Browse documentation
Use the verified Self-Hosted catalog
Find bug bounty programs run directly by organizations, compare rewards and scope, and get alerts when new programs are added.
5 min read
Open the Self-Hosted catalog
Self-Hosted Programs is a separate Pro catalog for security programs operated directly by organizations. Use it to browse paid bug bounties, include VDPs when useful, and open each program’s official policy and reporting route.
Browse and filter programs
- 1
Open the Self-Hosted catalog
Go to Self-Hosted Programs while signed in with Pro. - 2
Start with the paid list
The default view shows paid bug bounties, with the newest additions first. - 3
Include VDPs when needed
Turn on Include VDPs to add verified no-monetary-reward disclosure policies. - 4
Search and filter
Search names, domains, and structured targets, or filter by program type, scope tags, reward types, scope features such as wildcard coverage, and target type. - 5
Choose another view or sort
Switch between list and grid, or sort by newest or oldest discovery, name, or maximum bounty from high to low or low to high.
Read a program profile
A detail page brings the official policy, reporting route, reward range, and structured targets together. Use the policy and reporting buttons to verify current rules before testing or submitting a report.
- Profile field
- Paid or VDP
- Meaning
- Paid means the official program information advertises a monetary reward. VDP means no monetary reward was confirmed.
- Profile field
- Safe harbor
- Meaning
- Full, partial, stated, or not stated according to the official policy wording.
- Profile field
- Program Targets
- Meaning
- Available in-scope and out-of-scope entries. An empty section does not mean the policy has no scope.
| Profile field | Meaning |
|---|---|
| Paid or VDP | Paid means the official program information advertises a monetary reward. VDP means no monetary reward was confirmed. |
| Safe harbor | Full, partial, stated, or not stated according to the official policy wording. |
| Program Targets | Available in-scope and out-of-scope entries. An empty section does not mean the policy has no scope. |
Configure Self-Hosted alerts
Notification Rules have separate streams for newly verified paid programs and newly verified VDPs. Paid Self-Hosted alerts start enabled; VDP alerts start disabled so no-reward policies do not add noise unless you opt in.
- 1
Connect Telegram
Use a private Telegram chat for rules personalized to your account. - 2
Open Notification Rules
Enable Self-Hosted bounties, Self-Hosted VDPs, or both. - 3
Set filtered mode if needed
Select Self-Hosted in Platforms and add compatible program-level filters such as reward bounds or program includes and excludes. - 4
Save the rule
Wait for the saved confirmation before leaving the page.
Self-Hosted entries do not currently have the platform catalog’s opportunity tiers, submission-cost signals, target-change history, or repository-change stream. Filters that require one of those unavailable signals do not make the signal appear.
Build Self-Hosted alert rulesChoose paid or VDP streams and review matching behavior.Data boundaries and limitations
- Reward information can be incomplete when the official policy does not publish exact amounts
- An empty target inventory does not mean every asset is allowed
- Policies, scope, rewards, and reporting routes can change
- Self-Hosted catalog data is currently available in the Pro browser experience and notifications, not the Pro API or MCP package
If anything in a profile conflicts with the official policy, stop and follow the official policy. Use the profile links to review the current rules directly.
