Early access: the directory is still filling out, and every rating here is a reported experience.

State of the market · updated live from approved reviews

The State of Bug Bounty

An aggregate read on how programs actually behave, built entirely from 101 researcher-submitted, admin-approved reviews across 8776 programs. No vendor self-reporting: every number below comes from people who actually filed reports.

8776
Programs rated
101
Approved reviews
5
Verified researchers
36%
Would submit again

Grade distribution

1 graded · 8775 not yet rated
A programs 1 · 100%
B programs 0 · 0%
C programs 0 · 0%
D programs 0 · 0%
F programs 0 · 0%

Time to first response

7 reviews reporting
Same day 0 · 0%
Within 3 days 5 · 71%
Within 2 weeks 0 · 0%
Within a month 0 · 0%
1–3 months 2 · 29%
Over 3 months 0 · 0%

Paid the advertised range?

97 reviews reporting
Paid the advertised range 36 · 37%
Paid below the range 1 · 1%
Did not pay fairly 60 · 62%

Most-reported practices

Top strengths
+ Credits researchers 6 reports
+ Clear, honest scope 6 reports
+ Responsive communication 4 reports
+ Clear, current policy 4 reports
+ Respectful & professional 4 reports
Top concerns
− Slow to pay 4 reports
− Downgrades severity 2 reports
− Slow to first response 2 reports
− Auto-closes valid reports 1 report
− Disputes valid scope 1 report

Deduced from platform data · updated hourly

Intelligence

6,351 programs tracked

Cross-referenced from metrics snapshots, thanks leaderboards, researcher profiles, and advisory credits. Click any row to see the reasoning chain.

Reports (90-day window)
120,163
Lifetime resolved
223,280
Bounties paid (lifetime)
$152.4M
Median critical payout
$4,938
Avg response efficiency
79%
Invite-only programs
0

Launch surges

9 programs under 30 days old

Programs that launched recently and are taking reports faster than they can process.

Arc
Hackerone · 17 days old
3,097reports
182.2/day intake
2resolved
1.First seen in metrics 17 days ago → program is ≤17d old
2.reports_received_90d = 3,097 (rolling window, but program is 17d old → this IS the real total)
3.Intake rate = 3,097 ÷ 17d = 182.2 reports/day
4.resolved_report_count = 2 (lifetime monotonic counter)
5.Estimated backlog = 3,097 − 2 = 3,095 unresolved

⇒ At current intake of 182.2/day with 3,095 backlogged, this program is accumulating faster than resolving.

Omarchy
Hackerone · 2 days old
356reports
178.0/day intake
0resolved
1.First seen in metrics 2 days ago → program is ≤2d old
2.reports_received_90d = 356 (rolling window, but program is 2d old → this IS the real total)
3.Intake rate = 356 ÷ 2d = 178.0 reports/day
4.resolved_report_count = 0 (lifetime monotonic counter)
5.Estimated backlog = 356 − 0 = 356 unresolved

⇒ At current intake of 178.0/day with 356 backlogged, this program is accumulating faster than resolving.

Vercel
Hackerone · 12 days old
1,862reports
155.2/day intake
322resolved
1.First seen in metrics 12 days ago → program is ≤12d old
2.reports_received_90d = 1,862 (rolling window, but program is 12d old → this IS the real total)
3.Intake rate = 1,862 ÷ 12d = 155.2 reports/day
4.resolved_report_count = 322 (lifetime monotonic counter)
5.Estimated backlog = 1,862 − 322 = 1,540 unresolved

⇒ At current intake of 155.2/day with 1,540 backlogged, this program is accumulating faster than resolving.

Live Nation
Hackerone · 9 days old
909reports
101.0/day intake
65resolved
1.First seen in metrics 9 days ago → program is ≤9d old
2.reports_received_90d = 909 (rolling window, but program is 9d old → this IS the real total)
3.Intake rate = 909 ÷ 9d = 101.0 reports/day
4.resolved_report_count = 65 (lifetime monotonic counter)
5.Estimated backlog = 909 − 65 = 844 unresolved

⇒ At current intake of 101.0/day with 844 backlogged, this program is accumulating faster than resolving.

