Skip to main content
A program is the central unit of work on Hackrate. It defines what should be tested, by whom, under what rules, and — for bug bounty programs — what rewards are available. Every vulnerability report on the platform is associated with a program, and every program belongs to an organization. Understanding how programs work helps you configure them well and get the most out of your security testing investment.

What a program contains

When you create a program on Hackrate, you configure a set of fields that together describe the engagement completely. Researchers use this information to understand what to test and how to report; your team uses it to triage findings and manage budget.
Markdown formatting is supported in the Description and Policy fields, allowing you to use headings, lists, code blocks, and emphasis to make your program page clear and professional.

Public vs. private programs

One of the most important decisions when creating a program is whether it should be public or private.

Public Programs

Public programs appear in the Hackrate catalog and are open to any registered researcher who chooses to apply. This maximizes your testing coverage and exposes your assets to a diverse range of skill sets and approaches. Public programs are well-suited to mature products that have already been through initial hardening.

Private Programs

Private programs are invite-only. You select specific researchers from the Hackrate community and send them invitations. This approach gives you tighter control over who is testing and is ideal for sensitive systems, early-stage products, or situations where a smaller, focused group of researchers is preferred.
A common progression is to start with a private program to validate your scope and triage workflow with a small group of trusted researchers, then open the program publicly once you are confident in your process.

Program lifecycle

A Hackrate program moves through a series of states from initial setup to completion. Understanding this lifecycle helps you know what actions are available at each stage and what researchers experience.
The program has been created but has not yet been reviewed and published. Only your team can see it. Use this stage to finalize your scope, write your policy, and configure your bounty table before going live.
The program has been reviewed by the Hackrate team and is now visible to researchers (if public) or to invited researchers (if private). Researchers can view the program details and apply or accept invitations.
The program is open for submissions. Researchers can submit vulnerability reports, and your team receives notifications for each new report.
The program has been temporarily suspended. No new reports can be submitted. All participating researchers receive an automatic email notification when a program is paused. Pausing is typically used when your team needs time to catch up on a backlog of reports, or when significant changes are being made to the product under test.
The program has concluded. Existing reports remain accessible for your records and compliance needs, but no new submissions are accepted. For time-boxed engagements such as PTaaS, the end date is agreed upon at the start of the engagement.
Only a SuperAdmin can publish or pause a program. Pausing sends an automatic email to all enrolled researchers, so use this action deliberately.

Program announcements

You can post Announcements to a program at any time. Announcements appear prominently on the program’s details page and are useful for communicating scope changes, temporary restrictions, updated rules, or recognition of the research community’s contributions. Only one announcement is highlighted as “recent” at any given time; previous announcements are archived but remain visible. To notify researchers of an announcement by email (rather than just posting it on the program page), use the separate Send Notification feature in the program management menu.

Program types on Hackrate

Hackrate supports four service types. Each has its own dedicated setup guide.

Managed Bug Bounty

Continuous, reward-based vulnerability discovery with a global researcher community.

Vulnerability Disclosure Policy

A structured, no-bounty reporting channel that protects both your organization and researchers.

PTaaS

Time-boxed penetration testing with verified researchers and real-time report visibility.

Targets & Scope

How to define, tier, and manage the assets within any program type.