1
Register your company account
Go to hckrt.com and sign up for an account. During registration, you will provide your name and email address and create a password. After verifying your email, you will be prompted to indicate that you are joining as an organization (rather than as a security researcher).
2
Create your organization
Once you are logged in, create your Organization. An organization is your company’s top-level workspace — it holds all of your programs and allows you to manage team members and permissions centrally.You will provide:
- Organization name — your company’s display name on the platform
- Alias — a short, unique identifier used in program URLs (for example,
acme)
3
Choose your service type and create your first program
From your organization dashboard, create a new program. The most important decision at this stage is which service type fits your current needs.Fill in your program’s Name, Description (about your company), Policy (program rules for researchers), and set the program’s currency (USD or EUR). You can also choose whether the program should be public (visible in the Hackrate catalog) or private (accessible only to researchers you invite).
- Bug Bounty
- VDP
- PTaaS
Choose a Managed Bug Bounty Program if you want ongoing, continuous security testing with monetary rewards for researchers. Bug bounty works best when you already have a mature product that can tolerate creative, open-ended testing. You will configure a bounty table that sets payout amounts by severity and asset tier.
4
Define your targets and scope
Scope is one of the most important parts of any security program. Add the assets you want researchers to test as Targets. For each target, provide:
- Name — a clear, recognizable label (for example,
Main Web ApporCustomer API) - Type — the asset category (web application, API, mobile app, etc.)
- Description — context that helps researchers understand what the asset does
- Tier — Tier 1 for your primary or highest-value assets; Tier 2 for secondary assets. Tier affects bounty payouts in a bug bounty program.
- Bounty eligible — whether valid findings on this target are eligible for a monetary reward
5
Invite researchers and publish your program
With your scope defined, you are ready to open the program to researchers.
- Public programs — click Publish to list the program in the Hackrate catalog. Any registered researcher can apply to participate.
- Private programs — use the Invite Hackers feature to select specific researchers from the Hackrate community. You can resend invitations at any time.
Before publishing, the Hackrate team will review your program configuration to ensure the scope, rules, and bounty table are clear and complete. This review is part of the managed service.
6
Receive and triage your first report
When a researcher submits a vulnerability, it appears in your Reports inbox. Each report includes a title, description, reproduction steps, supporting evidence, and the researcher’s assessment of severity.Your team reviews each report, communicates with the researcher through the platform’s messaging thread, and updates the report status. For bug bounty programs, once a report is validated you can approve the bounty payout — Hackrate handles the payment to the researcher.Use the Analytics dashboard to track total reports by severity, bounties paid, budget consumption, and researcher activity over time.
What to do next
Account Setup
Invite your security team, configure notification preferences, and manage organization settings.
Programs Overview
Learn about program lifecycle stages, public vs. private programs, and key configuration fields.
Targets & Scope
Deep-dive into defining targets, assigning tiers, and managing out-of-scope assets.
Bug Bounty
Configure bounty tables, set payout ranges, and manage your program budget.