# Bug Bounty FAQ: Programs, History & Pro | bbradar.io

> Answers about bug bounty programs, program History, audit contests, Self-Hosted coverage, Pro features, alerts, API and MCP access, and billing.

Source: [https://bbradar.io/docs/faq](https://bbradar.io/docs/faq)

<a id="questions"></a>

## Questions and answers

<a id="which-bug-bounty-platforms-are-supported-on-bbradar-io"></a>

### [Which bug bounty platforms are supported on BBRadar.io?](https://bbradar.io/docs/faq.md#which-bug-bounty-platforms-are-supported-on-bbradar-io)

We aggregate programs from major platforms including [HackerOne](https://bbradar.io/platforms/hackerone)[BugCrowd](https://bbradar.io/platforms/bugcrowd)[Intigriti](https://bbradar.io/platforms/intigriti)[Immunefi](https://bbradar.io/platforms/immunefi)[HackenProof](https://bbradar.io/platforms/hackenproof)[YesWeHack](https://bbradar.io/platforms/yeswehack)[Standoff365](https://bbradar.io/platforms/standoff365)[BI.ZONE](https://bbradar.io/platforms/bi-zone)[Code4rena](https://bbradar.io/platforms/code4rena)[Sherlock](https://bbradar.io/platforms/sherlock)[CodeHawks](https://bbradar.io/platforms/codehawks)[Cantina](https://bbradar.io/platforms/cantina)[Bugbase](https://bbradar.io/platforms/bugbase)[BugRap](https://bbradar.io/platforms/bugrap)[IssueHunt](https://bbradar.io/platforms/issuehunt)[Inspectiv](https://bbradar.io/platforms/inspectiv)[Bug Bounty Switzerland](https://bbradar.io/platforms/bug-bounty-switzerland)[AuditOne](https://bbradar.io/platforms/auditone)[CertiK](https://bbradar.io/platforms/certik)[Huntr](https://bbradar.io/platforms/huntr)[Remedy](https://bbradar.io/platforms/remedy)[Compass Security](https://bbradar.io/platforms/compass-security)[GObugfree](https://bbradar.io/platforms/gobugfree)[PatchDay](https://bbradar.io/platforms/patchday)[HackZar](https://bbradar.io/platforms/hackzar) We keep expanding as new platforms emerge.

<a id="where-can-i-compare-web3-audit-contests-and-competition-deadlines"></a>

### [Where can I compare Web3 audit contests and competition deadlines?](https://bbradar.io/docs/faq.md#where-can-i-compare-web3-audit-contests-and-competition-deadlines)

Open the free [Web3 audit contest calendar](https://bbradar.io/contests) to compare smart contract competitions and security challenges by platform, language, published reward and UTC schedule. Available ICS downloads are free. Full program scope, target inventory and program intelligence require Pro. The [contest calendar guide](https://bbradar.io/docs/contests.md) explains filters, dates and exports.

<a id="why-can-a-contest-deadline-differ-from-the-platform-s-page"></a>

### [Why can a contest deadline differ from the platform’s page?](https://bbradar.io/docs/faq.md#why-can-a-contest-deadline-differ-from-the-platform-s-page)

BBRadar updates a schedule after the source data has been retrieved, checked and saved. A recently announced or changed deadline can appear on the official page first. Dates to confirm means the calendar does not yet have a complete, consistent verified schedule; it does not prove the platform has no deadline. Date-only deadlines remain labeled without an invented closing time. Check the official contest page for the latest schedule.

<a id="what-information-is-available-for-hackzar-programs"></a>

### [What information is available for HackZar programs?](https://bbradar.io/docs/faq.md#what-information-is-available-for-hackzar-programs)

HackZar coverage includes public program profiles, reward ranges or recognition-only VDP status, scope targets, and total report counts where available. Enable Include VDPs to see recognition-only programs. Pro users can inspect targets and report counts and select HackZar in Notification Rules. Catalog dates use the Created date published on each program page. When that date is unavailable, a conservative estimate is used.

