Submit or correct a bug bounty listing

Suggest a public bug bounty program, a platform, or a security event. You can also report outdated rewards, scope, reporting links, or program status on an existing listing.

What to send

  • The organization or platform name and its official website.
  • A first-party program policy with scope, testing rules, and the official reporting route.
  • Published reward information, any submission fee, and dates for time-limited events.
  • For corrections, the bbradar listing URL, the field that needs changing, and an official source showing the current information.

A company-run program can be considered for the verified Self-Hosted catalog. We review official evidence before admitting a program; a reporting email or security.txt alone is not enough.

Send a listing or correction request

Email the details and public source links. Avoid including private vulnerability reports or credentials.

Email [email protected]

You can also contact @Kle0z on X. Inclusion depends on the available evidence and supported sources.

A bbradar listing helps you discover a program. Its official policy determines whether and how you may test. Learn more about our data and signal methodology.