
4 views79 pages

Bug Bounty Programs | HackerOne

Bug bounty programs incentivize ethical hackers to identify and report vulnerabilities to organizations, enhancing security and building trust. These programs allow companies to continuously monitor their systems and leverage the expertise of the hacker community. The document lists various known bug bounty programs available through HackerOne, detailing their scope and minimum bounty amounts.

Uploaded by

longmuirj3
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views79 pages

Bug Bounty Programs | HackerOne

Bug bounty programs incentivize ethical hackers to identify and report vulnerabilities to organizations, enhancing security and building trust. These programs allow companies to continuously monitor their systems and leverage the expertise of the hacker community. The document lists various known bug bounty programs available through HackerOne, detailing their scope and minimum bounty amounts.

Uploaded by

longmuirj3
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Bug Bounty Programs

Learn more about HackerOne Bug Bounty

Platform
What is a bug bounty program?
Bug bounty programs reward ethical hackers who identify and responsibly
Solutions

disclose vulnerabilities to the application’s developer, before attackers can


exploit them. By engaging a diverse, global community of experts,
Partners
organizations continuously monitor and test their attack surface, uncover
hard-to-find vulnerabilities, reduce risk, and build customer trust. Bug
bounty programs allow companies to leverage the hacker community to
Researchers
improve their systems’ security posture over time.

Resources
Below is a list of known bug bounty programs from the HackerOne
opportunity page. If you are interested in learning more about setting up a
bug bounty program for your organization, see the HackerOne
Company Bounty
product page.

Get Started

[Link] 5/29/26, 13 37
Page 1 of 79
:
Login
CarrerZooms
[Link]/carrerzooms

Security Test External Program + Invite-only


See @security.
[Link]/security-test-ep-invite-only

1Password - CTF
O!ers bounties $50 minimum bounty
AgileBits/1Password introduced a $1 million CTF bug bounty challenge in 2022 to
further our commitment to providing an industry-leading security platform for
individuals, families, and businesses. Other Security Research Opportunities ==This
program…
[Link]/1password_ctf

1Password - Enterprise Password Manager


O!ers bounties $50 minimum bounty
Get started This isn’t an easy program — scanners are unlikely to help, and standard
XSS-type injections won't yield much either. We need creative researchers who aren’t
afraid to think outside the box. We're happy you're here. Start with the…
[Link]/1password

1win
O!ers bounties $50 minimum bounty
Program scope This Vulnerability Disclosure Program applies only to the identification
and reporting of technical security issues affecting the company’s services. Cases not
eligible for a reward No bounty will be paid, and such activity may lead to…
[Link]/1win_com

23andMe Bug Bounty


Managed O!ers bounties $50 minimum bounty

[Link] 5/29/26, 13 37
Page 2 of 79
:
Welcome, Security Research Community! 23andMe recognizes the importance of
working with skilled security researchers to identify and address vulnerabilities in our
technology. We encourage responsible disclosure through our Bug Bounty Program
and…
[Link]/23andme_bbp

3CX
Managed O!ers bounties $50 minimum bounty

Who we are 3CX is a global leader in business communications, being used by more
than 350,000 companies around the world. Taking advantage of the SIP open-standard
and WebRTC technology, 3CX has evolved from its roots as a PBX phone system to
a…
[Link]/3cx

8x8
O!ers bounties $100 minimum bounty

At 8x8, we help companies get their employees, customers and applications talking to
make people more connected and productive no matter where they are in the world. At
8x8 we value security and recognize the importance of ensuring the integrity and…
[Link]/8x8-bounty

Achievable
[Link]
[Link]/achievable

Acronis
O!ers bounties $100 minimum bounty

Acronis looks forward to working with the security community to find security
vulnerabilities in order to keep our businesses and customers safe. Rules for us We
respect the time and effort of our researchers We will respond within 5 business days…
[Link]/acronis

A!irm
Managed O!ers bounties $100 minimum bounty

[Link] 5/29/26, 13 37
Page 3 of 79
:
Managed O!ers bounties $100 minimum bounty
Introduction Affirm looks forward to working with the security community to find
security vulnerabilities in order to keep our businesses and customers safe. Response
Times Affirm will make a best effort to meet our response targets for hackers…
[Link]/a!irm

Airbnb
O!ers bounties
Join us to secure our Airbnb community! Have you discovered a potential security
vulnerability? Your expertise is invaluable. Partner with us by responsibly disclosing the
issue—your action is critical to protecting our global community. Share your…
[Link]/airbnb

Airlock Secure Access Hub


Airlock Secure Access Hub protects more than 30,000 web applications worldwide. We
have a private bug bounty program on HackerOne in which the security features of the
Web Application Firewall (WAF) and Identity and Access Management (IAM) solution…
[Link]/airlock

Airtable
Managed O!ers bounties $50 minimum bounty
Airtable considers privacy and security to be core functions of our platform. Earning
and keeping the trust of our users is our top priority, so we hold ourselves to the
highest privacy and security standards. If you have discovered a security issue…
[Link]/airtable

Akamai
Akamai CDN The Akamai Bug Bounty Program currently operates as a soft-launch,
invite-only, semi-private program. At this time, we are primarily interested in findings
relating to the CDN, the communications between our proxy layer and the origins,…
[Link]/akamai

Aliexpress
If you believe you have found a vulnerability within an asset relating to AliExpress,

[Link] 5/29/26, 13 37
Page 4 of 79
:
please submit it via the Alibaba Vulnerability Disclosure Program
([Link] This is a vulnerability disclosure program and
therefore we…
[Link]/aliexpress

ALSCO
O!ers bounties $50 minimum bounty
ALSCO Promise ALSCO looks forward to working with the security community to find
vulnerabilities in order to keep our businesses and customers safe. Secure Gateway
Promise At ALSCO, we are committed to partnering with the security community to…
[Link]/alsco

Amazon Vulnerability Research Program


Managed O!ers bounties $100 minimum bounty
Amazon Vulnerability Research Program (VRP) - Program Policy Introduction At
Amazon, we take security and privacy very seriously. If you believe that you have found
a security vulnerability that affects any Amazon product or service, please report…
[Link]/amazonvrp

Amazon Vulnerability Research Program - Devices


Managed O!ers bounties $50 minimum bounty
Amazon Devices and Services Bug Bounty Program Overview Safeguarding our
customers’ security is a top priority. We recognize that performing high quality security
research requires considerable amount of effort, time, and skills investment from…
[Link]/amazonvrp-devices

Android
Android Security Rewards Program Rules The Android Security Rewards program
recognizes the contributions of security researchers who invest their time and effort in
helping us make Android more secure. Through this program we provide monetary…
[Link]/android

Anduril Industries
Managed O!ers bounties $50 minimum bounty

[Link] 5/29/26, 13 37
Page 5 of 79
:
Disclosure Policy We currently don't disclose reports marked as Informative.
Exceptional reports may be considered for disclosure on a case-by-case basis.
Program Rules Please provide detailed reports with reproducible steps. If the report is
not…
[Link]/anduril_industries

Anthropic
Managed O!ers bounties $50 minimum bounty
The security of our systems and user data is Anthropic's top priority. We appreciate the
work of security researchers acting in good faith to identify and report potential
vulnerabilities. Involving researchers through our bug bounty program helps…
[Link]/anthropic

Aptible
Please see our Responsible Disclosure Policy
([Link] Do not test or report on out-
of-scope issues.
[Link]/aptible

Arkose Labs
Managed O!ers bounties $50 minimum bounty
At Arkose Labs, we take cybersecurity seriously and appreciate the valuable
contributions from the wider security community. We encourage security research
individuals to test our security, and we offer rewards for valid reported vulnerabilities…
[Link]/arkose_labs

Artsy
We welcome security researchers that practice responsible disclosure and comply with
our policies. Programs by Google, Facebook, Mozilla, and others have helped to create
a strong bug-hunting community. The Artsy bug bounty program gives a tip of…
[Link]/artsy

Asana
Responsible Disclosure Security of user data and communication is of utmost
importance to Asana. In pursuit of the best possible security for our service, we

[Link] 5/29/26, 13 37
Page 6 of 79
:
importance to Asana. In pursuit of the best possible security for our service, we
welcome responsible disclosure of any vulnerability you find in Asana. Principles of…
[Link]/asana

ASN Bank
ASN Bank is committed to providing its customers secure online financial services. We
see security as a top priority. We believe that all technology contains bugs and that
everybody plays a crucial role in identifying these bugs. If you believe you…
[Link]/asnbank

AT&T
Managed O!ers bounties $100 minimum bounty

AT&T Bug Bounty Program Policy Welcome to the AT&T Bug Bounty
Program! We now use a pay per vulnerability model and utilize the HackerOne platform!
The Program encourages and rewards contributions by developers and security
researchers who…
[Link]/a"

Atlassian
At the core of our approach to security bug management is our bug bounty program
which ensures that our products are being constantly tested for security vulnerabilities.
In a truly agile development environment with frequent releases, continuous…
[Link]/atlassian

Audible
Managed O!ers bounties $50 minimum bounty

Introduction Audible exists to unleash the power of the spoken word and to take the
digital audio book download business into the mainstream. We work to change the way
individuals control the what, when, where, and how of the words they hear, and to…
[Link]/audible

Automa"ic
O!ers bounties

Automattic runs [Link] ([Link] Jetpack


([Link] WordPress VIP ([Link] Beeper

[Link] 5/29/26, 13 37
Page 7 of 79
:
([Link] WordPress VIP ([Link] Beeper
([Link] Texts ([Link] Akismet ([Link]
Gravatar ([Link]
[Link]/automa"ic

Avast!
Please submit bugs to email address bugs@[Link]. It is recommended to encrypt
your email - here's our PGP key ([Link]
[Link]).
[Link]/avast

Banco Plata
Managed O!ers bounties $50 minimum bounty

Disclosure Policy As this is a private program, please do not discuss this program or
any vulnerabilities (even resolved ones) outside of the program without express consent
from the organization. Follow HackerOne's disclosure guidelines (https:/…
[Link]/banco_plata

Barracuda Networks
Please visit [Link] for the complete bounty brief
[Link]/barracuda

Basecamp
O!ers bounties $100 minimum bounty

TL;DR - Your insight and discoveries = our deep <3, and now $. We're a small team
born and bred on open source, so we look to the security community's lead for exploit
patterns, best practices, top vulns, new research—everything. We've learned…
[Link]/basecamp

Belastingdienst
Het kan onverhoopt voorkomen dat er een zwakke plek in een van onze systemen zit.
Als u een kwetsbaarheid ontdekt, kunt u deze volgens onderstaande afspraken aan ons

melden. U mag de Belastingdienst houden aan dit beleid ten aanzien van
Responsible…

[Link] 5/29/26, 13 37
Page 8 of 79
:
Responsible…
[Link]/belastingdienst

bigbasket
Security is a top priority for us and we take it very seriously. We put a lot of effort into
our application, infrastructure, and processes to ensure that BigBasket is safe and
secure for our customers to shop their groceries online. We also put a…
[Link]/bigbasket

[Link]
We value security during the development of [Link]. For safety our team will be
regularly trained at external companies. A specialized company examines our platform
with security audits and penetrations tests. Your efforts can contribute to make…
[Link]/bitcoin_de

Bitdefender
The Bug Bounty Reward program encourages security researchers to identify and
submit vulnerability reports regarding virtually everything that bears the Bitdefender
brand, including but not limited to the website, products and services. Program…
[Link]/bitdefender

BitMEX
Managed O!ers bounties $300 minimum bounty
Disclosure Policy Let us know as soon as possible upon discovery of a potential
security issue, and we'll make every effort to quickly resolve the issue. Provide us a
reasonable amount of time to resolve the issue before any disclosure to the public…
[Link]/bitmex

Blackphone
Program Rules Maintaining top-notch security is a group effort and Blackphone
encourages independent security researchers to help us spot potential issues. To
recognize such efforts and the important role they play in keeping the Blackphone…
[Link]/blackphone

[Link] 5/29/26, 13 37
Page 9 of 79
:
Blend Labs
Managed O!ers bounties $50 minimum bounty
Blend Labs looks forward to working with the security community to find vulnerabilities
in order to keep our businesses and customers safe. Response Targets Blend Labs will
make a best effort to meet the following SLAs for hackers participating in…
[Link]/blend-labs

Blogger
This application is covered under the Google Vulnerability Reward Program – read more
@google.
[Link]/blogger

[Link]
Managed O!ers bounties $100 minimum bounty
Please note when researching any vulnerability please use your @[Link]
email address this will help us to know on our internal monitoring tools that its a
researcher from hackerone and not a malicious actor Introduction [Link] is…
[Link]/bookingcom

Boozt Fashion AB
Managed O!ers bounties $50 minimum bounty
Boozt invites you to help enhance our security. We value your expertise in identifying
vulnerabilities. We're serious about security and eager to collaborate. Join us in making
a difference. Response Targets Boozt will make its best effort to meet…
[Link]/boozt