<a id="what-kinds-of-programs-do-you-list"></a>

### [What kinds of programs do you list?](https://bbradar.io/docs/faq.md#what-kinds-of-programs-do-you-list)

We list public programs across many categories and technologies, including:

[web](https://bbradar.io/tags/web)[mobile](https://bbradar.io/tags/mobile)[smart contract](https://bbradar.io/tags/smart-contract)[blockchain](https://bbradar.io/tags/blockchain)[contest](https://bbradar.io/tags/contest)[API](https://bbradar.io/tags/api)[cloud](https://bbradar.io/tags/cloud)[open source](https://bbradar.io/tags/open-source)[AI/ML](https://bbradar.io/tags/ai-ml)

<a id="how-often-are-programs-updated"></a>

### [How often are programs updated?](https://bbradar.io/docs/faq.md#how-often-are-programs-updated)

We check listings throughout the day. Update times vary by platform and depend on source availability, rate limits, and successful verification. Incomplete checks preserve existing listings.

<a id="how-do-i-submit-a-bug-to-a-program"></a>

### [How do I submit a bug to a program?](https://bbradar.io/docs/faq.md#how-do-i-submit-a-bug-to-a-program)

BBRadar is a tracker, not a submission platform. Open each program and submit your report directly on the program’s platform page. We link to the official program URL for every listing.

<a id="how-can-i-find-mobile-or-web3-bug-bounty-programs"></a>

### [How can I find mobile or web3 bug bounty programs?](https://bbradar.io/docs/faq.md#how-can-i-find-mobile-or-web3-bug-bounty-programs)

Use tags and filters: try the mobile tag for mobile targets, or the smart contract tag for web3. You can also use the search bar to filter by keywords.

<a id="are-all-programs-public"></a>

### [Are all programs public?](https://bbradar.io/docs/faq.md#are-all-programs-public)

BBRadar.io focuses on publicly available programs. Private or invite‑only programs are not listed.

<a id="can-i-sort-programs-by-rewards-or-alphabetically"></a>

### [Can I sort programs by rewards or alphabetically?](https://bbradar.io/docs/faq.md#can-i-sort-programs-by-rewards-or-alphabetically)

Yes. Use the “Sort by” control above the listings to sort by date (newest/oldest), name (A–Z/Z–A), and by maximum or minimum bounty. Pro users can also sort by report count or submission cost. Programs without a detected submission cost are currently treated as free.

<a id="can-i-see-whether-a-program-charges-to-submit-a-report"></a>

### [Can I see whether a program charges to submit a report?](https://bbradar.io/docs/faq.md#can-i-see-whether-a-program-charges-to-submit-a-report)

Yes, with Pro. When a platform publishes this data, bbradar shows the program’s submission fee or deposit in program listings, program details, Latest Targets, and Pro API responses. The Free submission fee only toggle works together with the other listing and Latest Targets filters. Money is displayed with a $ prefix, while non-cash systems such as YesWeHack are shown in credits. If no submission cost is detected, the program is currently shown as Free. Only positive costs are added to program, lifecycle, and target-change notifications.

<a id="how-fresh-are-the-latest-programs"></a>

### [How fresh are the “Latest” programs?](https://bbradar.io/docs/faq.md#how-fresh-are-the-latest-programs)

We check sources throughout the day. A program appears after its source data has been retrieved, validated, and saved. Source outages, rate limits, and verification can delay publication.

<a id="what-does-a-paused-program-mean"></a>

### [What does a Paused program mean?](https://bbradar.io/docs/faq.md#what-does-a-paused-program-mean)

The platform has confirmed that the program is paused. Its listing remains available for reference, with previously published rewards and scope. Current bounty eligibility and active opportunity signals are disabled while paused. Check the official policy before choosing work; retained targets do not establish current permission to test.

