Bug bounty programs

Below is a list of public bug bounty programs.

Through a bug bounty program, companies can tap into a global network of ethical hackers who continuously test a wide range of digital assets within the defined scope.

Bug bounty programs reward ethical hackers with financial incentives when valid vulnerabilities are discovered.

Industry

Program type

Sort by

Search

NxtPort VDP

NxtPort VDP

New

Transportation and Logistics

NxtPort builds the next digital link in the digital port infrastructure of the Port of Antwerp-Bruges, developing platforms to make the port faster, safer and more efficient. NxtPort welcomes security researchers and the broader security community to help us identify and responsibly disclose vulnerabilities in our systems. Through this Vulnerability Disclosure Program (VDP), we encourage the reporting of potential security issues that could impact the confidentiality, integrity, or availability of our services. Our goal is to work collaboratively with researchers to investigate and remediate valid findings, helping us maintain a secure and resilient digital ecosystem for the Port of Antwerp-Bruges community. We ask researchers to act responsibly, respect our disclosure guidelines, and avoid activities that could disrupt services or compromise user data. If you discover a vulnerability, please submit it through this program. We appreciate your efforts in helping us improve the security of NxtPort's platforms and services.

Sustainable

Responsible disclosure

Intel® Vulnerability Disclosure Program

Intel® Vulnerability Disclosure Program

New

Manufacturing Consumer

Intel Corporation believes that forging relationships with security researchers and fostering security research is a crucial part of our Security First Pledge. We encourage security researchers to work with us to mitigate and coordinate the disclosure of potential security vulnerabilities. By submitting your report, you agree to the terms of the Intel® Vulnerability Disclosure Program. Intel reserves the right to alter the terms and conditions of this program at its sole discretion.

Responsible disclosure

ADAC Vulnerability Disclosure Program

ADAC Vulnerability Disclosure Program

Financial Services and Insurance

The ADAC Group, consisting of ADAC e.V., ADAC SE, and ADAC Stiftung, uses various digital services. The security of data and processes is of the highest priority. Despite the utmost care, these digital services may contain vulnerabilities that are unknown to the ADAC Group. Therefore, we are grateful for any hints regarding vulnerabilities.

Responsible disclosure

Adobe Public

Adobe Public

Software

Hello and welcome, researchers! A huge welcome to both our returning researchers joining us here and the new members of the community — your work plays a critical role in helping keep Adobe's products and customers secure, and we're grateful to have you on board. Thank you for being part of this next chapter with us.

Bug bounty program

View program

$75 – $15,000

Dutch Lottery VDP

Dutch Lottery VDP

Media and Entertainment

At Nederlandse Loterij, we consider the security of our systems to be of paramount importance. Despite our efforts to secure our systems, it is possible that a vulnerability or weakness may still occur. If you discover a vulnerability or weakness in one of our systems or the associated or underlying domains and/or specific domains of third parties and/or partners, we would appreciate it if you would inform us so that we can take measures as soon as possible.

Responsible disclosure

Mateco VDP

Mateco VDP

Manufacturing Industrial

## Vulnerability Disclosure Program We are committed to maintaining the security of our products, services, and customers. We recognize that independent security researchers play an important role in identifying vulnerabilities that may otherwise go undetected. This Vulnerability Disclosure Program (VDP) provides security researchers with a clear and responsible channel to report security vulnerabilities affecting our in-scope assets. We welcome reports that help us identify weaknesses in our applications, APIs, authentication mechanisms, authorization controls, and other security-relevant functionality. We will review and triage submitted reports and, where appropriate, work with the relevant teams to validate and remediate confirmed vulnerabilities. Please provide sufficient technical information, including a clear description and proof of concept, to allow us to reproduce and assess the reported issue. ### Responsible Testing Researchers participating in this program are expected to: * Act in good faith and conduct testing in a manner that does not unnecessarily affect the availability, confidentiality, or integrity of our systems or data. * Limit testing to the minimum activity required to demonstrate the vulnerability. * Avoid accessing, modifying, deleting, or extracting data belonging to other users or customers. * Avoid actions that could negatively affect our production systems or other users. * Not perform denial-of-service or distributed denial-of-service testing, brute-force attacks, spam, social engineering, physical attacks, or other disruptive activities. * Respect the privacy of our customers, users, and employees. * Keep vulnerability information confidential and not publicly disclose vulnerabilities until remediation or disclosure has been coordinated with us. For authentication bypasses and similar vulnerabilities, demonstrating the ability to circumvent the relevant security control is sufficient. Researchers should not continue exploitation to demonstrate additional impact where doing so could affect our systems or data. Researchers who wish to perform authenticated testing or more extensive exploitation are encouraged to request access to our separate private bug bounty program. ### Reporting Please submit vulnerabilities through this VDP with enough information for our security team to reproduce and validate the issue. Reports should clearly describe the affected asset, the steps required to reproduce the vulnerability, the expected and actual behavior, and the potential security impact. We appreciate responsible security research and the contribution of the security community to improving the security of our products and services.

