Bug Bounty Programs

Below is a list of public bug bounty programs. Through a bug bounty program, companies can tap into a global network of ethical hackers who continuously test a wide range of digital assets within the defined scope.

Bug bounty programs reward ethical hackers with financial incentives when valid vulnerabilities are discovered.

Industry

Program type

Sort by

Search

Dropbox Bug Bounty

Dropbox Bug Bounty

Software

Welcome to the Dropbox Bug Bounty program — where your curiosity helps keep millions of users safe. At Dropbox, we take security seriously, and we know the best defenses are built with input from the wider security community. Whether you're diving into our apps, APIs, or backend systems, your expertise plays a critical role in protecting the data people trust us with every day. We reward creativity, precision, and clear reporting — and we’re here to support you along the way. Be sure to check out our scope, rules, and submission guidelines before getting started. Let’s work together to make Dropbox even more secure — one bug at a time.

Bug bounty program

$100 – $15,000

SimScale

SimScale

Manufacturing Consumer

SimScale is a browser-based, online engineering simulation platform that provides powerful modeling and simulation capabilities. With in-browser 3D visualization, scalable on-demand computing capacity, the SimScale platform enables a new way of using simulation technology. SimScale integrates a broad variety of simulation software tools for structural mechanics, fluid dynamics, and thermodynamics. The SimScale team and our partners are constantly expanding the features of the platform.

Bug bounty program

€250 – €6,000

Monzo Public Bug Bounty Program

Monzo Public Bug Bounty Program

Financial Services and Insurance

Welcome to the Monzo public bug bounty program! 🚀 At Monzo we aim to create a banking service that makes our customers financial lives better and easier. Our mantra is “make money work for everyone” and we mean it! 👍 We have created several apps to provide intuitive, helpful, and enjoyable experiences across our range of products 💖. We won’t sacrifice security though! So if you find a security bug in one of our apps or services, this is the place to report it! Happy hunting!

Bug bounty program

£50 – £12,500

DataCamp

DataCamp

Education

DataCamp’s mission is to democratize data skills for everyone. Companies and teams of every size use DataCamp to close their data skill gaps and make better data-driven decisions. Data science and analytics are rapidly shaping every aspect of our lives and our businesses. There is incredible power in data—but only if you know what to do with it. DataCamp teaches 1,600+ companies and 7 million individuals from 180+ countries the skills they need to work with data in the real world.

Bug bounty program

€25 – €1,500

Ninja Kiwi Games Bug Bounty program

Ninja Kiwi Games Bug Bounty program

Media and Entertainment

Creators of hit computer game franchises Bloons, Bloons TD and SAS: Zombie Assault for mobile and web. We have offices in Auckland, New Zealand and Dundee, Scotland. We are excited to engage with the security community to help us keep our users safe and our services secure. This is our second Bug Bounty program after a successful campaign in 2021.

Bug bounty program

€75 – €4,125

Aikido Security: Zen by Aikido

Aikido Security: Zen by Aikido

Software

Zen by Aikido is an embedded security engine for autonomously protecting applications against common web attacks, like shell injection and SQL injection. We do so by hooking into sinks, validating them together with the incoming user input and in case the request is malicious, we block the request. It's similar to a traditional WAF, but with the full context of the called code and the user's input.

Bug bounty program

€100 – €3,500

Meshtastic

Meshtastic

An open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices Hey Hackers! If you met us at DEF CON thank you for your interest in this program. This program can be used to disclose any vulnerabilities found on the devices handed out during the Con.

Responsible disclosure

Axel Springer National Media & Tech

Axel Springer National Media & Tech

Media and Entertainment

AS National Media & Tech (NMT) is a subsidiary of Axel Springer SE, a leading international media company. We develop and operate digital products for Germany’s top news brands, reaching over 50 million users each month. At Axel Springer, we stand for free journalism and unrestricted access to information, allowing people to make free decisions. To protect this, the security of our platforms and users is our top priority. Your contributions help us keep them safe.

Bug bounty program

€15 – €2,500

Arbonia VDP program

Arbonia VDP program

Construction

We are happy to relaunch our public VDP program! We've done our best to clean up our issues and now would like to request your help to spot the ones we missed! We start with just a few domains and want to continously increase our scope at regular intervals. So keep checking this page from time to time to see if there is anything new to find. ⚠️ Only submissions that follow the Rules of Engagement (e.g., using an intigriti.me email) and are not Out of Scope will be considered valid. Actions like mail bombing, denial of service, changing/removing data or parameters, or interfering with asset functionality are strictly forbidden and not protected by the safe harbor clause. Always aim to prevent harm, review all relevant sections before starting and follow the rules of engagment. Arbonia is one of the world's leading interior brands for doors, showers, and dividing systems made from wood, glass and metal. The company, which is listed on the SIX Swiss Exchange, is active as a leading supplier in Western, Central, and Eastern Europe with its own distribution companies. Its main production sites are located in Switzerland, Germany, Poland, Spain, Czech Republic, Portugal, and France. A total of around 3'700 employees work for the Arbonia.

Responsible disclosure

Wolt

Wolt

Leisure and Hospitality

We provide a platform for: - Businesses to sell products (like food, clothing and even electronics). - Customers to purchase such products and get them delivered by Wolt couriers. - Wolt couriers to receive and manage delivery requests. We have more than 30 million registered users and we operate in 20+ countries. Read more about us: https://wolt.com/en/about.

Bug bounty program

€100 – €3,500

PDQ bug bounty program

PDQ bug bounty program

Software

At PDQ our mission is to make device management simple, secure, and pretty damn quick. We know how important the security of our products is. We're a bunch of former sysadmins ourselves. Every decision we make revolves around ensuring our products are safe to use for managing your devices, which is why we have a bug bounty program. It’s a true win-win: We improve the security of our products, and you reap the rewards.

