Bugcrowd
Broad crowdsourced platform with a well-defined severity taxonomy and researcher-matching to private programs.
Tags: public, vrt, crowdmatch
- Program model
- Bounty · VDP · Pentest · ASM
- Regions
- Global
- Payout
- USD; rewards mapped to the VRT severity of the finding
Specialties: web, api, mobile, iot
How to approach it
The Vulnerability Rating Taxonomy (VRT) tells you upfront how a bug class is rated - learn it to predict payouts and avoid arguing severity.
What the platform publishes
Bugcrowd's disclosure docs say coordinated disclosure is the recommended default for new public programs, and nondisclosure is the default for On-Demand and Pen Test MAX. If a program brief disagrees with the standard terms, the brief wins. Full safe harbor is for programs that meet the disclose.io requirements Bugcrowd lists. A program that does not meet them is marked partial. Severity labels on Bugcrowd come from the Vulnerability Rating Taxonomy, which is a priority scale, not a CVSS score.
- Study the public VRT (bugcrowd.com/vulnerability-rating-taxonomy) before submitting - it sets expectations.
- Points and quality feed CrowdMatch, which drives private-program invites.
- Bugcrowd runs many managed enterprise programs; polished, on-scope reports get accepted fastest.