Getting credit
Report to Microsoft, claim it here
Credit publishes in Microsoft’s own advisories, often months after the report. We index those, so it is waiting for you — including recognitions that carry no CVE and appear nowhere else.
Microsoft runs the Microsoft Security Response Center rather than a third-party platform, and there is no profile to claim here.
MSRC is not one bounty but many — Azure, Microsoft 365, Windows, Edge, identity, AI — each with its own scope and award table. Reading the right programme page before submitting is the highest-value thing you can do.
Getting credit
Credit publishes in Microsoft’s own advisories, often months after the report. We index those, so it is waiting for you — including recognitions that carry no CVE and appear nowhere else.
Found a vulnerability?
Microsoft runs its own vulnerability reporting process. Here are your two ways to report it — we recommend the first.
Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.