Brave Software
O!ers bounties $50 minimum bounty
Brave Software believes that working with security researchers across the globe is
crucial in making the web safer. If you believe you've found a security issue in our
product or service, we encourage you to notify us. We will do our best to work…
[Link]/brave

[Link] 5/29/26, 13 37
Page 10 of 79
:
Braze, Inc.
Managed O!ers bounties $50 minimum bounty

Quick summary Test only the three [Link] hosts listed below —
all other Braze domains are out of scope No automated scanners, DoS, or large-scale
discovery scans Use one test-account pattern: h1-
username[+N]@[Link]…
[Link]/braze_inc

Bugcrowd
View Bugcrowd's security and disclosure policies at [Link]
[Link]/bugcrowd

Bugify
Responsible Disclosure Security issues within our product offerings take a very high
priority. We want to work with you to understand the scope of the vulnerability and
ensure that we correct the problem fully. In pursuit of the best possible…
[Link]/bugify

Bumba
Managed O!ers bounties $50 minimum bounty

[Link] is committed to security and recognizes the importance of security


researchers in keeping the community safe. We encourage responsible disclosure of
security vulnerabilities via our bug bounty program described on this page. Note:
This…
[Link]/bumba_bbp

Bumble
Managed O!ers bounties $130 minimum bounty

Bumble & Badoo Vulnerability Disclosure Program We reward security researchers


for reporting impactful vulnerabilities affecting Bumble, Badoo, BFF (including Geneva),
and related products. Vulnerabilities are ranked based on real-world impact…
[Link]/bumble

[Link] 5/29/26, 13 37
Page 11 of 79
:
BuzzFeed
BuzzFeed is a cross-platform, global network for news and entertainment that
generates seven billion views each month. BuzzFeed creates and distributes content
for a global audience and utilizes proprietary technology to continuously test, learn
and…
[Link]/buzzfeed

Bybit Fintech Ltd


Managed O!ers bounties $50 minimum bounty

Introduction Bybit is a cryptocurrency exchange established in March 2018 to offer a


professional platform where crypto traders can find an ultra-fast matching engine,
excellent customer service and multilingual community support. The company…
[Link]/bybit_fintech

Bykea
O!ers bounties $50 minimum bounty

Bykea looks forward to working with the security community to find security
vulnerabilities to keep our businesses and customers safe. Kindly review the rules set
forth on this page before testing and submitting a report to us. Testing Guidelines…
[Link]/bykea

Capital One Bug Bounty


Managed O!ers bounties $50 minimum bounty

Capital One Bug Bounty Program Terms Capital One looks forward to working with the
security community to keep our businesses and customers safe. Please read this
program policy in its entirety before you start any testing. Capital One has…
[Link]/capital-one-bounty

[Link]
[Link] creates Fair, Fashionable and Fun online prepaid card solutions. Inelegible
targets The following are specifically excluded from scope and should not be tested:
3rd party tools used by by [Link] 3rd party service providers to [Link]…
[Link]/card

[Link] 5/29/26, 13 37
Page 12 of 79
:
CareerZooms
Program Policy for External Researchers Introduction Welcome to [Link]’s
External Research Program on HackerOne! We value your contributions and dedication
to improving our platform’s security. This policy outlines the rules and guidelines…
[Link]/careerzooms

Chainlink
O!ers bounties $50 minimum bounty
SmartContract looks forward to working with the security community to find
vulnerabilities in order to keep our businesses and customers safe. Response Targets
SmartContract will make a best effort to meet the following SLAs for hackers…
[Link]/chainlink

Chaturbate
Managed O!ers bounties $100 minimum bounty
Security Stance Security and transparency are top priorities at Chaturbate. Networks
are dynamic. The technology, users, data in the systems, risks, and security
requirements are ever-changing. Chaturbate knows that security is never perfect and
can…
[Link]/chaturbate

Check Point Software Technologies


Report a Potential Security Issue Check Point is committed to the security of its
products. The security response team in Check Point is dedicated to respond to
potential security problems and to make sure reports on such issues are handled
properly…
[Link]/checkpointsw

[Link]
[Link] Bug Bounty Policy Updated: May 12, 2025, 9:58 AM [v0.1.6 | Last updated
May 12, 2025] This policy covers all payments to third parties for finding and disclosing
bugs, vulnerabilities, and exploits within the [Link] domain and not on…
[Link]/chess_com

Chia Network

[Link] 5/29/26, 13 37
Page 13 of 79
:
Chia Network
O!ers bounties $50 minimum bounty
No technology is perfect and Chia Network believes that working with skilled security
researchers across the globe is crucial in identifying weaknesses in any technology. We
are excited for you to participate as a security researcher to help us…
[Link]/chia_network

Chrome
Chrome Reward Program Rules The Chrome Reward Program was launched in January
2010 to help reward the contributions of security researchers who invest their time and
effort in helping us to make Chrome and Chrome OS more secure. Through this
program…
[Link]/chromium

Circle BBP
Managed O!ers bounties $50 minimum bounty
At Circle, our mission ([Link]
values#:~:text=Our%20mission%20is%20to%20raise,efficient%20and%20integrated%20world%
is to raise global economic prosperity through programmable internet commerce. In…
[Link]/circle-bbp

CLEAR
Managed O!ers bounties $100 minimum bounty
About Us CLEAR's mission is to strengthen security and create frictionless
experiences. With over 36 million Members and a growing network of partners across
the world, CLEAR's secure identity platform is transforming the way people live, work,
and…
[Link]/clear

Cloud Software Group


Managed O!ers bounties $50 minimum bounty
Citrix Bug Bounty Program Policy Citrix looks forward to working with the security
community to find security vulnerabilities to keep our businesses and customers safe.
Your participation in the Bug Bounty Program (“Program”) is voluntary and…
[Link]/csg-public

[Link] 5/29/26, 13 37
Page 14 of 79
:
CloudBees
CloudBees takes security very seriously and investigates all reported vulnerabilities. We
want to keep our software and services safe for everybody. We welcome working with
the security community to resolve valid issues promptly. Bounty Program…
[Link]/cloudbees

Cloudflare Public Bug Bounty


Managed O!ers bounties
Our Values Cloudflare appreciates the work of security researchers and takes security,
trust, and transparency seriously. This program was developed to make vulnerability
reporting easier and to recognize the efforts of all people striving to help…
[Link]/cloudflare

Cobalt
The objective of this program is to identify vulnerabilities on the Cobalt platform.
Vulnerabilities of special interest include: - Unauthorized access to vulnerabilities. -
Access to admin functionalities. - Information leaks. Please use Dummy…
[Link]/cobalt

Coinbase
Managed O!ers bounties $200 minimum bounty
Coinbase recognizes the importance and value of security researchers' efforts in
helping keep our community safe. We encourage responsible disclosure of security
vulnerabilities via our bug bounty program described on this page. Note: This
program…
[Link]/coinbase

Coinhako
Managed O!ers bounties $50 minimum bounty
Coinhako looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. Response Targets Coinhako will
make a best effort to meet the following SLAs for hackers participating in our…
[Link]/coinhako

[Link] 5/29/26, 13 37
Page 15 of 79
:
CoinJar
As part of our ongoing effort to keep your money safe and information secure, we run a
bug bounty program. If you discover a security related issue in our software, we'd like
to work with you to fix it and reward you for your assistance. Rewards We…
[Link]/coinjar

[Link]
O!ers bounties $50 minimum bounty

Vulnerability Disclosure Policy We take the security of our systems seriously and value
the contributions of the security community. This policy outlines how to responsibly
report vulnerabilities to us and what you can expect in return. Reporting…
[Link]/coinmate

CoinPayments
At CoinPayments, we are committed to providing a safe and secure payment platform.
We constantly improve our services and carry out security updates to make sure your
details are safe. In order to achieve the utmost security, we are interested in…
[Link]/coinpayments

CoinSpot
Managed O!ers bounties $250 minimum bounty

Response Targets CoinSpot will make a best effort to meet the following response
targets for hackers participating in our program: Time to first response (from report
submit) - 5 days Time to triage (from report submit) - 10 days Time to bounty …
[Link]/coinspot

Compass
Managed O!ers bounties $50 minimum bounty

Compass Bug Bounty Policy Compass is committed to protecting the data that drives
our marketplace. If you’re an independent security expert or researcher and believe
you’ve discovered a security-related issue on our platform, or other assets owned…
[Link]/compass-bbp

[Link] 5/29/26, 13 37
Page 16 of 79
:
Cosmos
O!ers bounties $1000 minimum bounty
Cosmos Stack Bug Bounty Program Cosmos Labs believes that proactively finding and
fixing bugs is a vital part of building strong, resilient blockchain protocols. This program
exists as a public good to actively reward the people who discover bugs in…
[Link]/cosmos

Coupang Taiwan
Managed O!ers bounties $50 minimum bounty
Disclosure Policy Even though this is a public program, please do not discuss this
program or any vulnerabilities (even resolved ones) outside of the program without
express consent from the organization. Follow HackerOne's disclosure guidelines …
[Link]/coupang_tw

cPanel
cPanel is now a part of the WebPros Private Bug Bounty on HackerOne. This page is
retained for legacy reasons and does not accept new reports. Please use the contacts
listed in the [Link] ([Link] to…
[Link]/cpanel

Credit Karma
Managed O!ers bounties $100 minimum bounty
Credit Karma is a personal finance technology company with nearly 130 million
members in the United States, Canada and UK. The company offers a suite of products
for members to monitor and improve credit health and provides identity monitoring,…
[Link]/creditkarma

Crowdstrike
O!ers bounties $100 minimum bounty
CrowdStrike encourages researchers to follow responsible disclosure procedures when
reporting security issues in our products, services, websites, or infrastructure.
CrowdStrike is committed to engaging with the research community in a positive,…
[Link]/crowdstrike

[Link] 5/29/26, 13 37
Page 17 of 79
:
[Link]
O!ers bounties $100 minimum bounty
Our Products As a globally regulated company, [Link] is required to follow
various laws and regulations in order to provide you access to our services. This means
that to gain access to our main product, the [Link] App, you will need to go…
[Link]/crypto

Cryptocat
Help make Cryptocat safer, get rewards and eternal greatness! February 21st, 2013
Cryptocat is launching a bug hunt and we need your help! Look through our source
code and squish security bugs. You'll be helping make free, open source software
more…
[Link]/cryptocat

CS Money
O!ers bounties $50 minimum bounty
No technology is perfect, and [Link] believes that working with skilled security
researchers across the globe is crucial in identifying weaknesses in any technology. If
you believe you've found a security issue in our product or service, we…
[Link]/cs_money

Databricks
Managed O!ers bounties $100 minimum bounty
As part of Databricks’ commitment to security, we reward security researchers who find
and report to us critical security vulnerabilities and help us keep our business and
customers safe. By participating in this program, you are agreeing to the…
[Link]/databricks

De Nederlandsche Bank
Heeft u een zwakke plek in een ICT-systeem of website van De Nederlandsche Bank
(DNB) ontdekt? Meld deze kwetsbaarheid dan zo spoedig mogelijk aan DNB via
info@[Link]. Doe de melding voordat u de kwetsbaarheid aan de buitenwereld kenbaar
maakt zodat…
[Link]/dnb_nl

[Link] 5/29/26, 13 37
Page 18 of 79
:
Deribit
Managed O!ers bounties $50 minimum bounty
ATTENTION : ALL TESTS SHOULD BE PERFORMED ON OUR TEST ENVIRONMENT :
[Link] Testing directly on [Link] will make you ineligible for
bounty and disallowed from further hunting. Introduction Deribit is the leading
cryptocurrency…
[Link]/deribit

[Link]
O!ers bounties $100 minimum bounty
The security of our products is very important to us, and we constantly strive to
guarantee our users' security. The [Link] security team aims to raise the
comprehensive security of our products by working closely with individuals,
organisations,…
[Link]/deriv

Deutsche Telekom
Within the Deutsche Telekom Bug Bounty initiative, only weaknesses in web portals of
the [Link] domain including subdomains are relevant. Further notifications are, of
course, welcome at any time, but are excluded from the reward program. The…
[Link]/deutschetelekom

Discourse
Managed O!ers bounties $256 minimum bounty
We welcome review of our 100% open source code
([Link] and our public instance at
[Link] to ensure the safety and security of Discourse forums across
the world. Temporary Bounty Suspension As of…
[Link]/discourse

Django
O!ers bounties $250 minimum bounty
Django is used to power some of the most important sites on the web and its
increasing popularity has made it a critical piece of internet infrastructure. If you’ve
found a security bug that could potentially impact the security of these sites, you…

[Link] 5/29/26, 13 37
Page 19 of 79
:
found a security bug that could potentially impact the security of these sites, you…
[Link]/django

