Independent ratings · by the researchers who work them
Know which programs are worth your time.
A standardized rating for every bug bounty program — triage speed, payout fairness, communication, and whether researchers would submit again. The good, the bad, and the data behind both.
Security releases
All releases →When a vendor ships a security release it names the researchers behind it — CVEs and additional recognitions alike. We record every line, CVE or not, with a BugRater ID you can quote. If your name is here, the credit is yours to claim — instantly, and durable on your profile.
macOS Tahoe 26.6
iOS 26.6 and iPadOS 26.6
Recent reviews
I've spent a significant amount of time testing Personio and interacting with their security team through responsible disclosure. Overall, the experience has been positive. The security team is professional, communicates clearly, and is willing to discuss technical details rather than relying on generic responses. Reports are reviewed carefully, and when a finding is considered out of scope or not applicable, they generally explain their reasoning instead of sending a canned rejection.
As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs and vendors.
NASA VDP is triaged by Bugcrowd team before handing it over to NASA officials for confirmation. I noticed that Bugcrowd's bot such as teapot_bugcrowd tends to mark report submissions as N/A. This was the case with my accepted report that earned me the NASA's LoR. I submitted a report in December 2024, but Bugcrowd's bot triaged it as N/A. Only in June 2025 did Bugcrowd's human triagers receive similar reports from other hackers, and they traced my report to be the first submission of its kind and marked my report as Accepted. The NASA VDP accepts only unique, non-duplicate reports that demonstrate a real security impact. However, my main critique of this program is related to a vulnerability I discovered. My report was closed as a duplicate of one submitted by another hacker over a year ago. Despite this long timeline, the affected endpoint remains completely unpatched, which I believe will cause more hackers to waste time and effort.
I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.
Contribute
Had a good experience? That’s the review researchers actually need.
Positive reviews tell people where to focus. Negative ones tell them what to expect. Both make the directory worth trusting.
The brief
Get the data, not the noise.
Occasional briefs built from real researcher reviews — which programs are worth your time, what the numbers say, and the pieces we publish. No spam.