Responsible disclosure

Ivo: AI VDP

Ivo: AI VDP

Software

Ivo.ai provides AI-powered legal technology designed to support contract review, document workflows, and related productivity use cases. Ivo.ai takes the security of its systems, users, and data seriously. This Vulnerability Disclosure Program invites security researchers to responsibly report vulnerabilities affecting approved Ivo.ai assets, including the Ivo web application, public APIs, Microsoft Word add-in, and authentication or authorization flows. This is a Vulnerability Disclosure Program. No bounty is offered unless explicitly confirmed by Ivo.ai.

Responsible disclosure

Dashlane Vulnerability Disclosure Program

Dashlane Vulnerability Disclosure Program

Software

Dashlane provides credential security solutions that help organisations and individuals protect credentials, identities, and sensitive account data. Dashlane recognises the importance of security researchers in helping keep its community safe. This Vulnerability Disclosure Program invites researchers to responsibly report security vulnerabilities affecting Dashlane-owned services, applications, APIs, browser extensions, mobile applications, autofill and autologin functionality, business features, and SSO/SAML functionality.

Responsible disclosure

Spacelift VDP

Spacelift VDP

Software

Spacelift is an infrastructure orchestration platform that helps teams provision, configure, and govern their entire infrastructure workflow across Terraform, OpenTofu, Pulumi, CloudFormation, Terragrunt, Ansible, and Kubernetes. Security is our first and foremost priority. This program gives security researchers, users, and partners a clear, safe channel to report vulnerabilities in good faith - under full safe harbor and without fear of legal repercussions. We're especially interested in high-impact issues: breaking out of a worker container to the host, privilege escalation beyond the container, cross-tenant access to another customer's workloads, or data exfiltration outside a job's scope. This is a coordinated disclosure program run without monetary bounties. Every valid, original report earns our recognition and sincere thanks. Please review the scope, out-of-scope list, and rules of engagement before testing. Thank you for helping us keep Spacelift and our customers safe.

Responsible disclosure

TrueLayer VDP

TrueLayer VDP

Financial Services and Insurance

TrueLayer is opening up finance and changing the way the world pays. Empowering businesses in every industry to create first-class financial experiences for their customers. We build on top of the Open Banking and PSD2 standards to provide APIs for our customers to use to provide financial data and payment initiation services.

Responsible disclosure

Salto Vulnerability Disclosure

Salto Vulnerability Disclosure

Manufacturing Consumer

Welcome to Salto's responsible vulnerability disclosure program. Here you can report any finding which does not fit into any of our other bug bounty programmes on Intigriti. Salto is a global leader in electronic access control. We design, develop, and manufacture hardware and software for access control systems covering a wide range of uses. Salto locks are installed in all types of buildings, single family housing, hotels, university buildings and dorms, marine applications, critical infrastructure, and many other types of locations. As an access control company security is fundamental to everything we build. We take all reports seriously and strive to always give reports fair triaging. As this is a VDP, bounties are not guaranteed, but we may award compensation at our discretion depending on the nature and impact of the finding. Thank you for helping us make access control more secure. You can learn more about us on our website https://saltosystems.com/

Responsible disclosure

NVIDIA Public Bug Bounty

NVIDIA Public Bug Bounty

Software

Welcome to the NVIDIA Public Bug Bounty Program Thank you for your interest in helping us protect our products and users. We deeply value the security research community and appreciate the time, effort, and creativity you bring to making technology safer for everyone. Your contributions play an essential role in strengthening the trust our users place in NVIDIA.