DoorDash
Managed O!ers bounties $50 minimum bounty

DoorDash welcomes the contributions of security researchers to help keep our


consumers, Dashers, and merchants safe. Our Bug Bounty Program focuses on
identifying vulnerabilities that could meaningfully impact the confidentiality, integrity,
or…
[Link]/doordash

Doppler
Managed O!ers bounties $50 minimum bounty

Doppler believes that working with skilled security researchers across the globe is
crucial in identifying potential security vulnerabilities. If you believe you have found a
security issue in our product or service, please notify us. We will make…
[Link]/doppler

Dynamic Labs
Managed O!ers bounties $50 minimum bounty

Brand Promise Dynamic Labs looks forward to working with the security community to
find vulnerabilities to keep our businesses and customers safe. We are on a mission to
accelerate the adoption of wallet-based authentication and identity. We make it…
[Link]/dynamic_labs

Dynatrace
Managed O!ers bounties $100 minimum bounty

Dynatrace's Bug Bounty Program We reward security researchers who help keep our
platform secure by discovering and responsibly disclosing vulnerabilities. Our bug
bounty program offers rewards up to $10,000. High quality reports generally qualify…
[Link]/dynatrace

Dyson
Managed O!ers bounties $100 minimum bounty

[Link] 5/29/26, 13 37
Page 20 of 79
:
Managed O!ers bounties $100 minimum bounty
Dyson Bug Bounty Program Dyson takes the security of its customers, employees, and
technology very seriously. Whilst we build our systems to be as robust as possible, we
greatly value the support of security experts around the world in helping us…
[Link]/dyson

Early Warning
Managed O!ers bounties $50 minimum bounty
Summary Zelle® is transforming how money moves, with more than five billion digital
payments sent since its launch in 2017. The Zelle Network® connects more than 2,100
bank and credit union brands of all sizes, enabling consumers and businesses to…
[Link]/early_warning

eero
Managed O!ers bounties $50 minimum bounty
eero Program Policy Introduction The first mesh home wifi system, eero blankets any
home in reliable and secure wifi. eero offers advanced online security tools, eero
Secure and eero Secure+, to help protect personal data, devices, and networks from…
[Link]/eero

Elastic
Managed O!ers bounties $100 minimum bounty
The Elastic team appreciates the security community and shares the goal of keeping
our businesses, customers, and the internet safe. Elastic values your efforts and
promises to remain responsive; update you as your reports are triaged and
remediated…
[Link]/elastic

Electronic Frontier Foundation


EFF is committed to protecting the privacy and security of our members, users of our
software tools, and visitors to EFF sites. Our Vulnerability Disclosure Program is
intended to minimize the impact any security flaws have on our tools, our hosted…
[Link]/e!

Elisa

[Link] 5/29/26, 13 37
Page 21 of 79
:
About Elisa bug bounty program Elisa is a telecommunications, ICT and online service
company serving 2.3 million consumer, corporate and public administration
organisation customers. In Finland, Elisa is the market leader in its field. Customer…
[Link]/elisa

Enjin
O!ers bounties $60 minimum bounty
Security is the utmost highest priority at Enjin. Despite the heavy attention to detail, we
understand that bugs are present within all pieces of technology - that includes our
own. It's for that reason why we love to work with talented security…
[Link]/enjin

Epic Games
Managed O!ers bounties $200 minimum bounty
Program Rules Program Eligibility You are not a resident of, and will not make your
submission from, a country against which the United State has issued export sanctions
or other trade restrictions (eg: Cuba, Iran, North Korea, Sudan, and Syria)…
[Link]/epicgames

Eternal
O!ers bounties $50 minimum bounty
We take security seriously at Eternal and are committed to protecting our community. If
you are a security researcher or expert and believe you've identified a security-related
issue with any of Eternal’s key verticals - Zomato, Blinkit, Hyperpure,…
[Link]/eternal

Ethereum
ETHEREUM Bounty Program Ethereum has a clear goal: delivering stable protocols
and secure software upon genesis block release. We call on our community and all bug
bounty hunters to help us deliver flawless protocols and clients. Earn cold hard cash…
[Link]/ethereum

Etsy
For Professional Security Researchers We genuinely appreciate the efforts of security

[Link] 5/29/26, 13 37
Page 22 of 79
:
For Professional Security Researchers We genuinely appreciate the efforts of security
researchers and offer a bounty for certain security bugs per the qualifications below: Q)
What's a valid bug? A) Web application vulnerabilities such as XSS, CSRF…
[Link]/etsy

eufy Security
Managed O!ers bounties $50 minimum bounty
** We’ve recently noticed new CVEs related to [Link], Dify and n8n, which have
already been identified and are being addressed internally. During this period, we’re
temporarily not accepting vulnerability reports related to these infrastructures,…
[Link]/eufy_security

Eureka
Eureka Bug Bounty Program Terms Security is a priority at Eureka. If you believe you've
found a security bug in our in-scope applications or infrastructure, we are happy to
work with you to resolve the issue promptly and ensure you are fairly…
[Link]/eureka_jp

Eutelsat
Eutelsat Group (OneWeb) looks forward to working with the security community to find
vulnerabilities in order to keep our businesses and customers safe. As a global Hybrid
Satellite Network communications company powered from both Low Earth Orbit …
[Link]/eutelsat-bbp

Evernote
Managed O!ers bounties $150 minimum bounty
Evernote is the go-to app that helps millions of people worldwide remember everything
and accomplish anything. It's important to us that our customer experience be both
private and secure. We strive to keep abreast on the latest state-of-the-art…
[Link]/evernote

EXNESS
O!ers bounties $50 minimum bounty
HOW TO SUBMIT BUG REPORT? A bug report must have the following (including
mobile reports): - Impact - it should describe the REAL impact of vulnerability that may

[Link] 5/29/26, 13 37
Page 23 of 79
:
mobile reports): - Impact - it should describe the REAL impact of vulnerability that may
affect our users and company funds or reputation - Highly detailed description of the…
[Link]/exness

Exodus
O!ers bounties $100 minimum bounty

Exodus is one of the top non-custodial crypto wallets. We value our customers wallet's
security more than anything. We are looking forward to working with you. ==Do NOT
test Exodus contact form and do NOT create multiple support tickets via Exodus…
[Link]/exodus

Expedia Group Bug Bounty


Managed O!ers bounties $100 minimum bounty

Bug Bounty Program Guidelines Expedia Group recognizes the important role that
security researchers play in helping to keep Expedia Group and our customers secure.
By submitting a vulnerability to us either directly or indirectly you acknowledge…
[Link]/expediagroup_bbp

F-Secure
We want to hear about any security vulnerabilities in our products and services. In
order to reward security researchers, we offer monetary rewards for eligible security
vulnerability reports that are disclosed to us in a coordinated way. However,…
[Link]/fsecure

F. Ho!mann-La Roche Ltd.


We are currently running an invite-only bug-bounty program at HackerOne. If you
would like to be invited, we kindly ask you to submit one issue with high severity as we
define it (see below) with a working POC that is in scope for our program. If…
[Link]/roche

FanDuel
O!ers bounties $100 minimum bounty

Bug Bounty Program Policy At FanDuel, Everything Begins with the Customer. We
strive to protect our valued customers from attackers who seek to compromise the
confidentiality, integrity or availability of our platform. We also recognize the…

[Link] 5/29/26, 13 37
Page 24 of 79
:
confidentiality, integrity or availability of our platform. We also recognize the…
[Link]/fanduel

FanDuel
[Link]/fanduel_old

Faraday, Inc.
Managed O!ers bounties $50 minimum bounty
Introduction Faraday, Inc. looks forward to working with the security community to find
security vulnerabilities in order to keep our businesses and customers safe. Please see
the "Out of scope" section - there are important exclusions. Response…
[Link]/faraday_inc

FetLife
O!ers bounties $100 minimum bounty
No technology is perfect, and FetLife believes that working with skilled security
researchers across the globe is crucial in identifying weaknesses in any technology. If
you believe you've found a security issue in our product or service, we…
[Link]/fetlife

Figma
Managed O!ers bounties $50 minimum bounty
Figma looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. Response Targets Our primary focus
is on high/critical findings right now, and we aim to expand scope beyond that…
[Link]/figma

[Link]
O!ers bounties $100 minimum bounty
Here at [Link], we take security seriously and encourage independent security
researchers to help us keep our platform secure. We offer a Security Bug Bounty
Program (the “Program”) to provide a clear incentive and reward structure for…
[Link]/files

[Link] 5/29/26, 13 37
Page 25 of 79
:
[Link]/files

FlexiSPY
[Link]/flexispyltd

Flickr
Managed O!ers bounties $200 minimum bounty
Welcome to Flickr's Bug Bounty Program! We look forward to seeing your reports and
working with you to improve our product. Please reach out with any questions, and feel
free to share a link to your photostream on reports if you're a user of the…
[Link]/flickr

Flipkart
Managed O!ers bounties $100 minimum bounty
At Flipkart, we take the security of our systems very seriously, and it is our constant
endeavour to make our products secure for our customers. However, in the rare case
when some security researcher or member of the general public identifies a…
[Link]/flipkart

FloQast
O!ers bounties $50 minimum bounty
Temporary Program Pause Thank you for all of your reports to our bug bounty program!
You may have noticed that we temporarily paused our program and are only offering a
maximum $50 bounty. This is a short-term measure to allow us some time to…
[Link]/floqast

Flu"er UK&I
Managed O!ers bounties $250 minimum bounty
Flutter UK & Ireland looks forward to work with the security community to find
vulnerabilities in our brands to keep our businesses and customers safe. The only
brands in scope of this program are Betfair, Paddy Power and Sky Betting and
Gaming…
[Link]/flu"eruki

[Link] 5/29/26, 13 37
Page 26 of 79
:
[Link]/flu"eruki

ForeScout Technologies
Managed O!ers bounties $100 minimum bounty
Forescout Technologies (the organization) looks forward to working with the security
community to find vulnerabilities in order to keep its businesses and customers safe.
Response Targets Forescout Technologies will make commercially reasonable…
[Link]/forescout_technologies

Freshworks
O!ers bounties $100 minimum bounty
Freshworks Bug Bounty Program Mission Freshworks places the highest priority on
safeguarding customer data. We deeply appreciate the contributions of security
researchers in strengthening our security posture and encourage their participation in
the…
[Link]/freshworks

Front
Managed O!ers bounties $100 minimum bounty
Front is a customer operations platform used by over 8,000 teams to streamline
communication. It combines the efficiency of a help desk and the familiarity of email so
teams can deliver exceptional service at scale. See here ([Link]
[Link]/fronthq

Frontegg
Managed O!ers bounties $50 minimum bounty
Frontegg looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. Frontegg is a comprehensive
developer platform designed to empower teams with self-service capabilities, robust…
[Link]/frontegg

Gearbest
[Link]/gearbest

[Link] 5/29/26, 13 37
Page 27 of 79
:
Ghostscript
Artifex Software is committed to producing code with as few bugs as possible. As
such, we have a public bug tracker where anyone is welcome to view open issues,
report new ones, and contribute analysis and fixes. When we have bugs that we'd like
to…
[Link]/ghostscript

Giesecke+Devrient
Giesecke+Devrient Directory Page This page is to enable you to submit information
about technical weaknesses and vulnerabilities in Giesecke+Devrient Group’s (“G+D”)
products and services. Submission of a Vulnerability If you identify any potential…
[Link]/giesecke_devrient

GitHub
O!ers bounties $617 minimum bounty
GitHub Security Bug Bounty Software security researchers are increasingly engaging
with internet companies to hunt down vulnerabilities. Our bounty program gives a tip of
the hat to these researchers and provides rewards of $30,000 or more for…
[Link]/github

GitLab
Managed O!ers bounties $100 minimum bounty
Rewards We have different rewards depending on the business impact of each asset. A
more complete description of each asset will be in the scope section, but in general
[Link] and all our products' source code is rewarded the highest, then non…
[Link]/gitlab

GMX GmbH
Security of data entrusted to us by our clients has the highest priority. This is why we
have decided to implement a bug bounty program and invite independent security
researchers to help us further improve the security of our systems. Systems in…
[Link]/gmx_gmbh

[Link] 5/29/26, 13 37
Page 28 of 79
:
GoCardless Bug Bounty Program
Managed O!ers bounties $50 minimum bounty

GoCardless is on a mission to take the pain out of getting paid for businesses with
recurring revenue. We’ve created a global bank debit network, to rival credit and debit
cards. On top of it, we’ve built a platform designed and optimised for…
[Link]/gocardless_bbp

Goldman Sachs
Managed O!ers bounties

==Most Valuable Hacker (MVH) Recognition Program== The Most Valuable Hacker
(MVH) program recognizes security researchers who consistently demonstrate
exceptional contributions to our security posture through high-impact, high-quality
vulnerability…
[Link]/goldmansachs

GoodRx
Managed O!ers bounties $100 minimum bounty

Intro GoodRx is America’s healthcare marketplace. Each month, more than 17 million
people use GoodRx’s website and popular mobile apps to find current prices and
discounts for their healthcare, and we’ve helped people save more than $20 billion…
[Link]/goodrx