<a id="how-are-self-hosted-programs-handled"></a>

### [How are Self-Hosted programs handled?](https://bbradar.io/docs/faq.md#how-are-self-hosted-programs-handled)

The Self-Hosted Pro catalog makes security programs run directly by organizations easy to find alongside the main platform catalog. It brings each program’s rewards, scope, policy, and reporting route into one profile, shows paid bounties first, and lets you include VDPs when you want broader disclosure coverage. The History tab beside Targets shows accepted structured profile and scope changes recorded after tracking begins. Historical details do not expose fetched policy bodies, evidence snippets or reporting contacts. Always review the linked official policy before testing.

<a id="what-can-i-see-in-latest-targets-and-commits"></a>

### [What can I see in Latest Targets and Commits?](https://bbradar.io/docs/faq.md#what-can-i-see-in-latest-targets-and-commits)

Latest Targets helps you follow confirmed scope additions, re-additions, updates, and removals. The Commits tab shows supported repository branch updates connected to bounty targets. Use these feeds to spot activity, then open the linked official scope or repository provider before acting.

<a id="where-can-i-review-a-program-s-change-history"></a>

### [Where can I review a program’s change history?](https://bbradar.io/docs/faq.md#where-can-i-review-a-program-s-change-history)

Open a platform or Self-Hosted program and select **History** beside **Targets**. Pro users can filter recorded changes by date range and category, then expand an event to compare before and after values. Visitors without Pro see a compact feature preview on public platform program pages; Self-Hosted details require Pro. Program History is available within each program’s details. The [Program History guide](https://bbradar.io/docs/pro/program-history.md) explains coverage, detection times and access.

<a id="does-history-include-changes-from-before-tracking-began"></a>

### [Does History include changes from before tracking began?](https://bbradar.io/docs/faq.md#does-history-include-changes-from-before-tracking-began)

No. History starts with new accepted observations. The first observation of a program or newly supported field creates a silent starting point; later confirmed differences can appear. Earlier events are not imported or reconstructed. Times are shown in UTC and describe BBRadar’s observations, not the exact time a source published an edit. Checks can miss intermediate changes.

<a id="which-policy-and-repository-changes-appear-in-history"></a>

### [Which policy and repository changes appear in History?](https://bbradar.io/docs/faq.md#which-policy-and-repository-changes-appear-in-history)

Coverage varies by provider and field. Immunefi includes verified policy sections, impacts, rewards and rule attributes; HackerOne includes supported reward-grid and target-instruction changes. Other platforms contribute known catalog and scope data. Inspectiv and Bug Bounty Switzerland catalog and scope changes are currently withheld while source-record public visibility remains unverified; independently verified public repository updates can still appear. Repository history stores supported reference and SHA changes, comparison quality and a commit count when known; it does not store source code, patches, commit messages or changed file paths.

<a id="why-might-a-program-s-history-tab-be-empty"></a>

### [Why might a program’s History tab be empty?](https://bbradar.io/docs/faq.md#why-might-a-program-s-history-tab-be-empty)

Broaden the date range and choose All events. Tracking may have only established its first starting point, no later changes may have been confirmed, or the source may not support the fields you expect. A tracking-unavailable notice means capture is not currently available, rather than proving there were no changes. Incomplete checks preserve known information instead of inventing removals. A quiet timeline does not prove the official source stayed unchanged.

<a id="does-every-history-event-trigger-a-notification"></a>

### [Does every History event trigger a notification?](https://bbradar.io/docs/faq.md#does-every-history-event-trigger-a-notification)

No. History and notifications serve different purposes. Existing notification streams and your saved rules determine which alerts are delivered. Opening a program’s History tab does not subscribe you to policy or reward alerts or create new alert streams.

