Early access — the directory is still filling out, and every rating here is a reported experience.

Security releases

Where credit is recorded in public

3 releases

Vendors name researchers in their own advisories and release notes — verifiable ground truth that needs no platform's permission. Find your line and claim it: it is yours immediately, and it is durable standing on your profile even for vendors that run no bounty platform at all. Every credit carries a BugRater ID you can quote, CVE or not.