Google
Google Vulnerability Reward Program (VRP) We have long enjoyed a close relationship
with the security research community. To honor all the cutting-edge external
contributions that help us keep our users safe, we maintain a Vulnerability Reward…
[Link]/google

Grab
Managed O!ers bounties $50 minimum bounty

Foreword Security is a top priority at Grab. We believe that no technology is perfect


and that working with skilled security researchers across the globe is crucial in
identifying weaknesses in our technology. If you believe you've found a security…
[Link]/grab

[Link] 5/29/26, 13 37
Page 29 of 79
:
[Link]/grab

[Link]
Managed O!ers bounties $100 minimum bounty

About Greenhouse is software to optimize your entire recruiting and onboarding


process. Find better candidates, conduct more focused interviews, and make data-
driven hiring decisions. Through this security bug bounty program we collaborate
with…
[Link]/greenhouse

Grindr
Managed O!ers bounties $50 minimum bounty

HackerOne Policy Introduction Grindr is excited to be working with the HackerOne


security community to help find security vulnerabilities. We are happy to work together
to keep Grindr and our users safe. Please report security issues or concerns…
[Link]/grindr

HackerOne
Managed O!ers bounties $200 minimum bounty

Must Read Header Requirements Set a custom HTTP header in all your testing traffic.
Once again, report to us what header you set so we can identify it easily for
deconfliction purposes. | Identifier Type | Format | Example | |----------------------|…
[Link]/security

HackForums
[Link]/hackforums

Highrise HQ
We are currently running a limited, invite-only bug-bounty program at HackerOne for all
Basecamp products, which includes *.[Link]. If you would like to submit a
severe issue in the mean time outside of the bounty program, please contact us…
[Link]/highrise_hq

[Link] 5/29/26, 13 37
Page 30 of 79
:
Hilton
Managed O!ers bounties $50 minimum bounty
Introduction At Hilton, our mission is to provide the light and warmth of hospitality to
the world, by delivering an exceptional, safe, and reliable customer experience. In
pursuit of this mission, we are partnering with HackerOne and the security…
[Link]/hilton

Hinge
Rewards |     [Link]
[Link]/hackerone/bar_low.png
Low             &n
| [Link]
[Link]/hinge

HireVue
At Hirevue, we are committed to the security of our products and the protection of our
customers' data. We value the crucial role that security researchers play in helping us
maintain a safe and secure environment. If you believe you've discovered a…
[Link]/hirevue

Hootsuite
We take security very seriously at Hootsuite, and have an Information Security Bug
Bounty program geared towards the identification and remediation of security issues.
Submitting a Report If you are interested in submitting your findings for review,…
[Link]/hootsuite

Hostelworld
[Link]/hostelworld

Hostfact

[Link] 5/29/26, 13 37
Page 31 of 79
:
Hostfact
[Link]
[Link]/hostfact

hostinger
O!ers bounties $100 minimum bounty
HOSTINGER BUG BOUNTY REWARD PROGRAM PLEASE READ THIS AGREEMENT
CAREFULLY, AS IT CONTAINS IMPORTANT INFORMATION REGARDING YOUR
LEGAL RIGHTS AND REMEDIES. Last Revised: 2024-01-24 RESPONSIBLE
DISCLOSURE POLICY Hostinger encourages the responsible…
[Link]/hostinger

HubSpot
Managed O!ers bounties $50 minimum bounty
Instructions for creating a HubSpot trial portal: Anyone may create a trial portal by
navigating to: [Link] When signing up, please use your
@[Link] email address. All available functionality may be tested…
[Link]/hubspot

Hya" Hotels
Managed O!ers bounties
Keeping Guests Safe Hyatt takes the security of our guests and colleagues very
seriously. By being the first organization in the hospitality industry to embrace the
collaborative efforts of global security researchers, we hope to continue to raise…
[Link]/hya"

Hybrid Saas
Responsible disclosure Hybrid SaaS vindt het erg belangrijk dat de eigen ICT-systemen
veilig zijn en streeft het een hoge beveiliging daarvan na. Toch kan het gebeuren dat er
een zwakke plek in één van deze systemen voorkomt. Kwetsbaarheden in ICT…
[Link]/hybridsaas

HYPR
O!ers bounties $50 minimum bounty

[Link] 5/29/26, 13 37
Page 32 of 79
:
O!ers bounties $50 minimum bounty

Bug Bounty Test Request Form In order to request credentials for the HYPR platform
please submit your handle and email in this form.
([Link] Main subdomain for testing:
[Link] or https:/…
[Link]/hypr-corp

ICANN
ICANN looks forward to working with the community to find security vulnerabilities in
order to keep our businesses and customers safe. SLA ICANN will make a best effort
to meet the following SLAs for hackers participating in our program: * Time to…
[Link]/icann

Indeed
[Link]/indeed

Independer
Responsible Disclosure Policy Independer Independer's mission is to restore
confidence in financial institutions and products. In it we run themselves like lead.
Independer customers can be confident that we are security and privacy seriously.
Our…
[Link]/independer

Inditex
Managed O!ers bounties $150 minimum bounty

Summer Special Campaign From 29/07/2024 to 15/08/2024 Summer Special


Campaign conditions. We are excited to announce our special summer bug bounty
campaign, where we will be offering up to 2x payouts for Critical and High severity
vulnerabilities…
[Link]/inditex

inDrive
O!ers bounties $50 minimum bounty

Security is a top priority at inDrive. If you believe you've found a security bug in our in-

[Link] 5/29/26, 13 37
Page 33 of 79
:
Security is a top priority at inDrive. If you believe you've found a security bug in our in-
scope applications or infrastructure, we are happy to work with you to resolve the issue
promptly and ensure you are fairly rewarded for your discovery. Also…
[Link]/indrive

ING
Responsible Disclosure Do you have the skills and did you discover any vulnerabilities
in our systems? If so, help us by reporting these vulnerabilities. So that we can improve
the safety and reliability of our systems together. ING and safety As…
[Link]/ing

Insightly
Managed O!ers bounties $100 minimum bounty

Introduction No technology is perfect, and Insightly believes that working with skilled
security researchers across the globe is crucial in identifying weaknesses in any
technology. If you believe you've found a security issue in our product or…
[Link]/insightly

Inspectorio
Managed O!ers bounties $50 minimum bounty

INSPECTORIO looks forward to working with the security community to find security
vulnerabilities in order to keep our businesses and customers safe. Response Targets
INSPECTORIO will make a best effort to meet the following response targets for…
[Link]/inspectorio

Instacart
Managed O!ers bounties $50 minimum bounty

Table of Contents Rules & Terms Vulnerability Types Out-of-Scope Known Issues
Assets Core Assets Out-of-Scope Rewards Eligibility Payout Amounts Additional
Factors Google Play Security Reward Program Submissions Report Quality
Demonstrating…
[Link]/instacart

Instagram
If you believe you have found a security vulnerability on Facebook, we encourage you

[Link] 5/29/26, 13 37
Page 34 of 79
:
If you believe you have found a security vulnerability on Facebook, we encourage you
to let us know right away. We will investigate all legitimate reports and do our best to
quickly fix the problem. Before reporting though, please review this page …
[Link]/instagram

Instamojo
[Link]/instamojo

Instructure
TELL US ABOUT A SECURITY ISSUE. Email us about vulnerabilities at
security@[Link]. (If you want, you can use our public key
([Link] Or participate in our
bug bounty via Bugcrowd (https…
[Link]/instructure

[Link]
Managed O!ers bounties $50 minimum bounty

Security is top priority at [Link]. We constantly release new features and no system
is perfect. We look forward to working with the security community around the world to
find vulnerabilities in order to keep our businesses and customers safe…
[Link]/judgeme

KAYAK
Managed O!ers bounties $100 minimum bounty

KAYAK is committed to working with security experts across the world to stay up to
date with the latest security techniques. If you have discovered a security issue that
you believe we should know about, we'd welcome working with you. Scope Scope…
[Link]/kayak

KFC
Responsible Disclosure Policy: This page is for security researchers interested in
reporting application security vulnerabilities. If you have reported an issue determined
to be within program scope, is determined to be a valid security issue, and…

[Link] 5/29/26, 13 37
Page 35 of 79
:
to be within program scope, is determined to be a valid security issue, and…
[Link]/kfc

KHealth
Managed O!ers bounties $100 minimum bounty
About Us K Health [Inc.]’s (“K Health”, “we”, “us” or “our”) mission is to use the power
of shared knowledge to provide everyone with access to better, more affordable
healthcare. We offer our users healthcare information based on the similar health…
[Link]/khealth

[Link]
Managed O!ers bounties $100 minimum bounty
[Link] is committed to working with security experts worldwide in cooperation with
HackerOne’s Triage team to ensure the high quality of our bug bounty program and the
security of our customers. If you’re good enough to spot a vulnerability on our…
[Link]/kiwicom

Klarna
Managed O!ers bounties $50 minimum bounty
Smoooth hacking Klarna looks forward to working with the security community to find
vulnerabilities in order to keep its businesses and customers safe. Our program
accepts reports of bugs that provide a potential attacker with the ability to…
[Link]/klarna

KnowBe4
KnowBe4 is running an invite-only bug-bounty program at HackerOne. If you would like
to submit an issue please contact us via email and provide us with your hackerone
username or you may submit the vulnerability directly to us outside of our bug…
[Link]/knowbe4

KOHO
O!ers bounties $50 minimum bounty
Introduction KOHO is a Canadian fintech company rooted in the belief that a better
banking alternative exists. Our bug bounty program will allow researchers to help us
improve our security for our customers to enable that better banking experience…

[Link] 5/29/26, 13 37
Page 36 of 79
:
improve our security for our customers to enable that better banking experience…
[Link]/koho

Kong
Managed O!ers bounties $50 minimum bounty
Kong's Bug Bounty Policy At Kong, security is a top priority. We value the contributions
of the security research community in helping keep our products, services, and users
safe. If you discover a vulnerability, we welcome your report and are…
[Link]/kong

Krisp
O!ers bounties $50 minimum bounty
Krisp looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. Response Targets Krisp will make a
best effort to meet the following SLAs for hackers participating in our program…
[Link]/krisp

Kubernetes
Managed O!ers bounties $50 minimum bounty
We’re incredibly grateful for security researchers and users that report vulnerabilities to
the Kubernetes Open Source Community. All reports are thoroughly investigated by a
set of community volunteers. Response Targets Cloud Native Computing…
[Link]/kubernetes

Kyup
If you believe you've discovered a security vulnerability in Kyup, you may responsibly
disclose your find by sending an email to security@[Link]. Please include the
following details with your disclosure: Description of vulnerability and potential…
[Link]/kyupcloud

Lark Technologies
Managed O!ers bounties $100 minimum bounty
The security and privacy of your data are our utmost concern. Lark abides by rigorous
security policies, and implements robust systems to protect user data. We encourage
security research individuals as well as teams to test our security, and we…

[Link] 5/29/26, 13 37
Page 37 of 79
:
security research individuals as well as teams to test our security, and we…
[Link]/lark_technologies

LastPass
LastPass Security Response We Value Your Concerns Our business is keeping
customer information both private and secure. We appreciate all security concerns
brought forth and are constantly striving to keep on top of the latest threats. Being
pro…
[Link]/lastpass

LG Electronics
If you have found a potential security issue with any of our products or services related
to our products, we kindly ask you to let us know at your earliest convenience via email
at [Link]@[Link]
[Link]/lge

Lightspark BBP
Managed O!ers bounties $50 minimum bounty

Response Times Lightspark is committed to meeting our response targets for hackers
participating in our program. We'll ensure regular updates on our progress throughout
the process. | Type of Response | SLA in business days | | ------------- | -----…
[Link]/lightspark_bbp

LinkedIn
Managed O!ers bounties $100 minimum bounty

Introduction LinkedIn believes that close partnerships with security researchers makes
us all more secure. Security researchers play an integral role in our ecosystem by
discovering vulnerabilities that went undiscovered during the software…
[Link]/linkedin

Linode
Linode Security Bug Bounty Program Linode has partnered with HackerOne to operate
our private bug bounty and disclosure program. We welcome in-scope vulnerability
reports. Linode is committed to the security of its infrastructure and customer's…
[Link]/linode

[Link] 5/29/26, 13 37
Page 38 of 79
:
[Link]/linode

lock&key
my test program
[Link]/lockkey

Logitech
Managed O!ers bounties $200 minimum bounty

Welcome to Logitech's Vulnerability Disclosure and Bug Bounty Program! Here at


Logitech we are committed to providing secure products and services to our
customers. If you believe you have discovered a potential security vulnerability with any
of…
[Link]/logitech

Lyft
Currently, the Lyft bug bounty program is private and is on a per-invite basis only. If you
believe you've discovered a security bug or vulnerability in the Lyft service, please
report it to us at the "Contact Security team" link on this page. We…
[Link]/lyft

