Browse documentation
    bbradar Pro guide

    Use the verified Self-Hosted catalog

    Find bug bounty programs run directly by organizations, compare rewards and scope, and get alerts when new programs are added.

    5 min read

    Open the Self-Hosted catalog

    Self-Hosted Programs is a separate Pro catalog for security programs operated directly by organizations. Use it to browse paid bug bounties, include VDPs when useful, and open each program’s official policy and reporting route.

    Browse and filter programs

    1. 1

      Open the Self-Hosted catalog

      Go to Self-Hosted Programs while signed in with Pro.
    2. 2

      Start with the paid list

      The default view shows paid bug bounties, with the newest additions first.
    3. 3

      Include VDPs when needed

      Turn on Include VDPs to add verified no-monetary-reward disclosure policies.
    4. 4

      Search and filter

      Search names, domains, and structured targets, or filter by program type, scope tags, reward types, scope features such as wildcard coverage, and target type.
    5. 5

      Choose another view or sort

      Switch between list and grid, or sort by newest or oldest discovery, name, or maximum bounty from high to low or low to high.
    Open the Self-Hosted catalogBrowse verified paid programs and optional VDPs.

    Read a program profile

    A detail page brings the official policy, reporting route, reward range, and structured targets together. Use the policy and reporting buttons to verify current rules before testing or submitting a report.

    Profile field
    Paid or VDP
    Meaning
    Paid means the official program information advertises a monetary reward. VDP means no monetary reward was confirmed.
    Profile field
    Safe harbor
    Meaning
    Full, partial, stated, or not stated according to the official policy wording.
    Profile field
    Program Targets
    Meaning
    Available in-scope and out-of-scope entries. An empty section does not mean the policy has no scope.

    Configure Self-Hosted alerts

    Notification Rules have separate streams for newly verified paid programs and newly verified VDPs. Paid Self-Hosted alerts start enabled; VDP alerts start disabled so no-reward policies do not add noise unless you opt in.

    1. 1

      Connect Telegram

      Use a private Telegram chat for rules personalized to your account.
    2. 2

      Open Notification Rules

      Enable Self-Hosted bounties, Self-Hosted VDPs, or both.
    3. 3

      Set filtered mode if needed

      Select Self-Hosted in Platforms and add compatible program-level filters such as reward bounds or program includes and excludes.
    4. 4

      Save the rule

      Wait for the saved confirmation before leaving the page.

    Self-Hosted entries do not currently have the platform catalog’s opportunity tiers, submission-cost signals, target-change history, or repository-change stream. Filters that require one of those unavailable signals do not make the signal appear.

    Build Self-Hosted alert rulesChoose paid or VDP streams and review matching behavior.

    Data boundaries and limitations

    • Reward information can be incomplete when the official policy does not publish exact amounts
    • An empty target inventory does not mean every asset is allowed
    • Policies, scope, rewards, and reporting routes can change
    • Self-Hosted catalog data is currently available in the Pro browser experience and notifications, not the Pro API or MCP package

    If anything in a profile conflicts with the official policy, stop and follow the official policy. Use the profile links to review the current rules directly.