Early access — the directory is still filling out, and every rating here is a reported experience.
MI

Self-hosted security programme

Microsoft

Microsoft runs the Microsoft Security Response Center rather than a third-party platform, and there is no profile to claim here.

MSRC is not one bounty but many — Azure, Microsoft 365, Windows, Edge, identity, AI — each with its own scope and award table. Reading the right programme page before submitting is the highest-value thing you can do.

Direct How to report
MSRC Triage
Many Programmes
Update Guide Where credit lands

Getting credit

Report to Microsoft, claim it here

Credit publishes in Microsoft’s own advisories, often months after the report. We index those, so it is waiting for you — including recognitions that carry no CVE and appear nowhere else.

Microsoft

Enterprise software · USA

microsoft.com →

Found a vulnerability?

Microsoft runs its own vulnerability reporting process. Here are your two ways to report it — we recommend the first.

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Programs