<a id="what-are-opportunity-tiers-target-scores-and-dupe-risk"></a>

### [What are opportunity tiers, target scores, and dupe risk?](https://bbradar.io/docs/faq.md#what-are-opportunity-tiers-target-scores-and-dupe-risk)

They are Pro research signals that help you compare programs and targets. Program opportunity tiers highlight promising listings, while each target can include a score, label, factor breakdown, and dupe-risk context. Use them to prioritize research, not as a guarantee of payout, exploitability, or a duplicate-free report.

<a id="what-does-pro-include"></a>

### [What does Pro include?](https://bbradar.io/docs/faq.md#what-does-pro-include)

Pro includes:

- Program notifications.
- A separate verified Self-Hosted paid-program and VDP catalog with reward ranges, reporting routes, tags, and structured scope.
- Separate Telegram streams for new Self-Hosted bounties and VDPs.
- Target change notifications.
- Repository-change alerts for supported GitHub and Gists, GitLab, Bitbucket, Gitea, Forgejo, SourceHut, and HTTPS Git hosts, with direct provider links.
- Private Telegram DM delivery for personal alerts.
- Program opportunity tiers plus target scores, labels, factor breakdowns, and dupe-risk context.
- Platform-reported submission fees or deposits in listings, program details, Latest Targets, API responses, and positive-cost alerts, plus cost sorting.
- Notification rules for streams, opportunity signals, platforms, scope tags, languages, rewards, programs, and targets.
- Opportunity filters for Elite, Hot, Strong, and Potential programs.
- Upcoming program visibility for future-dated launches.
- Full program targets with eligibility details.
- [Program History](https://bbradar.io/docs/pro/program-history.md) beside Targets, with before and after details for supported scope, reward, policy and repository changes.
- Pro API access with API key generation, regeneration, and revoke controls.
- Local MCP server access through the `@bbradar/mcp` npm package.

[See Pro plans](https://bbradar.io/pro.md)

<a id="how-do-repository-change-alerts-work"></a>

### [How do repository change alerts work?](https://bbradar.io/docs/faq.md#how-do-repository-change-alerts-work)

When a bounty target links to a supported repository and branch, later updates can appear in the Commits feed.

- The first observation establishes a starting point and does not create an alert.
- Later branch changes can appear under the [Commits tab](https://bbradar.io/latest-targets).
- Discord and opted-in Telegram notifications are grouped into hourly digests.
- Digest entries open the source provider's comparison, commit, or repository view.
- A confirmed scope match has supporting evidence. An unverified scope impact means the repository changed but the available comparison could not establish whether the scoped files changed.
- Historical events without recorded evidence quality are labelled as unknown.
- bbradar does not retain code, patches, filenames, or commit messages.

<a id="does-bbradar-pro-include-an-mcp-server"></a>

### [Does bbradar Pro include an MCP server?](https://bbradar.io/docs/faq.md#does-bbradar-pro-include-an-mcp-server)

Yes. Pro users can run the [@bbradar/mcp npm package](https://www.npmjs.com/package/@bbradar/mcp) as a local STDIO MCP server for compatible AI clients.

- Requires Node.js 20 or newer and a bbradar Pro API key.
- Most clients can run it with `npx -y @bbradar/mcp`.
- Add your key as `BBRADAR_API_KEY` in the MCP client environment.

<a id="is-every-pro-feature-available-through-the-api-or-mcp-server"></a>

### [Is every Pro feature available through the API or MCP server?](https://bbradar.io/docs/faq.md#is-every-pro-feature-available-through-the-api-or-mcp-server)

No. The Pro API covers platform and Self-Hosted program profiles, active target inventories, platform opportunity data, target intelligence, platform target changes, and minimal platform repository-change events. Self-Hosted responses explicitly mark unavailable signals instead of inventing opportunity scores, report counts, target-change feeds, submission costs, or repository changes. Repository events are available through the website, read-only Pro API, and supported notifications; MCP 0.2.3 also exposes get_repository_changes with compact program summaries and incremental polling. Snapshot parameters and some newer provenance fields remain HTTP API capabilities. The per-program History timeline currently requires a signed-in Pro browser session and is not included in API key endpoints or MCP tools.