Walt.io
Hackerone · 3 days old
150reports
50.0/day intake
27resolved
1.First seen in metrics 3 days ago → program is ≤3d old
2.reports_received_90d = 150 (rolling window, but program is 3d old → this IS the real total)
3.Intake rate = 150 ÷ 3d = 50.0 reports/day
4.resolved_report_count = 27 (lifetime monotonic counter)
5.Estimated backlog = 150 − 27 = 123 unresolved

⇒ At current intake of 50.0/day with 123 backlogged, this program is accumulating faster than resolving.

d-you App & German EUDI Wallet Ecosystem
Hackerone · 17 days old
722reports
42.5/day intake
0resolved
1.First seen in metrics 17 days ago → program is ≤17d old
2.reports_received_90d = 722 (rolling window, but program is 17d old → this IS the real total)
3.Intake rate = 722 ÷ 17d = 42.5 reports/day
4.resolved_report_count = 0 (lifetime monotonic counter)
5.Estimated backlog = 722 − 0 = 722 unresolved

⇒ At current intake of 42.5/day with 722 backlogged, this program is accumulating faster than resolving.

Nebius AI Vulnerability Disclosure
Hackerone · 10 days old
206reports
20.6/day intake
0resolved
1.First seen in metrics 10 days ago → program is ≤10d old
2.reports_received_90d = 206 (rolling window, but program is 10d old → this IS the real total)
3.Intake rate = 206 ÷ 10d = 20.6 reports/day
4.resolved_report_count = 0 (lifetime monotonic counter)
5.Estimated backlog = 206 − 0 = 206 unresolved

⇒ At current intake of 20.6/day with 206 backlogged, this program is accumulating faster than resolving.

CoinDCX Vulnerability Disclosure
Hackerone · 9 days old
68reports
7.6/day intake
213resolved
1.First seen in metrics 9 days ago → program is ≤9d old
2.reports_received_90d = 68 (rolling window, but program is 9d old → this IS the real total)
3.Intake rate = 68 ÷ 9d = 7.6 reports/day
4.resolved_report_count = 213 (lifetime monotonic counter)
5.Estimated backlog = 68 − 213 = -145 unresolved

⇒ At current intake of 7.6/day with -145 backlogged, this program is accumulating faster than resolving.

Crowding signals

31 programs

Rate of change in the 90-day report window. Positive = intake accelerating vs 90 days ago.

Vercel
1,862 reports · 180 researchers
Surging
+83.7reports/day Δ
+0.2researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = +83.7 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = +0.2/day
5.Large positive Δ = today's intake significantly exceeds 90-day-ago rate → SURGING

⇒ Vercel is surging — current intake exceeds what it was 90 days ago.

Arc
3,097 reports · 7 researchers
Surging
+70.0reports/day Δ
0.0researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = +70.0 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = 0.0/day
5.Large positive Δ = today's intake significantly exceeds 90-day-ago rate → SURGING

⇒ Arc is surging — current intake exceeds what it was 90 days ago.

MongoDB
1,333 reports · 289 researchers
Surging
+37.5reports/day Δ
+0.6researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = +37.5 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = +0.6/day
5.Large positive Δ = today's intake significantly exceeds 90-day-ago rate → SURGING

⇒ MongoDB is surging — current intake exceeds what it was 90 days ago.

Vercel Open Source
4,948 reports · 888 researchers
Cooling off
-36.3reports/day Δ
+1.3researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = -36.3 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = +1.3/day
5.Negative Δ = intake declining vs 90 days ago

⇒ Vercel Open Source is cooling off — intake has fallen below the 90-day-ago rate.

Agoda Public
559 reports · 5 researchers
Cooling off
-35.7reports/day Δ
0.0researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = -35.7 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = 0.0/day
5.Negative Δ = intake declining vs 90 days ago

⇒ Agoda Public is cooling off — intake has fallen below the 90-day-ago rate.

Live Nation
909 reports · 91 researchers
Surging
+33.8reports/day Δ
+1.5researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = +33.8 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = +1.5/day
5.Large positive Δ = today's intake significantly exceeds 90-day-ago rate → SURGING

⇒ Live Nation is surging — current intake exceeds what it was 90 days ago.

Anthropic
5,742 reports · 543 researchers
Surging
+25.3reports/day Δ
+1.8researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = +25.3 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = +1.8/day
5.Large positive Δ = today's intake significantly exceeds 90-day-ago rate → SURGING

⇒ Anthropic is surging — current intake exceeds what it was 90 days ago.

WordPress
1,912 reports · 617 researchers
Surging
+22.4reports/day Δ
+3.7researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = +22.4 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = +3.7/day
5.Large positive Δ = today's intake significantly exceeds 90-day-ago rate → SURGING

⇒ WordPress is surging — current intake exceeds what it was 90 days ago.

TikTok
1,358 reports · 694 researchers
Cooling off
-21.3reports/day Δ
+1.3researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = -21.3 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = +1.3/day
5.Negative Δ = intake declining vs 90 days ago

⇒ TikTok is cooling off — intake has fallen below the 90-day-ago rate.

Crypto.com
1,575 reports · 613 researchers
Surging
+19.4reports/day Δ
0.0researchers/day
1.reports_received_90d is a rolling window: at any instant = reports in last 90 days
2.Δ(R90) / Δt = r(now) − r(90 days ago) → this is the rate difference, not absolute intake
3.Measured Δ = +19.4 reports/day between snapshots
4.participants_count (monotonic lifetime): growth = 0.0/day
5.Large positive Δ = today's intake significantly exceeds 90-day-ago rate → SURGING

⇒ Crypto.com is surging — current intake exceeds what it was 90 days ago.

Resolution velocity

26 programs

Net flow = intake rate change minus resolution rate.

S-Pankki
137 lifetime resolved · 20 in window
Clearing backlog
7.8resolved/day
-7.4net flow/day
1.resolved_report_count = 137 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 7.8 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = -7.4/day

⇒ Resolving faster than new intake is growing → clearing backlog.

Adobe
8,973 lifetime resolved · 904 in window
Clearing backlog
6.1resolved/day
-16.7net flow/day
1.resolved_report_count = 8,973 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 6.1 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = -16.7/day

⇒ Resolving faster than new intake is growing → clearing backlog.

Vodafone
894 lifetime resolved · 289 in window
Steady
2.4resolved/day
-1.1net flow/day
1.resolved_report_count = 894 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 2.4 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = -1.1/day

⇒ Resolving faster than new intake is growing → clearing backlog.

Stripe
620 lifetime resolved · 716 in window
Falling behind
2.1resolved/day
+7.0net flow/day
1.resolved_report_count = 620 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 2.1 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = +7.0/day

⇒ Intake growing faster than resolution → falling behind.

Brave Software
543 lifetime resolved · 279 in window
Falling behind
1.9resolved/day
+3.5net flow/day
1.resolved_report_count = 543 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 1.9 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = +3.5/day

⇒ Intake growing faster than resolution → falling behind.

Sony
3,852 lifetime resolved · 261 in window
Steady
1.9resolved/day
-0.5net flow/day
1.resolved_report_count = 3,852 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 1.9 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = -0.5/day

⇒ Resolution roughly matches intake changes → steady state.

Figma
287 lifetime resolved · 401 in window
Falling behind
1.8resolved/day
+3.2net flow/day
1.resolved_report_count = 287 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 1.8 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = +3.2/day

⇒ Intake growing faster than resolution → falling behind.

