# What is a Bug Bounty?

> A bug bounty is a program that rewards external security researchers for reporting qualifying vulnerabilities in an organization’s systems or products under a defined scope and rules.

- Canonical URL: https://yellowcube.eu/glossary/bug-bounty/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Programs set scope, eligible vulnerability classes, safe-harbor terms, reporting channels, triage expectations, and reward structures — typically operating through a mediation platform or a published policy. The reward is an incentive to look, not a guarantee of quality: programs must still validate, triage, and fix what arrives.

A bounty supplements rather than substitutes for assurance work. It crowdsources attention across a wide, unpredictable researcher population, which can surface defects internal testing missed — but it also produces noise, duplicates, and out-of-scope submissions that an unprepared triage function cannot absorb.

### Key points

- **Program design:** Define scope, exclusions, authorized testing boundaries, severity and reward criteria, response targets, safe-harbor language, and the internal triage and remediation path before inviting reports.
- **Triage capacity:** Expect a high proportion of duplicates, low-impact findings, and non-vulnerabilities; fund the people and process to handle the volume before funding rewards.
- **Program fit:** Combine with a vulnerability disclosure policy, internal testing, and remediation ownership — a bounty with nobody accountable for fixes collects liability, not security.
- **Important limitation:** Participation does not prove the tested scope is secure, and payment does not purchase confidentiality or researcher vetting. Researchers vary in skill and conduct, scope boundaries will be tested, and a bounty can draw adversarial attention as well as helpful reports.

### Related terms

[Coordinated vulnerability disclosure (CVD)](<https://yellowcube.eu/glossary/coordinated-vulnerability-disclosure/>) · [Penetration testing](<https://yellowcube.eu/glossary/penetration-testing/>) · [Vulnerability management](<https://yellowcube.eu/glossary/vulnerability-management/>) · [Vulnerability assessment](<https://yellowcube.eu/glossary/vulnerability-assessment/>)

### Sources

[CISA, VDP Platform Bug Bounty Fact Sheet](https://www.cisa.gov/sites/default/files/2025-05/CSSO-VDP%20Platform%20Bug%20Bounty%20Fact%20Sheet%202024.pdf) · [CISA, BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy](https://www.cisa.gov/news-events/directives/bod-20-01-develop-and-publish-vulnerability-disclosure-policy) · [NIST SP 800-216, Recommendations for Federal Vulnerability Disclosure Guidelines](https://csrc.nist.gov/pubs/sp/800/216/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