<a id="where-do-i-manage-my-pro-api-key-and-endpoints"></a>

### [Where do I manage my Pro API key and endpoints?](https://bbradar.io/docs/faq.md#where-do-i-manage-my-pro-api-key-and-endpoints)

Go to [Account & Billing](https://bbradar.io/account) to create, regenerate, or delete your API key. Then open [Pro API reference](https://bbradar.io/docs/api.md) for endpoint details and cURL examples.

<a id="can-i-customize-which-pro-notifications-i-receive"></a>

### [Can I customize which Pro notifications I receive?](https://bbradar.io/docs/faq.md#can-i-customize-which-pro-notifications-i-receive)

Yes. Pro users can manage [notification rules](https://bbradar.io/account/notifications) for platform program, Self-Hosted paid/VDP, target, and repository-change streams plus program opportunity tiers, target scores and labels, dupe risk, platforms, scope tags, languages, bounty ranges, free or paid submission fees with an optional maximum, target changes, and specific programs or targets.

<a id="where-do-pro-notifications-appear"></a>

### [Where do Pro notifications appear?](https://bbradar.io/docs/faq.md#where-do-pro-notifications-appear)

Notifications can be delivered to your private Telegram DM and the Pro Discord channels after you connect your account. You can also browse [Latest Targets and Commits](https://bbradar.io/latest-targets) on the site.

<a id="how-do-i-enable-pro-notifications"></a>

### [How do I enable Pro notifications?](https://bbradar.io/docs/faq.md#how-do-i-enable-pro-notifications)

Subscribe to Pro, then use [Account & Billing](https://bbradar.io/account) to connect Telegram for private DM alerts and connect Discord for server channel access. Then open [Notification Rules](https://bbradar.io/account/notifications) to choose which alerts you want.

<a id="can-telegram-alerts-be-sent-to-groups-or-shared-channels"></a>

### [Can Telegram alerts be sent to groups or shared channels?](https://bbradar.io/docs/faq.md#can-telegram-alerts-be-sent-to-groups-or-shared-channels)

No. Telegram delivery is limited to private 1:1 DMs connected from the Pro user account, so alerts stay personal and tied to active Pro access.

<a id="how-do-pro-billing-and-cancellation-work"></a>

### [How do Pro billing and cancellation work?](https://bbradar.io/docs/faq.md#how-do-pro-billing-and-cancellation-work)

Monthly and yearly Pro plans include the same current features. Stripe handles checkout, invoices, payment methods, and cancellation. If you cancel, Pro normally remains available until the end of the period you already paid for; use Account & Billing to manage the subscription and confirm its current status.

<a id="how-can-i-get-private-account-or-billing-support"></a>

### [How can I get private account or billing support?](https://bbradar.io/docs/faq.md#how-can-i-get-private-account-or-billing-support)

Email [info@bbradar.io](mailto:info@bbradar.io) for private account or billing questions. Include the page URL, approximate time, and visible status. Keep credentials, connection links, payment details, and session cookies out of the message. The [troubleshooting guide](https://bbradar.io/docs/troubleshooting.md#contact) lists useful support context.

<a id="how-do-i-request-a-platform-or-program-to-be-added"></a>

### [How do I request a platform or program to be added?](https://bbradar.io/docs/faq.md#how-do-i-request-a-platform-or-program-to-be-added)

Use the “Get Listed” page to contact us. We welcome requests from platforms and maintainers of public programs.

<a id="is-bbradar-io-affiliated-with-any-platform"></a>

### [Is BBRadar.io affiliated with any platform?](https://bbradar.io/docs/faq.md#is-bbradar-io-affiliated-with-any-platform)

No. We are an independent aggregator. Each program remains owned and managed by its respective platform or organization.