Epic Games
2,575 lifetime resolved · 948 in window
Falling behind
1.4resolved/day
+6.0net flow/day
1.resolved_report_count = 2,575 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 1.4 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = +6.0/day

⇒ Intake growing faster than resolution → falling behind.

Roblox
939 lifetime resolved · 314 in window
Clearing backlog
1.1resolved/day
-5.8net flow/day
1.resolved_report_count = 939 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 1.1 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = -5.8/day

⇒ Resolving faster than new intake is growing → clearing backlog.

Valve
1,514 lifetime resolved · 372 in window
Falling behind
1.1resolved/day
+2.1net flow/day
1.resolved_report_count = 1,514 (monotonic lifetime counter → delta IS true rate)
2.Resolution rate = Δ(resolved) / Δt = 1.1 reports/day
3.Intake rate change = Δ(reports_received_90d) / Δt (rolling window derivative)
4.Net flow = intake_Δ − resolution_rate = +2.1/day

⇒ Intake growing faster than resolution → falling behind.

SLA accuracy (deduced)

51 programs

Inferred from the gap between first observation and first researcher thanked, vs declared SLA.

Anthropic
SLA: 3d first response · 97% eff. · 549 thanked
Missed
191hdeduced triage
5,683est. backlog
1.Declared SLA threshold_new = 3 days (72h)
2.response_efficiency_pct = 97% (platform-reported SLA compliance)
3.549 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 191h actual triage time
6.Declared SLA = 72h vs deduced = 191h → EXCEEDS SLA by 119h

⇒ Actual triage appears to exceed the declared SLA threshold.

Elastic
SLA: 1d first response · 80% eff. · 909 thanked
Missed
161hdeduced triage
3,256est. backlog
1.Declared SLA threshold_new = 1 days (24h)
2.response_efficiency_pct = 80% (platform-reported SLA compliance)
3.909 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 161h actual triage time
6.Declared SLA = 24h vs deduced = 161h → EXCEEDS SLA by 137h

⇒ Actual triage appears to exceed the declared SLA threshold.

Crypto.com
SLA: 3d first response · 100% eff. · 660 thanked
Missed
162hdeduced triage
1,567est. backlog
1.Declared SLA threshold_new = 3 days (72h)
2.response_efficiency_pct = 100% (platform-reported SLA compliance)
3.660 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 162h actual triage time
6.Declared SLA = 72h vs deduced = 162h → EXCEEDS SLA by 90h

⇒ Actual triage appears to exceed the declared SLA threshold.

Chia Network
SLA: 5d first response · 100% eff. · 105 thanked
Stretched
192hdeduced triage
1,468est. backlog
1.Declared SLA threshold_new = 5 days (120h)
2.response_efficiency_pct = 100% (platform-reported SLA compliance)
3.105 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 192h actual triage time
6.Declared SLA = 120h vs deduced = 192h → EXCEEDS SLA by 72h

⇒ SLA compliance is under pressure based on available data points.

TikTok
SLA: 1d first response · 82% eff. · 733 thanked
Missed
178hdeduced triage
1,350est. backlog
1.Declared SLA threshold_new = 1 days (24h)
2.response_efficiency_pct = 82% (platform-reported SLA compliance)
3.733 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 178h actual triage time
6.Declared SLA = 24h vs deduced = 178h → EXCEEDS SLA by 154h

⇒ Actual triage appears to exceed the declared SLA threshold.

Banco Plata
SLA: 1d first response · 99% eff. · 18 thanked
Missed
194hdeduced triage
1,102est. backlog
1.Declared SLA threshold_new = 1 days (24h)
2.response_efficiency_pct = 99% (platform-reported SLA compliance)
3.18 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 194h actual triage time
6.Declared SLA = 24h vs deduced = 194h → EXCEEDS SLA by 170h

⇒ Actual triage appears to exceed the declared SLA threshold.

