> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hckrt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Private Programs: Invitations, Access, and Participation

> Hackrate private programs explained: join by invitation or application, unlock the full scope once accepted, and build reputation to earn more invitations.

Not every program on Hackrate appears in the public catalog. **Private programs** are invite-only engagements where the company has chosen to work with a curated group of researchers rather than the entire Hackrate community. These programs are not discoverable through catalog browsing — you can only access them after receiving an invitation or being accepted through an application process.

Private programs are typically used by organizations with more sensitive systems, higher security maturity, or specific requirements around which researchers they work with. They often offer higher bounties, more focused scope, and more direct communication with the security team. Building a reputation that earns you private program access is one of the most valuable long-term goals for a Hackrate researcher.

## How private programs differ from public ones

<CardGroup cols={2}>
  <Card title="Not listed in the catalog" icon="eye-slash">
    Private programs do not appear as clickable cards in the public catalog. You may see a locked placeholder card indicating a private program exists, but you cannot view any details without access.
  </Card>

  <Card title="Invitation or application required" icon="envelope">
    You need either a direct invitation from the program owner or an accepted application to gain access. Browsing or submitting reports without access is not possible.
  </Card>

  <Card title="Curated researcher pool" icon="users">
    Program owners choose exactly who participates. This gives companies confidence in who is testing their systems and lets them build ongoing relationships with trusted researchers.
  </Card>

  <Card title="Submit reports only after acceptance" icon="lock-open">
    Even if you know a private program exists, you cannot submit a report against it until you have been formally accepted. Submissions from non-accepted researchers are rejected automatically.
  </Card>
</CardGroup>

## How to get access to a private program

There are two routes to joining a private program:

### Route 1: Direct invitation from the program owner

Program owners can invite specific researchers directly based on their Hackrate profiles. If you receive an invitation:

1. You will be notified through the platform and by email.
2. The program appears in your **Dashboard** under **Invites** for a limited period (12 days from the invitation date).
3. Accept the invitation to gain full access to the program scope, policy, bounty table, and report submission form.

<Warning>
  Invitations expire after **12 days** if not accepted. If you miss the window, you will need to contact the program owner or wait for a new invitation. Check your platform dashboard and notifications regularly so you do not miss time-sensitive invites.
</Warning>

### Route 2: Applying through a public invitation link

Some programs provide a public application link that lets any researcher express interest in joining. When such a link is available, you can submit an application — this creates an access request that the program owner reviews before granting or denying access.

The application process is straightforward:

<Steps>
  <Step title="Find the application link">
    Public invitation links are shared by program owners through Hackrate communications, their company's security page, or community channels. You will not find them in the catalog itself.
  </Step>

  <Step title="Submit your application">
    When you open an application link while signed in to Hackrate, your application is recorded. Your public profile — including your nickname, reputation score, verified status, and submitted work history — is what program owners use to evaluate you.
  </Step>

  <Step title="Wait for a decision">
    Program owners review applications at their own pace. There is no guaranteed timeline. Building a strong reputation on public programs makes your application more compelling.
  </Step>

  <Step title="Access granted or declined">
    If accepted, the program appears in your Dashboard under **Applied Programs**. You can then access the full program page, review scope and policy, and begin submitting reports. If declined, you will be notified — this does not prevent you from applying to other programs.
  </Step>
</Steps>

## What changes once you are accepted

After acceptance, your experience is similar to a public program — but with some meaningful differences:

* **The full program page is unlocked.** You can read the complete scope, policy, bounty table, and any announcements that were previously hidden from you.
* **The report submission form is active.** You can submit vulnerability reports directly to the program.
* **Your accepted status is recorded.** Your access is tracked through a platform access record linked to both you and the program. This cannot be transferred or shared.
* **Higher expectations apply.** Private programs typically expect higher-quality reports, strict adherence to the program policy, and more professional communication than a general public program might. Program owners have chosen to work with you specifically — represent yourself accordingly.

<Note>
  Access to a private program does not mean unlimited testing. You are still bound by the program's scope and policy. Test only in-scope targets, during permitted testing hours, and within the rules set out in the program policy. Access can be revoked if you violate these terms.
</Note>

## Building toward private program invitations

If you are new to Hackrate and do not yet have access to any private programs, the most reliable path is consistent, high-quality work on public programs. Program owners watch the leaderboard and public researcher profiles when deciding whom to invite.

<CardGroup cols={2}>
  <Card title="Earn reputation points" icon="trophy">
    Reputation is the primary signal program owners look at. Every valid finding on a public program earns reputation points. Aim for steady growth rather than chasing a single large bounty.
  </Card>

  <Card title="Get identity verified" icon="badge-check">
    Verified researchers receive significantly more private program invitations. The verification badge signals to program owners that you have passed identity and trustworthiness checks. Complete your verification as early as possible.
  </Card>

  <Card title="Write high-quality reports" icon="file-pen">
    Reports that are clear, well-documented, and reproducible on the first read reflect positively on you. Program owners remember researchers who make their triage process easy.
  </Card>

  <Card title="Aim for the leaderboard" icon="chart-bar">
    The Hackrate leaderboard ranks researchers by reputation, impact, and valid report count. Appearing on the leaderboard — especially in the top positions — makes you highly visible to program owners actively searching for researchers to invite.
  </Card>
</CardGroup>

<Tip>
  The [Hackrate Elite Club](https://elite.hckrt.com) is reserved for the most trusted and accomplished researchers on the platform. Elite members receive priority consideration for all private program invitations. Working toward Elite status is the single most effective way to maximize your private program access over the long term.
</Tip>
