Early access — the directory is still filling out, and every rating here is a reported experience.

Community

Review Guidelines

A good review helps another researcher decide where to spend their week. These guidelines keep BugRater honest, useful, and safe. Reviews that follow them get published faster; reviews that don't get sent back or removed.

Write from first-hand experience

Only review a program you actually worked. Base your rating on your own submissions and interactions — triage speed, payout fairness, communication, scope honesty, and whether you'd submit again. Secondhand rumors and "I heard that…" don't belong here.

Be specific and fair

Specifics help: median time to first response, how a duplicate or scope dispute was handled, how the payout compared to the advertised range. Both positive and negative reviews are welcome — the fast, fair programs deserve credit just as much as the slow ones deserve a heads-up. Rate the experience you had, not the mood you're in.

Never post sensitive details publicly

Protecting users comes first. Nothing below relaxes this. Do not post:

You can describe how a program handled a report without revealing what the report was.

You may tell us privately

The most useful thing on a program page is why reports get closed there — and the useful version of that needs detail you must never publish. So we ask for it privately instead. Each report row in the review form has a Tell us privately panel with three questions:

Never a proof of concept, never reproduction steps, never a payload. If someone could follow what you wrote, it is too much — trim it or leave it blank. The panel is optional, the consent box is off until you tick it, and you can withdraw everything you have given us at any time from your reviews, which erases the text.

What we do with it

One promise, and it is the whole design: it never appears as your report — only as a number in a distribution that at least three reports contributed to. Here is how that is held up.

What encryption at rest does not do is defeat someone who has compromised the application itself: code that runs as us can use the key, the same way the site does when it shows you your own answers. That is the honest boundary, and it is the reason the aggregate floors above are enforced in the query rather than left to good intentions.

If it isn't fixed yet

Tick hold this back on that report. An embargoed row counts toward nothing — not the component list, not any total — until you come back and untick it. If you are unsure whether a fix has shipped, leave it ticked.

Your NDA and the program's terms still bind you

Us asking does not override them. We are a third party. If the program's terms, your NDA, or a platform's disclosure policy forbid sharing this with anyone outside the program, then they forbid sharing it with us — don't. Leaving the panel blank costs you nothing, and a review with no private detail is still a good review.

No doxxing

Critique the program and its process, not the people. Don't publish private information about anyone, and don't name and target individual triagers or employees. "The triage team was slow to respond" is fair; naming a specific person to attack them is not.

No astroturfing or retaliation

Companies may not rate their own programs, and no one may post fake positive reviews to inflate a grade. Likewise, don't post a retaliatory fake review to punish a program over an unrelated dispute. Both undermine the ratings everyone relies on.

What gets a review rejected

We decline reviews that aren't first-hand, disclose sensitive or embargoed details, break an NDA, name individuals, read as astroturfing or retaliation, or are abusive or spammy. Reviews from researchers who've verified a platform account carry more weight in a program's grade, so verifying your account makes your honest experience count for more.

Keep it constructive

The goal is to help researchers choose where to spend their time. Write the review you wish you'd read before you started — clear, specific, and fair.

Write a review Browse programs