TRON DAO
SLA: 5d first response · 93% eff. · 20 thanked
Stretched
189hdeduced triage
1,060est. backlog
1.Declared SLA threshold_new = 5 days (120h)
2.response_efficiency_pct = 93% (platform-reported SLA compliance)
3.20 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 189h actual triage time
6.Declared SLA = 120h vs deduced = 189h → EXCEEDS SLA by 69h

⇒ SLA compliance is under pressure based on available data points.

Neon
SLA: 1d first response · 86% eff. · 151 thanked
Missed
193hdeduced triage
1,054est. backlog
1.Declared SLA threshold_new = 1 days (24h)
2.response_efficiency_pct = 86% (platform-reported SLA compliance)
3.151 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 193h actual triage time
6.Declared SLA = 24h vs deduced = 193h → EXCEEDS SLA by 169h

⇒ Actual triage appears to exceed the declared SLA threshold.

Superhuman (formerly Grammarly)
SLA: 1d first response · 95% eff. · 500 thanked
Missed
159hdeduced triage
939est. backlog
1.Declared SLA threshold_new = 1 days (24h)
2.response_efficiency_pct = 95% (platform-reported SLA compliance)
3.500 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 159h actual triage time
6.Declared SLA = 24h vs deduced = 159h → EXCEEDS SLA by 135h

⇒ Actual triage appears to exceed the declared SLA threshold.

Epic Games
SLA: 1d first response · 74% eff. · 1,139 thanked
Missed
160hdeduced triage
902est. backlog
1.Declared SLA threshold_new = 1 days (24h)
2.response_efficiency_pct = 74% (platform-reported SLA compliance)
3.1,139 researchers thanked → cross-ref their total reports to this program
4.Generously assuming all thanked-researcher reports were triaged: upper bound on triage count
5.Observed first-thank timestamp vs first-metrics-snapshot = 160h actual triage time
6.Declared SLA = 24h vs deduced = 160h → EXCEEDS SLA by 136h

⇒ Actual triage appears to exceed the declared SLA threshold.

Payout fairness

31 programs ±30%+ from peers

Critical payout vs median for same-industry programs.

Shopify
Computer Software · 65 peers · 41 critical reports
+2,305%
$104,688pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.Shopify avg_bounty_critical = $104,688 from 41 critical reports
4.Deviation = ($104,688 − $4,353) / $4,353 = +2,305%

⇒ Pays 2,305% above industry peers — above-average payout.

GitHub
Computer Software · 65 peers · 96 critical reports
+2,197%
$100,000pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.GitHub avg_bounty_critical = $100,000 from 96 critical reports
4.Deviation = ($100,000 − $4,353) / $4,353 = +2,197%

⇒ Pays 2,197% above industry peers — above-average payout.

Cosmos
Computer Software · 65 peers · 21 critical reports
+1,049%
$50,000pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.Cosmos avg_bounty_critical = $50,000 from 21 critical reports
4.Deviation = ($50,000 − $4,353) / $4,353 = +1,049%

⇒ Pays 1,049% above industry peers — above-average payout.

Vercel Sandbox
Computer Software · 65 peers · 0 critical reports
+1,049%
$50,000pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.Vercel Sandbox avg_bounty_critical = $50,000 from 0 critical reports
4.Deviation = ($50,000 − $4,353) / $4,353 = +1,049%

⇒ Pays 1,049% above industry peers — above-average payout.

Coinbase
Financial Services & Insurance · 12 peers · 22 critical reports
+816%
$100,000pays
$10,917industry median
1.Industry: Financial Services & Insurance → 12 programs with critical payout data
2.Industry median critical payout = $10,917 (sorted middle value)
3.Coinbase avg_bounty_critical = $100,000 from 22 critical reports
4.Deviation = ($100,000 − $10,917) / $10,917 = +816%

⇒ Pays 816% above industry peers — above-average payout.

Epic Games
Computer Software · 65 peers · 186 critical reports
+481%
$25,286pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.Epic Games avg_bounty_critical = $25,286 from 186 critical reports
4.Deviation = ($25,286 − $4,353) / $4,353 = +481%

⇒ Pays 481% above industry peers — above-average payout.

