Skip to content

A structured collection of public bug bounty and vulnerability disclosure programs across multiple platforms worldwide.

Notifications You must be signed in to change notification settings

SecAnalysts/Bug-Bounty-Programs

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

6 Commits
Β 
Β 
Β 
Β 

Repository files navigation

🎯 Bug Bounty Programs Collection

A structured collection of public bug bounty and vulnerability disclosure programs
across multiple platforms worldwide.

This repository is designed to help security researchers quickly navigate, discover, and track bug bounty programs from different providers in one centralized place.


πŸ“Œ Overview

The Bug Bounty Programs Collection repository aggregates various platforms that host:

  • 🐞 Bug Bounty Programs
  • πŸ” Vulnerability Disclosure Programs (VDP)
  • πŸ’° Responsible Disclosure Initiatives
  • 🏒 Private & Public Security Programs

This project helps researchers:

  • Discover new programs faster
  • Organize reconnaissance targets
  • Compare platforms
  • Track opportunities across ecosystems

🌍 Supported Platforms

Below are major bug bounty and security disclosure platforms included in this repository:

🐞 Global Bug Bounty Platforms

  • Bugcrowd
  • HackerOne
  • Intigriti
  • YesWeHack
  • Synack
  • Cobalt
  • Open Bug Bounty
  • HackenProof
  • Federacy
  • Detectify Crowdsource

πŸ› Tech Company Programs

  • Google VRP
  • Microsoft MSRC
  • Apple Security Bounty
  • Meta (Facebook) Bug Bounty
  • GitHub Security Lab
  • Shopify Bug Bounty
  • PayPal Bug Bounty
  • Netflix Bug Bounty
  • Uber Bug Bounty
  • Airbnb Bug Bounty

🏦 Financial & Crypto Platforms

  • Binance Bug Bounty
  • Coinbase Bug Bounty
  • Kraken Security Program
  • Crypto.com Bug Bounty
  • Tether Security Program
  • Blockchain.com Security
  • Polygon Bug Bounty
  • Ethereum Foundation
  • Solana Security Program

πŸ› Government & Public Sector

  • US Department of Defense (Hack The Pentagon)
  • UK Government Vulnerability Disclosure
  • Singapore GovTech
  • European Union Bug Bounty
  • Various National CERT Programs

🌐 Independent & Corporate VDPs

  • Company-hosted Responsible Disclosure pages
  • ISO 29147-compliant VDPs
  • Security.txt-based disclosures
  • Self-hosted bounty portals

πŸ“‚ Repository Structure

Example structure:

Bug-Bounty-Programs/
β”‚
β”œβ”€β”€ bugcrowd/
β”œβ”€β”€ hackerone/
β”œβ”€β”€ intigriti/
β”œβ”€β”€ yeswehack/
β”œβ”€β”€ synack/
β”œβ”€β”€ crypto/
β”œβ”€β”€ tech-companies/
β”œβ”€β”€ government/
└── README.md

Each folder may contain:

  • Program lists
  • Engagement details
  • Scope references
  • Research notes
  • Automation scripts (if applicable)

πŸš€ Purpose

This repository aims to:

  • Centralize bug bounty intelligence
  • Assist reconnaissance planning
  • Improve researcher workflow
  • Provide structured navigation across platforms

It is intended for:

  • Ethical hackers
  • Bug bounty hunters
  • Security researchers
  • Pentesters
  • Red teamers

⚠️ Usage Notice

  • Always read and follow each program’s rules.
  • Only test targets that are explicitly marked as in-scope.
  • Respect platform Terms of Service.
  • Unauthorized testing is illegal.

πŸ›‘ Disclaimer

This repository is for educational and authorized security research purposes only.

The author does not encourage or support illegal activities.
Users are responsible for ensuring compliance with all applicable laws and program policies.


πŸ‘€ Author

SecAnalysts
Security Research & Automation


β˜• Support / Donation

If this repository helps your research, you may support my work:

BTC Address:

1sAXERLyPhg4Fg4rkhuRQfm9eek2NJo6V

Your contribution supports continued development and my child’s education. πŸ™

About

A structured collection of public bug bounty and vulnerability disclosure programs across multiple platforms worldwide.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages