What a program contains
When you create a program on Hackrate, you configure a set of fields that together describe the engagement completely. Researchers use this information to understand what to test and how to report; your team uses it to triage findings and manage budget.Markdown formatting is supported in the Description and Policy fields, allowing you to use headings, lists, code blocks, and emphasis to make your program page clear and professional.
Public vs. private programs
One of the most important decisions when creating a program is whether it should be public or private.Public Programs
Public programs appear in the Hackrate catalog and are open to any registered researcher who chooses to apply. This maximizes your testing coverage and exposes your assets to a diverse range of skill sets and approaches. Public programs are well-suited to mature products that have already been through initial hardening.
Private Programs
Private programs are invite-only. You select specific researchers from the Hackrate community and send them invitations. This approach gives you tighter control over who is testing and is ideal for sensitive systems, early-stage products, or situations where a smaller, focused group of researchers is preferred.
Program lifecycle
A Hackrate program moves through a series of states from initial setup to completion. Understanding this lifecycle helps you know what actions are available at each stage and what researchers experience.Draft
Draft
The program has been created but has not yet been reviewed and published. Only your team can see it. Use this stage to finalize your scope, write your policy, and configure your bounty table before going live.
Published
Published
The program has been reviewed by the Hackrate team and is now visible to researchers (if public) or to invited researchers (if private). Researchers can view the program details and apply or accept invitations.
Active
Active
The program is open for submissions. Researchers can submit vulnerability reports, and your team receives notifications for each new report.
Paused
Paused
The program has been temporarily suspended. No new reports can be submitted. All participating researchers receive an automatic email notification when a program is paused. Pausing is typically used when your team needs time to catch up on a backlog of reports, or when significant changes are being made to the product under test.
Ended
Ended
The program has concluded. Existing reports remain accessible for your records and compliance needs, but no new submissions are accepted. For time-boxed engagements such as PTaaS, the end date is agreed upon at the start of the engagement.
Program announcements
You can post Announcements to a program at any time. Announcements appear prominently on the program’s details page and are useful for communicating scope changes, temporary restrictions, updated rules, or recognition of the research community’s contributions. Only one announcement is highlighted as “recent” at any given time; previous announcements are archived but remain visible. To notify researchers of an announcement by email (rather than just posting it on the program page), use the separate Send Notification feature in the program management menu.Program types on Hackrate
Hackrate supports four service types. Each has its own dedicated setup guide.Managed Bug Bounty
Continuous, reward-based vulnerability discovery with a global researcher community.
Vulnerability Disclosure Policy
A structured, no-bounty reporting channel that protects both your organization and researchers.
PTaaS
Time-boxed penetration testing with verified researchers and real-time report visibility.
Targets & Scope
How to define, tier, and manage the assets within any program type.