PayPal
Computer Software · 65 peers · 160 critical reports
+463%
$24,500pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.PayPal avg_bounty_critical = $24,500 from 160 critical reports
4.Deviation = ($24,500 − $4,353) / $4,353 = +463%

⇒ Pays 463% above industry peers — above-average payout.

GitLab
Computer Software · 65 peers · 113 critical reports
+413%
$22,312pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.GitLab avg_bounty_critical = $22,312 from 113 critical reports
4.Deviation = ($22,312 − $4,353) / $4,353 = +413%

⇒ Pays 413% above industry peers — above-average payout.

Snapchat
Computer Software · 65 peers · 27 critical reports
+398%
$21,667pays
$4,353industry median
1.Industry: Computer Software → 65 programs with critical payout data
2.Industry median critical payout = $4,353 (sorted middle value)
3.Snapchat avg_bounty_critical = $21,667 from 27 critical reports
4.Deviation = ($21,667 − $4,353) / $4,353 = +398%

⇒ Pays 398% above industry peers — above-average payout.

CoinSpot
Financial Services & Insurance · 12 peers · 4 critical reports
+358%
$50,000pays
$10,917industry median
1.Industry: Financial Services & Insurance → 12 programs with critical payout data
2.Industry median critical payout = $10,917 (sorted middle value)
3.CoinSpot avg_bounty_critical = $50,000 from 4 critical reports
4.Deviation = ($50,000 − $10,917) / $10,917 = +358%

⇒ Pays 358% above industry peers — above-average payout.

Ghost programs

21 programs

Taking reports but not resolving them.

Wolt
Hackerone · Never resolved
Ghost
1,426reports in
0ever resolved
1.reports_received_90d = 1,426 → program IS taking reports
2.resolved_report_count = 0 (lifetime)
3.last_report_resolved_at = NEVER

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

d-you App & German EUDI Wallet Ecosystem
Hackerone · Never resolved
Ghost
722reports in
0ever resolved
1.reports_received_90d = 722 → program IS taking reports
2.resolved_report_count = 0 (lifetime)
3.last_report_resolved_at = NEVER

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

Agoda Public
Hackerone · Never resolved
Ghost
559reports in
0ever resolved
1.reports_received_90d = 559 → program IS taking reports
2.resolved_report_count = 0 (lifetime)
3.last_report_resolved_at = NEVER

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

Omarchy
Hackerone · Never resolved
Ghost
356reports in
0ever resolved
1.reports_received_90d = 356 → program IS taking reports
2.resolved_report_count = 0 (lifetime)
3.last_report_resolved_at = NEVER

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

Insightly
Hackerone · 200d since last resolve
Ghost
268reports in
158ever resolved
1.reports_received_90d = 268 → program IS taking reports
2.resolved_report_count = 158 (lifetime)
3.last_report_resolved_at = 200 days ago

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

Nebius AI Vulnerability Disclosure
Hackerone · Never resolved
Ghost
206reports in
0ever resolved
1.reports_received_90d = 206 → program IS taking reports
2.resolved_report_count = 0 (lifetime)
3.last_report_resolved_at = NEVER

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

Stripchat
Hackerone · 219d since last resolve
Ghost
195reports in
50ever resolved
1.reports_received_90d = 195 → program IS taking reports
2.resolved_report_count = 50 (lifetime)
3.last_report_resolved_at = 219 days ago

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

Verily Life Sciences
Hackerone · 102d since last resolve
Ghost
164reports in
125ever resolved
1.reports_received_90d = 164 → program IS taking reports
2.resolved_report_count = 125 (lifetime)
3.last_report_resolved_at = 102 days ago

⇒ Reports go in but nothing comes out. Researchers submitting here are likely wasting their time.

Add to the data

Every review sharpens this picture.

These numbers only mean something because they came from researchers who actually filed reports. Rate a program you've worked with, good or bad.

Write a review