Lyst
Managed O!ers bounties $100 minimum bounty

No technology is perfect, and Lyst believes that working with skilled security
researchers across the globe is crucial in identifying weaknesses in any technology. If
you believe you've found a security issue in our product or service, we encourage…
[Link]/lyst

M-Pesa Africa Limited


Managed O!ers bounties $50 minimum bounty

If you believe you have found a security vulnerability on any of our Mpesa products or
services, we encourage you to let us know right away. We will investigate all legitimate
reports and do our best to quickly fix the problem. Please be aware that…
[Link]/mpesa

[Link] 5/29/26, 13 37
Page 39 of 79
:
Magic Eden
Managed O!ers bounties $50 minimum bounty
Magic Eden looks forward to working with the security community to find vulnerabilities
in order to keep our businesses and customers safe. We’ll try to keep you informed
about our progress throughout the process. Disclosure Policy Please do not…
[Link]/magic-eden

[Link]
[Link]/makemytrip

Malwarebytes
Managed O!ers bounties $50 minimum bounty
{F2076724} Here at Malwarebytes, we believe that when you’re free from threats,
you’re free to thrive. It all started with one person who needed help with a malware
infection, and a community coming together to find solutions. In that moment in time…
[Link]/malwarebytes

ManageWP
White Hat Reward Terms for claiming your bounty Provide us reasonable time to
analyze and respond to your report and please do not disclose this information without
our consent. Avoid privacy violations, deleting our data and interruption of our…
[Link]/managewp

Mapbox
Managed O!ers bounties $200 minimum bounty
Mapbox appreciates the effort of software security researchers who work to make the
Internet more secure. Our security vulnerability bounty system exists to reward the
work of security researchers who find issues with our software and web services…
[Link]/mapbox

[Link] 5/29/26, 13 37
Page 40 of 79
:
Marrio" Bug Bounty Program
Managed O!ers bounties $100 minimum bounty
Welcome to the Marriott Bug Bounty Program ! Marriott takes cybersecurity seriously.
Individuals that participate in the Program by responsibly researching and reporting
vulnerabilities help us to ensure the security and privacy of our customers and…
[Link]/marrio"

Massachuse"s Institute of Technology


The MIT Security Bug Bounty Program We do our best to keep MIT's network and
services secure, but we're not perfect. If you're an MIT affiliate and find a security
vulnerability that falls within scope, we'll reward you for responsibly disclosing…
[Link]/mit

[Link]
Match Bug Bounty Program Terms Security is a priority at Match. If you believe you've
found a security bug in our in-scope applications or infrastructure, we are happy to
work with you to resolve the issue promptly and ensure you are fairly rewarded…
[Link]/match

Matomo
O!ers bounties $10000 minimum bounty
Disclosure Policy Let us know as soon as possible upon discovery of a potential
security issue, and we'll make every effort to quickly resolve the issue. Provide us a
reasonable amount of time to resolve the issue before any disclosure to the public…
[Link]/matomo

Meesho
O!ers bounties $50 minimum bounty
Overview At Meesho, we prioritise security and value responsible disclosure. If you
identify a security issue in our website or apps, we encourage you to report it to us
responsibly. Our team is committed to resolving issues promptly and requests…
[Link]/meesho_bbp

[Link]

[Link] 5/29/26, 13 37
Page 41 of 79
:
[Link]
Immediately after our launch, our security model and implementation came under
intense crossfire, most of which turned out to be damp squibs. We have, however, also
suffered three direct hits, and we want more! To improve MEGA's security, we are…
[Link]/megaprivacy

Meraki
This program is managed by Bugcrowd and can be found at
[Link]
[Link]/meraki

MercadoLibre
Managed O!ers bounties $100 minimum bounty

Table of Contents Current Active Challenge (#user-content-current-active-challenge)


Rewards (#user-content-rewards) Loyalty And Gamification (#user-content-loyalty-and-
gamification) Tier 3 — Non-Applicative Vulnerabilities (#user-content-tier-3-non…
[Link]/mercadolibre

Mergify
O!ers bounties $50 minimum bounty

Mergify looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. Response Targets Mergify will make
its best effort to meet the following SLAs for hackers participating in our…
[Link]/mergify

MetaMask
Managed O!ers bounties $50 minimum bounty

Prioritized Focus Areas Reports demonstrating how an attacker could extract the
secret recovery phrase or a private key from a wallet. Reports demonstrating how an
attacker could make a users wallet behave in unexpected ways. Response Targets…
[Link]/metamask

Modern Treasury
Managed O!ers bounties $50 minimum bounty

[Link] 5/29/26, 13 37
Page 42 of 79
:
Modern Treasury Bug Bounty Policy Modern Treasury looks forward to working with the
security community to find vulnerabilities in order to keep our businesses and
customers safe. This policy (“Policy”) governs your participation in our bug bounty…
[Link]/modern_treasury

Moneybird
O!ers bounties $50 minimum bounty

Disclosure policy At Moneybird, we consider the security of our systems a top priority.
But no matter how much effort we put into system security, there can still be
vulnerabilities present. If you discover a vulnerability, we would like to know…
[Link]/moneybird

MongoDB
Managed O!ers bounties $50 minimum bounty

{F1894478} At MongoDB, our mission is to empower investors to create, transform,


and disrupt industries by unleashing the power of software and data. We are a leading
modern, general purpose database platform and our open-source model provides…
[Link]/mongodb

MoonPay
O!ers bounties $50 minimum bounty

MoonPay Bug Bounty Program At MoonPay, we are committed to maintaining the


security and privacy of our products and customers. We believe that working with the
security research community through our bug bounty program is a crucial part of our…
[Link]/moonpay

Mozilla
Managed O!ers bounties $50 minimum bounty

Table of Contents Program Scope Severity Definitions and Examples Test Plan
Submission Guidelines Program Rules Appeal Process Response Targets Disclosure
Policy Safe Harbor Program Scope Please check the list of sites under the Scope

section, we…
[Link]/mozilla

[Link] 5/29/26, 13 37
Page 43 of 79
:
Mux
Mux is an API driven platform for developers to build amazing video experiences into
their websites or apps. We work hard to ensure Mux is a safe and secure environment
for our customers and their viewers. We welcome and reward vulnerability reports…
[Link]/mux

N26
N26 Bugbounty Program Security has the highest priority at N26 and we are
continuously working to provide secure products. We follow international standards as
defined by leading tech companies and security communities. However, no technology
is…
[Link]/n26

Namecheap
[Link]/namecheap

Naver Whale
[Link] Naver Corp. launches the Whale Security Bug Bounty Program to
encourage security researchers in helping us to find and fix security vulnerabilities on
Whale and to reward their efforts spent to make our product more safe. [Link] We…
[Link]/naver_whale

NBA Public Bug Bounty


Managed O!ers bounties $50 minimum bounty

Purpose (#user-content-purpose) Scope (#user-content-scope) Rules of Engagement


(#user-content-rules-of-engagement) In-Scope Vulnerabilities (#user-content-in-scope-
vulnerabilities) Out of Scope Vulnerabilities (#user-content-out-of-scope…
[Link]/nba-public

Neon
Managed O!ers bounties $50 minimum bounty

Overview Neon is an open-source database company dedicated to delivering a

[Link] 5/29/26, 13 37
Page 44 of 79
:
Overview Neon is an open-source database company dedicated to delivering a
serverless PostgreSQL platform optimized for cloud deployment. Our architecture
separates storage and compute, enabling features like autoscaling, instant branching,
and…
[Link]/neon_bbp

Nest
If you’re a security researcher and think you’ve found a security vulnerability, we want
to hear about it right away. We ask that you give us a reasonable amount of time to
respond to your report before making any information public. Please don’t…
[Link]/nest

Netflix
Managed O!ers bounties $50 minimum bounty
Netflix Program Policy Netflix’s goal is to deliver joy to our members around the world,
and it is the security team's job to keep our members, partners, and employees secure.
We have been engaging with the security community to achieve this goal…
[Link]/netflix

Netlify
Managed O!ers bounties $100 minimum bounty
About Netlify Netlify is the fastest way to combine your favorite tools and APIs to build
the fastest sites, stores, and apps for the web. Attack surface Netlify provides a UI
([Link]), an API ([Link]), a build system triggered by…
[Link]/netlify

NetScaler Public Program


O!ers bounties $50 minimum bounty
Disclosure Policy Follow HackerOne's disclosure guidelines
([Link] Program Rules Please provide
detailed reports with reproducible steps. If the report is not detailed enough to
reproduce the issue, the…
[Link]/netscaler_public_program

Newegg

[Link] 5/29/26, 13 37
Page 45 of 79
:
Newegg
Managed O!ers bounties $50 minimum bounty

Introduction Our mission at Newegg is to make e-Commerce better for everyone.


Newegg's bug bounty program will give the security community the opportunity to help
us accomplish our mission by making us the most secure and trusted e-commerce
platform…
[Link]/newegg

Nintendo
O!ers bounties $100 minimum bounty

Nintendo’s goal is to provide a secure environment for our customers so that they can
enjoy our games and services. In order to achieve this goal, Nintendo is interested in
receiving vulnerability information that researchers may discover regarding…
[Link]/nintendo

[Link]
O!ers bounties $500 minimum bounty

Reporting a Bug in [Link] All security bugs in [Link] are taken seriously. Please
report any security issues here (/nodejs/reports/new). All reports are evaluated based
on the [Link] Threat Model. You can find more information about it at…
[Link]/nodejs

Nord Security
Managed O!ers bounties $100 minimum bounty

At Nord Security, we strive to maximize the security of our infrastructure and


customers' data. We believe that in order to reach our goal community participation is
essential. Please note that your submission of potential security vulnerability…
[Link]/nordsecurity

Notion Labs, Inc.


Managed O!ers bounties $50 minimum bounty

Notion Labs, Inc. looks forward to working with the security community to find security
vulnerabilities in order to keep our businesses and customers safe. Response Targets
Notion Labs, Inc. will make a best effort to meet the following response…
[Link]/notion

[Link] 5/29/26, 13 37
Page 46 of 79
:
Nuon
Nuon pays much attention to the proper security of its information and communication
systems. Despite this, a weak spot may exist or develop: a security vulnerability.
Abusing a security vulnerability, or informing third parties about such a…
[Link]/nuon

Oculus
Responsible Disclosure Policy If you give us reasonable time to respond to your report
before making any information public, and make a good faith effort to avoid privacy
violations, destruction of data, and interruption or degradation of our…
[Link]/oculus

OKG
Managed O!ers bounties $50 minimum bounty

About OKG: OKG Technology Holdings Limited is a leading innovator in the blockchain
sector, dedicated to the research, development, and commercial application of
blockchain technology. Founded in 2013, the company has emerged as a global
blockchain…
[Link]/okg

Ola
We request you not to do any public disclosure of a bug before it has been fixed.
Please understand that due to high number of submissions, it might take a bit of time in
order to fix the vulnerability reported by you. Therefore, give us reasonable…
[Link]/olacabs

Olark
Security at Olark We sincerely thank you for your help, and will happily offer a bounty
for submissions of security bugs under the following criteria: The bug is an application
vulnerability (database injection, XSS, session hijacking, remote code…
[Link]/olark

OnePlus Old

[Link] 5/29/26, 13 37
Page 47 of 79
:
OnePlus Old
We welcome independent security researchers of all backgrounds and levels to join us
in our efforts to secure the OnePlus ecosystem. If you believe you've found a security
issue in our products or systems, we encourage you to notify us through…
[Link]/oneplus_old

Onshape
Onshape Security Bug Identification Program (Effective as of April 15, 2015) Rules for
you Don’t attempt to gain access to another user’s account or data. Don’t perform any
attack that could harm the reliability/integrity of our services or data…
[Link]/onshape

OPPO
Managed O!ers bounties $10 minimum bounty

OPPO’s commitment to global researcher collaboration significantly enhances product


security. We welcome hackers worldwide to submit security vulnerability reports related
to OPPO services. Your contributions will help enhance the security of OPPO…
[Link]/oppo_bbp

OV-chipkaart
Responsible disclosure beleid Trans Link Systems (TLS) draagt met de OV-chipkaart
eraan bij dat reizigers elke dag veilig en makkelijk reizen met het openbaar vervoer. De
beveiliging van de OV-chipkaart heeft de hoogste prioriteit bij TLS. Uiteraard…
[Link]/ovchipkaart

OVH
While we are trying our best to keep OVH services as safe as possible, We know that
some vulnerabilities have slip trough our scrutiny. If you believe you've found a security
issue in the services listed in our scope, we will work with you to…
[Link]/ovh-group

Palantir Public
O!ers bounties $50 minimum bounty

If you've identified a potential security flaw in our infrastructure or software, please let
us know within 24 hours. Prior to reporting, please review the following information

