# Use the verified Self-Hosted catalog | bbradar.io

> Find bug bounty programs run directly by organizations, compare rewards and scope, review program History, and set up new-program alerts.

Source: [https://bbradar.io/docs/pro/self-hosted](https://bbradar.io/docs/pro/self-hosted)

<a id="catalog-boundary"></a>

## [Open the Self-Hosted catalog](https://bbradar.io/docs/pro/self-hosted.md#catalog-boundary)

Self-Hosted Programs is a separate Pro catalog for security programs operated directly by organizations. Use it to browse paid bug bounties, include VDPs when useful, and open each program’s official policy and reporting route.

<a id="browse"></a>

## [Browse and filter programs](https://bbradar.io/docs/pro/self-hosted.md#browse)

1. ### Open the Self-Hosted catalog

   Go to [Self-Hosted Programs](https://bbradar.io/self-hosted) while signed in with Pro.
2. ### Start with the paid list

   The default view shows paid bug bounties, with the newest additions first.
3. ### Include VDPs when needed

   Turn on **Include VDPs** to add verified no-monetary-reward disclosure policies.
4. ### Search and filter

   Search names, domains, and structured targets, or filter by program type, scope tags, reward types, scope features such as wildcard coverage, and target type.
5. ### Choose another view or sort

   Switch between list and grid, or sort by newest or oldest discovery, name, or maximum bounty from high to low or low to high.

[Open the Self-Hosted catalogBrowse verified paid programs and optional VDPs.](https://bbradar.io/self-hosted)

<a id="profiles"></a>

## [Read a program profile](https://bbradar.io/docs/pro/self-hosted.md#profiles)

A detail page brings the official policy, reporting route, reward range, and structured targets together. Use the policy and reporting buttons to verify current rules before testing or submitting a report.

Select **History** beside **Targets** to compare accepted structured profile and scope changes recorded after tracking begins. The [Program History guide](https://bbradar.io/docs/pro/program-history.md) explains the starting point, filters and coverage.

| Profile field | Meaning |
| --- | --- |
| Paid or VDP | Paid means the official program information advertises a monetary reward. VDP means no monetary reward was confirmed. |
| Safe harbor | Full, partial, stated, or not stated according to the official policy wording. |
| Program Targets | Available in-scope and out-of-scope entries. An empty section does not mean the policy has no scope. |

Important

The organization’s current official policy is authoritative. Recheck authorization, scope, testing restrictions, and reward terms before interacting with any asset.

<a id="alerts"></a>

## [Configure Self-Hosted alerts](https://bbradar.io/docs/pro/self-hosted.md#alerts)

Notification Rules have separate streams for newly verified paid programs and newly verified VDPs. Paid Self-Hosted alerts start enabled; VDP alerts start disabled so no-reward policies do not add noise unless you opt in.

1. ### Connect Telegram

   Use a private Telegram chat for rules personalized to your account.
2. ### Open Notification Rules

   Enable **Self-Hosted bounties**, **Self-Hosted VDPs**, or both.
3. ### Set filtered mode if needed

   Select Self-Hosted in Platforms and add compatible program-level filters such as reward bounds or program includes and excludes.
4. ### Save the rule

   Wait for the saved confirmation before leaving the page.

Self-Hosted entries do not currently have the platform catalog’s opportunity tiers, submission-cost signals, target-change alert stream or repository-change stream. Browser History records accepted structured changes separately; it does not add those notification filters or alert streams.

[Build Self-Hosted alert rulesChoose paid or VDP streams and review matching behavior.](https://bbradar.io/docs/notifications/rules.md)

<a id="limitations"></a>

## [Data boundaries and limitations](https://bbradar.io/docs/pro/self-hosted.md#limitations)

- Reward information can be incomplete when the official policy does not publish exact amounts
- An empty target inventory does not mean every asset is allowed
- Policies, scope, rewards, and reporting routes can change
- The browser History tab covers accepted structured changes without exposing fetched policy bodies, evidence snippets or reporting contacts
- Self-Hosted profiles and active targets are available through the Pro API and MCP; program History, opportunity tiers, target-change feeds and repository changes are not included in those Self-Hosted responses

If anything in a profile conflicts with the official policy, stop and follow the official policy. Use the profile links to review the current rules directly.