Bug bounty program

€50 – €3,500

Suivo bug bounty

Suivo bug bounty

Software

The Suivo Web Platform provides access to Tracking data from vehicles equiped with Suivo hardware. The platform is built around 4 components: - Real-time Tracking data - Analytics based on historical Tracking data, both in a web view en generated reports - Communication: tasks and messages - Fleet management (Maintenance planning etc.)

Sustainable

Bug bounty program

Up to €2,000

Torfs

Torfs

Retail

Torfs - the well-known shoe retailer in Belgium - is still a 100% family business today. This family character guarantees a number of important values within the company where employees are central. A head office in Sint-Niklaas and a spectacular distribution center in Temse offer support to the points of sale and customers of the E-Commerce website. With more than 80 stores in Flanders, 2 shops in the French part of Belgium and a growing online shop in Belgium, The Netherlands and several marketplaces, Torfs wants to be and remain the most customer-friendly optichannel shoe store chain.

Bug bounty program

€25 – €6,500

Soundtrack Your Brand

Soundtrack Your Brand

Media and Entertainment

Soundtrack Your Brand offers music streaming services for businesses. We serve small customers like the café around the corner or larger brands like McDonald’s. Through our service customers have total control over the music and can manage locations across the world. We provide a wide variety of playback options, from mobile apps to custom hardware, that our customers use to play music at their venues. They manage their account, music and locations via our web app.

Bug bounty program

€50 – €3,500

De Lijn

De Lijn

Transportation and Logistics

De Lijn is the Flemish public transportation company dedicated to giving their customers a comfortable and quick ride. Due the fact that we use the latest IT equipment and servers is our security ought to be at the top of our game. For this program we are putting the focus at our web clients, APIs and of course the mobile application.

Responsible disclosure

Dropbox Vulnerability Disclosure Program

Dropbox Vulnerability Disclosure Program

Software

Dropbox invites security researchers to responsibly disclose security vulnerabilities in its services via a structured VDP. Unlike its bug bounty program, this VDP does not offer monetary rewards, though Dropbox may offer discretionary “thank you” bonuses or inclusion in a public hall of fame. The program emphasizes legal protections, timely handling of submissions, and a communication channel for responsible disclosures that are not seeking a reward.

Responsible disclosure

Webnode

Webnode

Media and Entertainment

Webnode is an amazingly simple website builder. Launched in 2008, it has already helped over 50 million users create their own websites. Webnode has recently been acquired by the number one hosting company in Europe and therefore the product will be used and implemented throughout different brands in Europe.

Bug bounty program

2FA Required

Application Required

€100 – €1,750

Aikido Security: Bug Bounty Program

Aikido Security: Bug Bounty Program

Software

Aikido Security is an automated application security platform designed specifically for software engineering teams. We secure your entire stack - code, open-source dependencies, infrastructure, and more and integrate into your existing workflows to provide visibility and control across your entire application infrastructure.

Bug bounty program

€50 – €2,500

Say Technologies Bug Bounty Program

Say Technologies Bug Bounty Program

Financial Services and Insurance

Say unlocks the power of investor communications by working with broker-dealers to connect shareholders with the public companies they invest in.

Bug bounty program

Up to $10,000

BMW Group

BMW Group

Manufacturing Consumer

With its four brands BMW, MINI, Rolls-Royce and BMW Motorrad, the BMW Group is the world’s leading premium manufacturer of automobiles and motorcycles and also provides premium financial services. Our vehicles and products are tailored to the needs of our customers and constantly enhanced. We place special emphasis on the security, integrity and availability of our data and systems and thus also on those of our customers, employees and partners.

Bug bounty program

€150 – €6,000

Nexuzhealth

Nexuzhealth

Hospitals and Healthcare

Website + Android Apps + iOS Apps Android Apps KWS Companion The application is only to be used by doctors and no logon information will be given. mynexuz CPV The application is only to be used by personnel of UZ Leuven responsible for transport of patients and no logon information will be given. mynexuzhealth app This application is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. iOS Apps KWS Companion The application is only to be used by doctors and no logon information will be given. Website mynexuzhealth website This website is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. In order to be able to logon to the mynexuzhealth website and app, an ethical hacker will need to request one or more logon credentials via the platform. You can request this information via support (support@intigriti.be). The information they will receive is - A user ID of 8 numbers - A PIN code of 4 numbers - A QRCode

Sustainable

Bug bounty program

Up to €4,000

Proof.com VDP

Proof.com VDP

Software

Proof℠ is the world's first identity-assured transaction management platform. Developed by the same market leaders and experts who brought notarization online with Notarize℠, Proof offers trust in a digital world by verifying identities and securing transactions to protect your business and its customers. When risk is low and speed matters, get it signed. When the law dictates it, get it notarized. When trust matters, you need Proof. Welcome to our public vulnerability disclosure page! This program is sponsored by the Information Security team. We look forward to your submissions.

Responsible disclosure

Lansweeper Bug Bounty Program

Lansweeper Bug Bounty Program

Software

Lansweeper is an IT asset management software provider helping businesses better understand, manage and protect their IT devices and network. Lansweeper helps customers minimize risks and optimize their IT assets by providing actionable insight into their IT infrastructure at all times, offering trustworthy, valuable, and accurate insights about the state of users, devices, and software.

Bug bounty program

€50 – €6,000

WP Engine VDP

WP Engine VDP

Media and Entertainment

WP Engine invites you to test the WP Engine and Flywheel Digital Experience Platforms. WP Engine equips its customers with a suite of agility, performance, intelligence, and integration solutions, so you can build and deploy a range of online experiences from campaign sites to content hubs to e-commerce extensions. Good luck and happy hunting!

Responsible disclosure