[Link] 5/29/26, 13 37
Page 48 of 79
:
us know within 24 hours. Prior to reporting, please review the following information
including our responsible disclosure policy, scope, reward information,…
[Link]/palantir_public

Paper Inc
This program has been temporarily paused !! Submit your findings at
[Link]
554adb715ead/embedded_submissions/new or reach out to security@[Link]
Best Regards, Paper Security Team
[Link]/withpaper

Parse
If you believe you have found a security vulnerability on Facebook, we encourage you
to let us know right away. We will investigate all legitimate reports and do our best to
quickly fix the problem. Before reporting though, please review this page …
[Link]/parseit

PasteCoin
Bug Bounty Although our team of experts has made every effort to squash all the bugs
in our systems, there's always the chance that we might have missed one posing a
significant vulnerability. If you discover a bug, we appreciate your cooperation in…
[Link]/pastecoin

Payoneer
Managed O!ers bounties $50 minimum bounty
Payoneer looks forward to working with the security community and welcome your
participation in our program aimed at identifying potential security vulnerabilities related
to Payoneer’s products or website (the “Program”), in order to keep our…
[Link]/payoneer

PayPal
Managed O!ers bounties
Our team of dedicated security professionals works diligently to maintain the security
of customer information. We acknowledge the crucial role that security researchers and
our user community play in helping to keep PayPal and our customers secure…

[Link] 5/29/26, 13 37
Page 49 of 79
:
our user community play in helping to keep PayPal and our customers secure…
[Link]/paypal

paysafecard
[Link]/paysafecard

Phabricator
O!ers bounties $300 minimum bounty
Security is serious business, just like Phabricator. If you can find a security vulnerability
in the project, we’ll reward you with cold, hard cash. The cash will be transmitted
electronically, so it will be cold and hard only figuratively. READ…
[Link]/phabricator

Ping Identity
Managed O!ers bounties $125 minimum bounty
Ping Identity looks forward to working with the security community to find and solve
vulnerabilities. Thank you for helping us keep our customers safe. Getting Access For
our docker images: Please clone this repo ([Link]
[Link]/pingidentity

Pinterest
Pinterest is a place to discover ideas for all your projects and interests, hand-picked by
people like you. We take our security very seriously and welcome any responsible
disclosure of potential gaps in our systems.
[Link]/pinterest

pixiv
Managed O!ers bounties $200 minimum bounty
No technology is perfect, and pixiv believes that working with skilled security
researchers across the globe is crucial in identifying weaknesses in any technology. If
you believe you've found a security issue in our product or service, we encourage…
[Link]/pixiv

[Link] 5/29/26, 13 37
Page 50 of 79
:
Plaid
Managed O!ers bounties $100 minimum bounty

Plaid looks forward to working with the security community to find security
vulnerabilities in order to keep our business and customers safe. Program Scope Any
domain/property of Plaid not listed in the Scope, including data repos such as
GitHub,…
[Link]/plaid

PlayStation
Managed O!ers bounties $50 minimum bounty

Program Overview At PlayStation, we strive to be the best place to play, and believe
that the security of our environment is fundamental to that goal. We believe that
through close partnerships with the security research community we can deliver a…
[Link]/playstation

Playtika
Managed O!ers bounties $50 minimum bounty

Playtika is a leading mobile gaming company with over 34 million monthly active users
across a portfolio of games titles. Playtika Ltd. and all of its affiliate companies
(together, “Playtika”) look forward to working in collaboration with the…
[Link]/playtika

Pleo
Pleo looks forward to working with the security community to find security
vulnerabilities. Please submit any questions you might have to security-vd@[Link].
Join our private program Pleo runs a private program. Joining the private program
grants…
[Link]/pleo

Polygon Technology
Managed O!ers bounties $50 minimum bounty

Polygon Labs Bug Bounty Program Polygon Labs looks forward to working with the
security community to find security vulnerabilities to keep users safe. Response Targets
Polygon Labs will make a best effort to meet the following response targets for…

[Link] 5/29/26, 13 37
Page 51 of 79
:
Polygon Labs will make a best effort to meet the following response targets for…
[Link]/polygon-technology

PornBox
Managed O!ers bounties $50 minimum bounty

While we are doing our best to keep Pornbox as safe as possible, we know that some
bugs can slip trough our scrutiny. If you believe you've found a security issue in the
services listed in our scope, we will work with you to resolve it promptly and…
[Link]/pornbox

PortSwigger Web Security


O!ers bounties $100 minimum bounty

Vulnerabilities of interest Here are some examples of vulnerabilities that we could


consider to be valid, and rough guidelines as to what kind of payout you can expect:
Critical - $15,000 SQL injection on [Link] Remotely retrieving…
[Link]/portswigger

Priceline
Managed O!ers bounties $100 minimum bounty

Welcome to Priceline's Bug Bounty Program Priceline is committed to collaborating


with security experts across the globe to stay up-to-date with the latest security
developments. If you have discovered a security issue that you believe requires our…
[Link]/priceline

Privy (Bounty)
O!ers bounties $100 minimum bounty

IMPORTANT ** To be eligible for bounties, please create your Privy account name with
the string "(BBP)" (e.g., in the "Project or company name" field) so we can associate
your account with any submissions to the program. ** Overview Privy believes…
[Link]/privy-bbp

Qualcomm
Qualcomm Technologies Inc. Vulnerability Rewards Program Qualcomm Technologies,
Inc. (QTI) understands that maintaining a large variety of products comes with certain
responsibilities. We recognize that conducting security research often requires…

[Link] 5/29/26, 13 37
Page 52 of 79
:
responsibilities. We recognize that conducting security research often requires…
[Link]/qualcomm

Quora
O!ers bounties $100 minimum bounty

Update Highlights: [Link] ([Link] We highly encourage all researchers who


are interested in AI products to test it and help us maintain the highest possible levels
of security for our users. Introduction We are committed to the safety and…
[Link]/quora

Rabobank
Welcome ! This is our private program and is invitation-only.
[Link]/rabobank

ragnarocSec
ourPolicy
[Link]/ragnarocsec

Razorpay
O!ers bounties $250 minimum bounty

Razorpay looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. Response Targets Razorpay will
make the best effort to meet the following SLAs for hackers participating in our…
[Link]/razorpay

Reddit
Managed O!ers bounties $100 minimum bounty

Reddit Policy Program Terms Reddit's responsible disclosure and bug bounty program
is focused on protecting our users' private data, accounts, and identities. The vast
majority of data posted to Reddit every day is intended to be public, however…
[Link]/reddit

[Link] 5/29/26, 13 37
Page 53 of 79
:
Redox
Managed O!ers bounties $50 minimum bounty
Our Security team identifies, evaluates, and manages vulnerabilities across Redox,
including corporate assets, applications, and cloud infrastructure. Our purpose is to
reduce risk exposure and support our goal to become the most trusted brand in…
[Link]/redox_bbp

REI BBP
Managed O!ers bounties $50 minimum bounty
Purpose At REI, protecting the security and privacy of our members is just as important
as helping them enjoy life outdoors. We believe that a strong security foundation is
essential to earning and maintaining the trust of our community. This bug…
[Link]/rei_bbp

ReleaseWire
Bug Bounty Program If you have found a bug or a security vulnerability in the
ReleaseWire site or related web sites not managed by a 3rd party, we ask that you let
us know as soon as possible. We take all submitted bugs seriously and work to…
[Link]/releasewire

Remitly
O!ers bounties $50 minimum bounty
Remitly looks forward to working with the security community to find security
vulnerabilities in order to keep our customers and business safe. Response Targets
Remitly will make a best effort to meet the following response targets for hackers…
[Link]/remitly

ResourceSpace
Before submittting a report please check the following:- Your organisation doesn't have
a have a commercial contract with us. Supported customers should have their
designated contact raise issues via the customer extranet. You are running the latest…
[Link]/resourcespace

[Link] 5/29/26, 13 37
Page 54 of 79
:
Rijksoverheid
Hoe kan ik een zwakke plek in een ICT-systeem van de Rijksoverheid melden
(Responsible Disclosure)? Een zwakke plek in een ICT-systeem van de Rijksoverheid,
zoals [Link], kunt u melden aan het Nationaal Cyber Security Centrum
(NCSC). U…
[Link]/rijksoverheid

Ring
Managed O!ers bounties $50 minimum bounty

Ring and BlinkForHome Bug Bounty Program Overview We believe that stronger
communities are the key to safer neighborhoods. That’s why we’re driven to create
products that help you protect what matters most at home and empower you to
connect with…
[Link]/ring

Riot Games
CHANGELOG March 13th, 2026 - Updated policy to pause submissions for
UVS/[Link] assets. November 7th, 2025 - Updated policy to clarify repercussions for
improper conduct in the program. October 20th, 2025 - Updated policy to add clarity
on Broken…
[Link]/riot

Ripio
O!ers bounties $100 minimum bounty

Ripio HackerOne Program - Scope & Exclusions Policy (Logic-Based) To ensure


clear communication and efficient triage, we have defined our scope using strict logic-
based rules. Please review these exclusions carefully before submitting. ATO…
[Link]/ripio

Ripple Old
We are offering a bounty for any security-relevant bugs. This includes exploits,
vulnerabilities and information about ongoing attacks. In order to qualify for a bounty, a
bug must be - Relevant – Only security issues qualify for this bounty. A…
[Link]/ripple-old

[Link] 5/29/26, 13 37
Page 55 of 79
:
[Link]
This engagement is an on-going bounty against a hosted vulnerability intelligence
platform. The application processes over 50 million vulnerabilities daily on behalf of its
customers against threat, exploit and breach data collected across 150+…
[Link]/riskio

Robinhood Markets Bounty


Managed O!ers bounties $50 minimum bounty

Robinhood Markets Bounty looks forward to working with the security community to
find vulnerabilities in order to keep our businesses and customers safe. Bug Bounty
Program Rules By submitting reports to our program, you agree that you’ve read,…
[Link]/robinhood

Roblox
Managed O!ers bounties $100 minimum bounty

Our Mission Roblox’s vision is to reimagine the way people come together, and our
mission is to connect a billion people every day with optimism and civility in a shared
3D experience. Our platform empowers people of all ages to imagine, create, and…
[Link]/roblox

Rockstar Games
Managed O!ers bounties $150 minimum bounty

Statement We are dedicated to the privacy and security of our users, and the
environment we create for them. We believe that having a talented group of
independent security researchers is paramount to achieving that goal. We are running
this…
[Link]/rockstargames

Ruby
O!ers bounties $500 minimum bounty

Scope This program is for security issues in the Ruby programming language. Please
note that the following are outside the scope of this program: * Websites (including
*.[Link]) * Third-party applications * Processing Ruby code with RDoc…
[Link]/ruby

[Link] 5/29/26, 13 37
Page 56 of 79
:
[Link]/ruby

S-Pankki
Managed O!ers bounties $150 minimum bounty

S-Pankki Bug Bounty Program S-Pankki and S-Group looks forward to working with
the security community to find security vulnerabilities in order to keep our businesses,
systems and customers safe. This program is a joint effort between S-Pankki and S…
[Link]/s-pankki

Samsung Mobile
Responsible Disclosure Policy At Samsung, we take security and privacy issues very
seriously, and we value the security research community with our commitment to
address potential security vulnerabilities as quickly as possible. The responsible…
[Link]/samsungmobile

Samsung SmartTV
Samsung welcomes you to the Samsung Smart TV Security Bug Bounty Program. We
are pleased to offer a monetary bounty for certain qualifying security bugs. Every
participant has to log a security bug in the Smart TV/BD which thereafter will be…
[Link]/samsungsmar"v

Schuberg Philis
RESPONSIBLE DISCLOSURE We are dedicated to providing a secure environment for
our customers, our visitors and ourselves. Therefore, we appreciate it if you notify us of
any security issues you may encounter. Since we launched our responsible…
[Link]/schubergphilis

Sea
As the security threat landscape evolves, effective security requires continual
engagement and innovation. Sea’s security professionals are committed to continual
improvement and strategic collaboration with other security experts in the security…
[Link]/sea

Security Test External Program

[Link] 5/29/26, 13 37
Page 57 of 79
:
Security Test External Program
See @security.
[Link]/security-test-ep

Security Test External Program + Sandbox


See @security.
[Link]/security-test-ep-sandbox

Semrush
O!ers bounties $100 minimum bounty

Program Policy Play by the rules. This includes following this policy ("Policy"),
HackerOne’s Disclosure Guidelines ([Link] and any other
relevant agreements. Test only with your own account(s) when investigating bugs,
and…
[Link]/semrush

[Link]
[Link]/shapeshift-io

Sheer
Managed O!ers bounties $50 minimum bounty

While we are doing our best to keep Sheer as safe as possible, we know that some
bugs can slip trough our scrutiny. If you believe you've found a security issue in the
services listed in our scope, we will work with you to resolve it promptly and…
[Link]/sheer_bbp

