How a finding gets published
The decision to publish a report to Hacktivity rests entirely with the company, not the researcher. After a report reaches a resolved or accepted status, the company can submit it for publication. Platform administrators review and approve the submission before it goes live on the public feed.1
Report resolved
Your report reaches a closing status — such as Resolved or Accepted Risk — after the company has addressed or acknowledged the finding.
2
Company submits for disclosure
The company opts to share the report publicly. They may add a Team Summary, adjust visible fields, and choose what details to include in the disclosure.
3
Platform review
Hackrate administrators review the submission to ensure no sensitive details are inadvertently exposed before publication.
4
Published to the feed
The entry becomes visible on the public Hacktivity feed and receives a permanent, shareable detail page that you can link to from your portfolio.
You cannot self-publish a report to Hacktivity. Disclosure is always initiated by the company after resolution. If you want your finding disclosed, discuss it with the program team once the issue is fully resolved.
What each Hacktivity entry shows
The feed lists all published entries in reverse-chronological order. Each card on the feed displays:Viewing full disclosure details
Clicking the Details button on any feed entry takes you to the full disclosure page for that finding. This page includes:Finding metadata
Finding metadata
The full detail view shows the program name, affected target and its tier, severity, CVSS score (if provided), CVE number (if assigned), affected versions, and CWE weakness classification. These fields give readers the technical context to understand the vulnerability class and its potential impact.
Summary and description
Summary and description
The publication includes a researcher-authored summary and description of the finding, rendered in formatted Markdown. Well-written summaries make your disclosed work more valuable as a portfolio piece.
Impact statement
Impact statement
A dedicated Impact section describes what an attacker could have achieved by exploiting the vulnerability — for example, data exfiltration, privilege escalation, or denial of service.
Team summary
Team summary
If the company added a Team Summary, it appears at the top of the disclosure. This is the company’s perspective on the finding — typically acknowledging the researcher’s contribution and describing how they responded.
Timeline
Timeline
The disclosure includes a curated timeline drawn from the report’s activity log, showing key milestones such as when the report was created, when it was accepted, when severity was adjusted, and when the bounty was awarded.
Bounty information
Bounty information
If a bounty was awarded and the company chose to include it in the disclosure, the amount is shown on the detail page.
Public vs. private programs
The way your name appears in a Hacktivity entry depends on the program’s visibility setting:- Public programs
- Private programs
When a finding from a public program is disclosed, the full program name appears on the entry. Your nickname, severity, status, and all approved metadata are displayed. The entry is fully indexed and searchable.
Why Hacktivity matters for your reputation
Having your reports published to Hacktivity provides benefits that go beyond the bounty itself:Public portfolio
Disclosed findings link to your public profile. Potential employers, clients, and program administrators can see your track record of real-world vulnerabilities — not just your score, but the actual work.
Community recognition
A strong Hacktivity presence demonstrates that companies trust you enough to disclose your work publicly. It signals quality and professionalism to the broader security community.
Verified author badge
Disclosed entries show your verified status badge if your identity is confirmed. This increases credibility and is visible to anyone reading the feed.
Platform transparency
Published findings contribute to the platform’s public record of security improvements — helping other researchers understand what vulnerability classes are in scope and what companies value.