Security research platform · disclosure
Open Bug Bounty
Free, non-profit coordinated-disclosure platform for a narrow set of externally verifiable issues (XSS, etc.) on any website.
Overview
Research on Open Bug Bounty
Follows ISO 29147 coordinated disclosure. Only submit issues you can prove non-intrusively; there is no authorization to test beyond that.
- Program type
- Coordinated disclosure (non-profit)
- Regions
- Global
- Payout
- None guaranteed - optional, researcher-and-owner negotiated rewards
Field notes
Practical guidance
- Good for building a public disclosure record, not for income.
- Stay strictly within the non-intrusive rules - this is not open pentest authorization.
Primary source
Official links
Version history: normalized permanent page created 2026-08-20. Verify current platform terms before testing.