SHEIN
Managed O!ers bounties $100 minimum bounty

SHEIN looks forward to working with the security community to find security
vulnerabilities in order to keep our businesses and customers safe. Response Targets
SHEIN will make a best effort to meet the following response targets for hackers…

[Link] 5/29/26, 13 37
Page 58 of 79
:
SHEIN will make a best effort to meet the following response targets for hackers…
[Link]/shein

Shopify
O!ers bounties $500 minimum bounty
Shopify's Bug Bounty Program We reward security researchers for finding and
reporting vulnerabilities that help keep our platform secure. Our bug bounty program
offers rewards up to $200,000 and bonuses for outstanding contributions. Here’s what
you…
[Link]/shopify

SideFX
Managed O!ers bounties $50 minimum bounty
Brand Promise SideFX looks forward to working with the security community to find
vulnerabilities in order to keep our businesses and customers safe. Rewards Rewards
are based on severity per CVSS (the Common Vulnerability Scoring Standard (https:/…
[Link]/sidefx

Simple
Simple offers a bank account that has all the tools you need to manage your money
built right in, including a Simple Visa® Card, our powerful iOS and Android apps, a
beautifully designed web interface, and customer support that really cares. Simple…
[Link]/simple

SimplyBuilt
We take security very seriously here at SimplyBuilt! As such, we provide bug bounties
for security related issues that are responsibly reported to us. Please review our Rules
and Guidelines for bug bounties before you start hunting. If you think you…
[Link]/simplybuilt

SIX Group
Managed O!ers bounties $50 minimum bounty
SIX operates the infrastructure for the financial centers in Switzerland and Spain, thus
ensuring the flow of information and money between financial market players. SIX
offers exchange services, financial information and banking services with the…

[Link] 5/29/26, 13 37
Page 59 of 79
:
offers exchange services, financial information and banking services with the…
[Link]/six-group

SIX Group Private


SIX operates the infrastructure for the financial centers in Switzerland and Spain, thus
ensuring the flow of information and money between financial market players. SIX
offers exchange services, financial information and banking services with the…
[Link]/six-group-private

slack
[Link]
[Link]/slack-bbp

Slack
Managed O!ers bounties $250 minimum bounty

Slack Technologies, LLC, a Salesforce company Over $12M in bounties awarded


across all our H1 Bug Bounty programs since 2015! At Slack, a Salesforce company,
Trust is our #1 value and we take the protection of our customers' data very seriously.
We…
[Link]/slack

SmartNews
test
[Link]/smartnews

SMTP2GO BBP
Managed O!ers bounties $100 minimum bounty

SMTP2GO is a fast and scalable email service provider, for sending transactional and
marketing emails and viewing reports on email delivery. SMTP2GO has previously run a
Vulnerability Disclosure Program (VDP) and made the switch to a Bug Bounty…
[Link]/smtp2go

[Link] 5/29/26, 13 37
Page 60 of 79
:
Snapchat
O!ers bounties $250 minimum bounty

Policy At Snapchat, we are looking forward to fostering new relationships with the
security community as part of our bug bounty program (“Bug Bounty Program”). Our
security team reviews all vulnerability reports and acts upon them in accordance with…
[Link]/snapchat

Snowflake
Snowflake’s Vulnerability Disclosure Policy Overview Snowflake Inc. (“Snowflake”) is
committed to the security and privacy of our customers and their data. We believe that
collaborating with the security community and supporting coordinated…
[Link]/snowflake

Socket
If you believe you've found a security issue in our product or service, we encourage
you to notify us. We will work with you to resolve the issue promptly. Thanks in
advance! Socket has other policies concerning disclosure of vulnerabilities found…
[Link]/socket_dev

Sofi
Introduction Welcome to SoFi’s Bug Bounty Program! Our commitment to security
means we value the independent security research community's contribution. SoFi’s
bug bounty program is private and invite-only and requires SoFi’s Security Team to
review…
[Link]/sofi-1

Sorare
Managed O!ers bounties $50 minimum bounty

Introduction Sorare recognizes the importance and value of security researchers’


efforts in helping keep our community safe. We encourage responsible disclosure of
security vulnerabilities via our bug bounty program (“Bug Bounty Program”)
described…
[Link]/sorare

[Link] 5/29/26, 13 37
Page 61 of 79
:
Sourcegraph OLD
Our policy is documented at [Link]
[Link]/sourcegraph_old

Spotify
Managed O!ers bounties $250 minimum bounty
We're big believers in protecting your privacy and security. As a company, we not only
have a vested interest, but also a deep desire to see the Internet remain as safe as
possible for us all. So, needless to say, we take security issues very…
[Link]/spotify

Starbucks
Managed O!ers bounties $100 minimum bounty
Starbucks believes in a program that fosters collaboration among security
professionals to help protect our systems and customers’ personal information from
malicious activity and to help set security policies across our organization. We value
the…
[Link]/starbucks

Starbucks China
Managed O!ers bounties $50 minimum bounty
Starbucks believes in a program that fosters collaboration among security
professionals to help protect our systems and customers’ personal information from
malicious activity and to help set security policies across our organization. We value
the…
[Link]/starbucks_china

Starbucks Japan
Managed O!ers bounties $50 minimum bounty
Starbucks believes in a program that fosters collaboration among security
professionals to help protect our systems and customers’ personal information from
malicious activity and to help set security policies across our organization. We value
the…
[Link]/starbucks_japan

[Link] 5/29/26, 13 37
Page 62 of 79
:
[Link]/starbucks_japan

[Link]
StatusPage takes security very seriously, and we thank all of the white hats in our
community for their research and assistance. Below you will find our responsible
vulnerability disclosure policy, as well as multiple methods to get in contact with…
[Link]/statuspageio

Stripchat
O!ers bounties $50 minimum bounty
Stripchat Bug Bounty Program Policy (“Program Policy”) At Stripchat, we take the
security and privacy of our platform very seriously. We highly value collaboration with
skilled security researchers who help us improve the protection of our users,…
[Link]/stripchat

Stripe
Managed O!ers bounties $100 minimum bounty
The Stripe Bug Bounty Program Terms and Conditions ("Terms'') governs your
participation in the Stripe Bug Bounty Program ("Program"). These Terms are between
you and Stripe ("Stripe," "us," or "we"). By performing vulnerability research against…
[Link]/stripe

Sunrise
We appreciate all security concerns brought forth and are constantly striving to keep on
top of the latest threats. Being pro-active rather than re-active to emerging security
issues is a fundamental belief at Sunrise. Every day new security issues…
[Link]/sunrise

Superbet
Managed O!ers bounties $100 minimum bounty
Please limit the amount of requests to max 50/second Do not use Scanners such as
Nessus, acunetix,etc, we already scan our assets with these tools and you won't be
rewarded if you report vulnerabilities found by scanners All our LOGIN services are…
[Link]/superbet

[Link] 5/29/26, 13 37
Page 63 of 79
:
Superhuman (formerly Grammarly)
Managed O!ers bounties $100 minimum bounty

Superhuman (formerly Grammarly) Bug Bounty Program Welcome, Hackers


We’ve merged the Grammarly and Coda programs into a single unified program —
Superhuman (formerly Grammarly). We’re excited to continue working with the security
community…
[Link]/superhuman

Sweet TV
Sweet TV engineers work hard to ensure that our site and users are 100% safe and
sound. We greatly respect the work of security experts everywhere and strive to stay
up to date with the latest security techniques. But nobody's perfect. Should you…
[Link]/sweet_bbp

Swiggy
[Link]/swiggy

Syfe
Managed O!ers bounties $50 minimum bounty

Disclosure Policy Please do not discuss any vulnerabilities (even resolved ones) outside
of the program without express consent from the organization. Follow HackerOne's
disclosure guidelines ([Link]
[Link]/syfe_bbp

Symphony
Enterprise customers may report issues via their Symphony technical support contacts.
Symphony runs a private invitation-only program on HackerOne, receiving vulnerability
disclosures from participants covering freely accessible web sites.
[Link]/symphony-3

[Link] 5/29/26, 13 37
Page 64 of 79
:
Synology
Synology Security Bug Bounty Program As threats evolve and increase in both
frequency and sophistication, Synology is working with security researchers to maintain
and further bolster our protections. Synology’s Security Bug Bounty Program grants…
[Link]/synology

Tarsnap
According to Linus' Law, "given enough eyeballs, all bugs are shallow". This is one of
the reasons why the Tarsnap client source code is publicly available; but merely making
the source code available doesn't accomplish anything if people don't…
[Link]/tarsnap

Taxfix
Taxfix runs a private bug bounty program and is on a per-invite basis only. If you
believe you've discovered a security bug or vulnerability in the Taxfix service, please
report it to us at the "Contact Security team" link on this page. Our…
[Link]/taxfix

Technisys
Introducción ¡Bienvenido al Programa de Recompensas por Errores de Technisys!
Nuestro compromiso con la seguridad significa que valoramos la contribución de la
comunidad de investigación independiente en seguridad. El programa de recompensas
por…
[Link]/galileo-ft

Telegram
Q: Why should I trust you? Telegram is open, anyone can check our source code,
protocol and API, see how everything works and make an informed decision. In fact,
we welcome security experts to audit our system and will appreciate any feedback.
We…
[Link]/telegram

Temu
Managed O!ers bounties $50 minimum bounty

[Link] 5/29/26, 13 37
Page 65 of 79
:
Managed O!ers bounties $50 minimum bounty
Temu looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. Response Targets Temu will make a
best effort to meet the following SLAs for hackers participating in our program: …
[Link]/temu

test
test
[Link]/sec1337

Test Inc
All south of bugs
[Link]/h1111

tes"es"es"es"es"es"es"est
test
[Link]/tes"es"es"es"f"es"es"e

The Browser Company of NYC


Managed O!ers bounties $50 minimum bounty
Response Targets The Browser Company will make a best effort to meet the following
response targets for researchers participating in our program: Time to first response
(from report submit) - 3 business days Time to triage (from report submit) - 10…
[Link]/bcny

TikTok
Managed O!ers bounties $50 minimum bounty
TikTok Bug Bounty Program Policy TikTok's mission is to inspire creativity and bring joy
to our vibrant community. We recognize and value external feedback from the global
security research community on potential vulnerabilities which helps…
[Link]/tiktok

[Link] 5/29/26, 13 37
Page 66 of 79
:
Tinder
Managed O!ers bounties $250 minimum bounty
Tinder Bug Bounty Program Terms Security is a top priority at Tinder. If you believe
you've found a security bug in our in-scope applications or infrastructure, we are happy
to work with you to resolve the issue promptly and ensure you are fairly…
[Link]/tinder

Tools for Humanity


Managed O!ers bounties $100 minimum bounty
Tools For Humanity (TFH) is proud to collaborate with the vibrant community of
independent security research to secure our platform and our users. To recognize your
efforts and the role you play in enhancing the security of TFH and the World…
[Link]/toolsforhumanity

Tor
O!ers bounties $100 minimum bounty
The Tor Project is committed to working with security experts across the world to stay
up to date with the latest security techniques. If you have discovered a security issue
that you believe we should know about, we'd welcome working with you. The…
[Link]/torproject

TradingView
We offer rewards for reports about security vulnerabilities in our services, infrastructure,
web and mobile applications. If you have found a security vulnerability and would like
to report it to us, please use this form: [Link]
[Link]/tradingview-2

Trendyol
O!ers bounties $50 minimum bounty
As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value
security and privacy and look forward to working with the security community to find
security vulnerabilities in order to keep our businesses and customers safe. Off the
back…
[Link]/trendyol

[Link] 5/29/26, 13 37
Page 67 of 79
:
[Link]/trendyol

[Link]
Managed O!ers bounties $50 minimum bounty
[Link] Group looks forward to working with the security community to find
vulnerabilities in order to keep our businesses and customers safe. ==** Before
submitting a vulnerability report, please read our policy first**== Response Targets
[Link]…
[Link]/trip_com

TripAdvisor
Testing ...
[Link]/tripadvisor

TRON DAO
O!ers bounties $50 minimum bounty
TRON is an open-source platform for launching highly decentralized applications, new
financial primitives, and new interoperable blockchains. It is conducted and supported
by the active TRON developer community and is governed by TRON DAO. The
TRON…
[Link]/tron_dao

Truecaller
Managed O!ers bounties $100 minimum bounty
General rules Provide detailed reports with reproducible steps. If the report is not
detailed enough to reproduce the issue, the issue will not be eligible for a reward.
Submit one vulnerability per report, unless you need to chain vulnerabilities…
[Link]/truecaller

Tweakers
Tweakers has a bug bounty program via Intigriti. For more information and reports see:
[Link]
[Link]/tweakers

[Link] 5/29/26, 13 37
Page 68 of 79
:
Twilio
Managed O!ers bounties $50 minimum bounty

Twilio Security Disclosure Program Overview Ensuring the security and integrity of the
Twilio platform is critical to the service we provide to our customers. We are committed
to providing a secure product and appreciate help from the community in…
[Link]/twilio

