How bug bounty works on Hackrate
The lifecycle of a managed bug bounty program follows four phases:1
Plan — Define scope and rewards
Work with the Hackrate team to define which assets are in scope, what types of vulnerabilities are eligible for rewards, and how much you are willing to pay for each severity level. Setting the right bounty amounts and clear boundaries is the foundation of a successful program. A well-scoped program attracts quality researchers and produces actionable findings.
2
Prepare — Finalize rules and launch strategy
Finalize the program policy: what researchers can and cannot do during testing, which vulnerability classes are in scope, how to report findings, and the expected response time from your team. Decide whether to start with a private (invite-only) program or go public immediately. Hackrate’s team reviews and approves the program before it goes live.
3
Test — Researchers find and report vulnerabilities
Once the program is published, researchers begin testing. Each submission arrives in your report inbox with a structured format: title, affected target, reproduction steps, evidence, and the researcher’s severity assessment. Hackrate’s managed triage validates reports for accuracy before they reach your team, eliminating duplicate and low-quality submissions.
4
Fix — Resolve findings and reward researchers
Review validated reports, collaborate with researchers through the platform’s messaging thread, and track remediation progress. When a report is accepted, you approve the bounty payout. Hackrate handles the actual payment to the researcher after your authorization, and the researcher earns both the monetary reward and reputation points on the platform.
Setting up your bounty table
The Bounty Table defines exactly how much a researcher earns for a valid finding, based on the severity of the vulnerability and the tier of the affected target.Severity levels
Hackrate uses five severity levels, aligned with industry-standard vulnerability scoring practices:Tiers: prioritizing your most important assets
Hackrate’s bounty table uses a two-tier system that lets you pay more for vulnerabilities in your most critical assets without affecting payouts for secondary systems.- Tier 1 — Primary or business-critical assets, such as your main customer-facing application, core API, or payment system. Tier 1 vulnerabilities command the highest bounties.
- Tier 2 — Secondary assets, such as staging environments, marketing sites, or less sensitive internal tools. Tier 2 payouts are lower, reflecting the reduced business risk.
Example bounty table
The table below shows a typical bounty configuration. Your actual amounts will depend on your budget, the sensitivity of your assets, and market benchmarks for your industry.The Exceptional severity row is optional — you can choose whether to include it in your program. Bounty amounts can also be configured as fixed values or as ranges (a minimum and maximum per cell). Ranges give your team flexibility to reward exceptional report quality within a severity band. Contact the Hackrate team to configure range-based payouts.
Currency
Each program is denominated in either USD or EUR. All bounty table values and budget tracking use the currency you select at program creation. Currency cannot be changed after the program is published.Managing your budget
Every bug bounty program has an associated Budget — the total funds allocated for bounty payments across the program’s lifetime. The Hackrate analytics dashboard gives you live visibility into:- Bounties paid — the sum of all approved payouts to date
- Bonus payments — any additional discretionary rewards granted on top of standard bounties
- Budget consumption percentage — how much of your total budget has been spent
- Bounty forecast — the estimated future spend based on open, unresolved reports
Public vs. private bug bounty programs
- Private (Invite-Only)
- Public
A private bug bounty program is only accessible to researchers you explicitly invite. This approach is ideal when you are:
- Running your first bug bounty program and want to start with a small, trusted cohort
- Testing a sensitive or pre-release product
- Working within regulatory constraints that require controlled access
Program models and maturity paths
Bug bounty programs do not have to follow a one-size-fits-all model. Hackrate supports several common approaches:Private → Public
Start with a controlled, invite-only program. Once your team is comfortable triaging reports and your scope is well-defined, expand to a public program for broader coverage.
Continuous
An always-on program with no fixed end date. Ideal for products that ship continuously and need ongoing security validation as each release introduces new code.
Hybrid (alongside PTaaS)
Run a bug bounty program for continuous coverage while commissioning targeted PTaaS engagements for deep-dive assessments of specific features or compliance requirements.
Gradual scope expansion
Begin with a narrow scope — one or two core assets — and expand the target list as your remediation capacity grows and your team’s confidence increases.