TYPO3
Security in TYPO3 TYPO3 Security Team ([Link]
Reporting & Security Policy ([Link]
in-typo3) Bug Bounty Program & Rules ([Link]
[Link]/typo3

Uber
Managed O!ers bounties $500 minimum bounty

Uber Bug Bounty Program Terms The scope for Uber’s Bug Bounty Program is
focused on securing the data of our users and company assets. Therefore, our
approach is to evaluate any given report based on the specific security impact for users

[Link]/uber

Ubiquiti Inc.
Managed O!ers bounties $150 minimum bounty

Introduction At Ubiquiti Inc. ("Ubiquiti"), we take security very seriously, and embrace
the security research community. We provide products and services that millions
around the world use every day, and understand privacy and security is very…
[Link]/ui

Udemy
Managed O!ers bounties $50 minimum bounty

TL;DR Do no harm. Respect users’ privacy. Research and disclose in good faith.
Udemy is a global marketplace for learning and instruction. By connecting students all
over the world to the best instructors, Udemy is helping individuals reach their…
[Link]/udemy

[Link] 5/29/26, 13 37
Page 69 of 79
:
[Link]/udemy

Unico IDtech
Managed O!ers bounties $50 minimum bounty

Unico IDTech Bug Bounty Program Unico IDTech is pioneering the future of biometric
authentication through our advanced liveness detection engine. We're inviting security
researchers to help protect millions of digital identities by finding novel…
[Link]/unico_idtech

United
United Airlines vulnerability disclosure program At United, we take your safety, security
and privacy seriously. We utilize best practices and are confident that our systems are
secure. We are committed to protecting our customers' privacy and the…
[Link]/united

Urban Company
O!ers bounties $200 minimum bounty

We take security seriously at Urban Company, and we’re committed to protecting our
community. If you are a security researcher or expert and believe you’ve identified
security-related issues with Urban Company’s website or apps, we would appreciate…
[Link]/urbancompany

Valve
Managed O!ers bounties $100 minimum bounty

If you are a Steam user and have a security issue to report regarding your personal
Steam account, please visit our support site [Link] This
includes password problems, login issues, suspected fraud, and account abuse
issues…
[Link]/valve

Van Lanschot
Responsible Disclosure – Van Lanschot Kempen Van Lanschot Kempen considers the
security of its systems a top priority. If you identify a weakness, we request that you
report it to us responsibly. Who can report Any individual who discovers a…
[Link]/vanlanschot

[Link] 5/29/26, 13 37
Page 70 of 79
:
[Link]/vanlanschot

Varonis
Managed O!ers bounties $50 minimum bounty
Varonis Bug Bounty Program (BBP) Policy At Varonis, we specialize in software for data
protection, threat detection and response, and compliance – and we know how
valuable contributions from the security community help safeguard organizations. We…
[Link]/varonis

Vercel Open Source


Managed O!ers bounties $50 minimum bounty
Vercel looks forward to working with the security community to find vulnerabilities in
our open source projects in order to keep our ecosystem and users safe. This program
covers core Vercel open source projects that power modern web development…
[Link]/vercel-open-source

Veridu
We understand the hard work that goes into security research. To show our
appreciation for researchers who help us keep our users safe, we operate a reward
program for responsibly disclosed vulnerabilities on our API and Widgets. Veridu may
reward…
[Link]/veridu

Verily Life Sciences


Managed O!ers bounties $50 minimum bounty
Disclosure Policy Please do not discuss any vulnerabilities (even resolved ones) outside
of the program without express consent from the organization. Follow HackerOne's
disclosure guidelines ([Link]
[Link]/verily_life_sciences

Via
O!ers bounties $50 minimum bounty
About Via At Via, we are building the transportation systems of tomorrow, right now.
Via's technology is deployed worldwide through dozens of partner projects with public
transportation agencies, private transit operators, taxi fleets, private…

[Link] 5/29/26, 13 37
Page 71 of 79
:
transportation agencies, private transit operators, taxi fleets, private…
[Link]/ridewithvia

Vimeo
Managed O!ers bounties $100 minimum bounty
Vimeo's Bug Bounty Program Policy Vimeo engineers are committed to ensuring the
safety and security of our site and users. We greatly respect the work of security
experts and strive to stay up-to-date with the latest security techniques. However,
we…
[Link]/vimeo

Visa
Managed O!ers bounties $50 minimum bounty
Visa Bug Bounty Program Rules Visa is a global payments technology company that
connects consumers, businesses, financial institutions and governments in more than
200 countries and territories to fast, secure and reliable digital currency. We have…
[Link]/visa

Vodafone Oman
O!ers bounties $50 minimum bounty
Vodafone Oman looks forward to working with the security community to find
vulnerabilities in order to keep our businesses and customers safe. Response Targets
Vodafone Oman will make a best effort to meet the following SLAs for hackers…
[Link]/vodafone_oman

Wallet on Telegram
Managed O!ers bounties $50 minimum bounty
Wallet on Telegram looks forward to working with the security community to find
vulnerabilities in order to keep our businesses and customers safe. Vulnerability
Classification & Severity Levels We assess and categorize reported
vulnerabilities…
[Link]/wallet_on_telegram

Wamba
Wamba Bug Bounty Program Wamba invites you to take part in Wamba Bug Bounty

[Link] 5/29/26, 13 37
Page 72 of 79
:
Wamba Bug Bounty Program Wamba invites you to take part in Wamba Bug Bounty
Program, which aims to search for possible vulnerabilities of our service. We give a
reward for each vulnerability found, and add the names of users who successfully
found…
[Link]/wamba

WazirX
[Link]/wazirx

Wealthsimple
Managed O!ers bounties $100 minimum bounty

Introduction Wealthsimple looks forward to working with the security community to find
security vulnerabilities in order to keep our businesses and customers safe. Please
read through and abide by the following program rules and scope exclusions…
[Link]/wealthsimple

[Link] GmbH
Security of data entrusted to us by our clients has the highest priority. This is why we
have decided to implement a bug bounty program and invite independent security
researchers to help us further improve the security of our systems. Systems in…
[Link]/web_de_gmbh

Websecurify
Bug Bounty Eligibility Rules Give us reasonable time before making any information
public. Be the first person to report the bug. All high to critical severity issues qualify.
The award value varies depending on the severity and creativity of your…
[Link]/websecurify

Wells Fargo Bounty


Managed O!ers bounties $150 minimum bounty

Introduction Wells Fargo welcomes security researchers to participate in our bug


bounty program to help us identify and fix vulnerabilities in our systems. By working
together, we can improve everyone's security of our products and services. Note:…

[Link] 5/29/26, 13 37
Page 73 of 79
:
together, we can improve everyone's security of our products and services. Note:…
[Link]/wellsfargo-bbp

Werken Bij Defensie


Responsible disclosure Optimizing safety when it comes to the ICT systems is a top
priority for the Dutch Ministry of Defense. However, as such systems remain vulnerable,
possible loopholes and weaknesses cannot be eliminated. Hence, we would love…
[Link]/werkenbijdef

Whatnot
Managed O!ers bounties $50 minimum bounty

Important program rule: While registering an account on Whatnot, please use email
address: username@[Link] Whatnot is a livestream shopping platform
where people buy and sell in real time across categories like trading cards, sneakers,…
[Link]/whatnot

WHMCS
WHMCS is now a part of the WebPros Private Bug Bounty on HackerOne. This page is
retained for legacy reasons and does not accept new reports. Please use the contacts
listed in the [Link] ([Link] to…
[Link]/whmcs

Whoop Bug Bounty


Managed O!ers bounties $50 minimum bounty

At WHOOP, our mission is to unlock human performance. We exist to improve the lives
of our members, not invade their lives. Like all companies providing wearable devices
and health monitoring services, WHOOP manages personal and sensitive data of…
[Link]/whoop_bug_bounty

WisdomTree, Inc.
Managed O!ers bounties $50 minimum bounty

WISDOMTREE BUG BOUNTY PROGRAM POLICY Updates: February 2026: Updated


Bounty Table WisdomTree, Inc. and its subsidiaries (“WisdomTree”) takes very seriously
and prioritizes the security of our customers data, products and services. If you have…
[Link]/wisdomtree

[Link] 5/29/26, 13 37
Page 74 of 79
:
[Link]/wisdomtree

WordPress
O!ers bounties $10 minimum bounty
WordPress ([Link] is an open-source publishing platform. Our
HackerOne program covers the Core software, as well as a variety of related projects
and infrastructure. Our most critical targets are: WordPress Core software (https:/…
[Link]/wordpress

WP Engine
[Link]/wpengine

X / xAI
Managed O!ers bounties $100 minimum bounty

Program Rules Maintaining effective security is a community effort, and we are proud
to have a vibrant group of independent security researchers who volunteer their time to
help us spot potential issues. To recognize their efforts and the important…
[Link]/x

Xiaomi
O!ers bounties $50 minimum bounty

TABLE OF CONTENTS Ground Rules & Code of Conduct Disclosure Policy Safe
Harbour Response Time General Assessment Rules Detailed Rules and Reward
Scheme Web Vulnerabilities Mobile Vulnerabilities Hardware Vulnerabilities Privacy
Vulnerabilities…
[Link]/xiaomi

XVIDEOS
Managed O!ers bounties $50 minimum bounty
Xvideos looks forward to working with the security community to find vulnerabilities in
order to keep our businesses and customers safe. While we are doing our best to keep
Xvideos services as safe as possible, we know that some bugs can slip…
[Link]/xvideos

[Link] 5/29/26, 13 37
Page 75 of 79
:
[Link]/xvideos

Yammer
Yammer is participating in the Microsoft Online Services Bug Bounty
([Link]
launches-office-365/), which allows thousands of security researchers to test Yammer
and help make…
[Link]/yammer

Yandex
Охота за ошибками Яндекс выплачивает награды за обнаружение проблем в
безопасности своих сервисов. Любой желающий может попытаться найти
уязвимость, сообщить нам ([Link] нам об этом и
получить денежный приз, а также…
[Link]/yandex

[Link]
[Link]/yatra_com

Yelp
O!ers bounties $50 minimum bounty
There’s no such thing as a perfect technology — not since they put the finishing
touches on the wheel — but here at Yelp we are committed to getting as close as we
can. It’s a big world and we believe that working with skilled security researchers…
[Link]/yelp

Yoti
O!ers bounties $100 minimum bounty
SIGNUP / Hackerone identification SIGNUP: when registering an organisation, page,
application or any "service" within our various services, can you please prepend
[Hackerone] to the names you use! For example, when register a business or…
[Link]/yoti

[Link] 5/29/26, 13 37
Page 76 of 79
:
YouTube
This application is covered under the Google Vulnerability Reward Program – read more
@google.
[Link]/youtube

Zabbix
Managed O!ers bounties $50 minimum bounty
Please take the time to carefully read the rules and scope exclusions. Failure to adhere
can result in your report being closed as Not Applicable (reputation penalty). Scope
This program is solely focused on finding vulnerabilities in the Zabbix…
[Link]/zabbix

Zapier OLD
Contact Please email us at security@[Link] with any vulnerability reports or
questions about the program. Please report each new bug in a separate email thread.
Security Exploit Bounty Program ([Link]
[Link]/zapier-old

Zoominfo
Before submitting a claim, please read some of the guidelines and scope of the
program. If you have other issues with your account, please use the links or contacts
below for help. Be aware that accessing another person’s account while logged into…
[Link]/zoominfo

Zooplus
Managed O!ers bounties $50 minimum bounty
Zooplus Since 1999, zooplus has been a pioneer in pet supplies e-commerce, serving
millions of pet parents with an ever-growing range of nutritional and lifestyle products,
proprietary premium food and accessory brands, alongside expert advice,…
[Link]/zooplus

ZTE

[Link] 5/29/26, 13 37
Page 77 of 79
:
ZTE
ZTE has launched its new Bug Bounty Programs to encourage security
researchers/organizations worldwide to identify vulnerabilities in ZTE’s products and
services. ZTE Bug Bounty Programs cover the following four categories of products,
specifically,…
[Link]/zte

What is the HackerOne bug bounty program?


HackerOne is the #1 crowdsourced security platform, helping organizations
find and fix critical vulnerabilities before attackers can exploit them.
HackerOne Bounty connects you with a global community of vetted ethical
hackers who uncover high-impact vulnerabilities tailored to your assets and
goals. The platform combines triage, validation, communication, and
workflow integration with AI-powered risk prioritization, actionable
recommendations, and benchmarking insights, driven by Hai, to improve
outcomes over time.

Learn more about the HackerOne platform and how it can strengthen your
security program.

Contacted by a hacker?

Company

Knowledge Center

[Link] 5/29/26, 13 37
Page 78 of 79
:
Resources

Policies Terms Privacy Security Trust

©2026 HackerOne All rights reserved.

[Link] 5/29/26, 13 37
Page 79 of 79
:

You might also like