Bug bounty program

View program

$150 – $15,000

Grafana Labs - Vulnerability Disclosure Program (VDP)

Grafana Labs - Vulnerability Disclosure Program (VDP)

Software

Grafana Labs builds the open source observability stack — Grafana, Loki, Mimir, Tempo, and Pyroscope — and the commercial platform around it, including Grafana Cloud, Grafana Cloud k6, and Grafana IRM (OnCall and Incident). This is a coordinated disclosure programs — the current program is run without monetary bounties; valid, original reports are recognized in the Grafana Labs Security Hall of Fame (https://grafana.com/security/hall-of-fame/), with an associated CVE where applicable. Before you submit, we kindly ask you to read "Submission requirements" and "Use of AI and automated tooling" below. --- Grafana Labs runs an invite-only VIP Bug Bounty program with monetary rewards and all assets are in scope. To get invited to this program you must have demonstrated value in this VDP by having either 3 medium, 2 high or 1 exceptional submissions accepted.

Responsible disclosure

European Space Agency (ESA) VDP

European Space Agency (ESA) VDP

Science and Biotechnology

- Who is the European Space Agency The European Space Agency (ESA) is Europe’s gateway to space. Its mission is to shape the development of Europe’s space capability and ensure that investment in space continues to deliver benefits to the citizens of Europe and the world. - What do we do? We are dedicated to the peaceful exploration and use of space for the benefit of everyone. Established in 1975, we now have 23 Member States and for 50 years we have promoted European scientific and industrial interests in space. - Intention for this specific program? ESA recognizes that vulnerabilities may be discovered by external parties at any time. This policy aims to provide clear and accessible guidance to security researchers, encouraging them to report any findings in a responsible and good‑faith manner, and ensuring they feel supported throughout the process. Our intent is to collaborate with the security community to identify real-world vulnerabilities and continuously improve the security of our systems.

Responsible disclosure

OURA Vulnerability Disclosure Program

OURA Vulnerability Disclosure Program

Retail

ŌURA is a health and technology company, best known as the maker of the world’s leading smart ring, Oura Ring. Guided by a mission to shift healthcare from sick care to prevention, Oura supports millions of members worldwide across sleep, activity, stress, readiness, women’s health, and heart health. Scientifically validated against medical gold standards, the lightweight Oura Ring tracks 50+ health metrics continuously, empowering both individuals and thousands of research teams, healthcare providers, and organizations.

Responsible disclosure

Daytona Bug Bounty

Daytona Bug Bounty

Software

Daytona is an open-source, secure and elastic infrastructure for running AI-generated code. Daytona provides full composable computers — sandboxes — with complete isolation, a dedicated kernel, filesystem, network stack, and allocated vCPU, RAM, and disk. Sandboxes are the core component of the Daytona platform, spinning up in under 90ms from code to execution and running any code in Python, TypeScript, and JavaScript. Built on OCI/Docker compatibility, massive parallelization, and unlimited persistence, sandboxes deliver consistent, predictable environments for agent workflows. Agents and developers interact with sandboxes programmatically using the Daytona SDKs, API, and CLI. Operations span sandbox lifecycle management, filesystem operations, process and code execution, and runtime configuration. Our stateful environment snapshots enable persistent agent operations across sessions, making Daytona the ideal foundation for AI agent architectures.

Bug bounty program

2FA Required

Application Required

View program

€200 – €3,500

SolarWinds VDP

SolarWinds VDP

Software

SolarWinds was founded by IT professionals solving complex problems in the simplest way, and we have carried that spirit forward since 1999. This is our public Vulnerability Disclosure Program (VDP). We invite security researchers to help us identify and remediate potential vulnerabilities on our public-facing marketing websites, domains, and related infrastructure, as well as our product suite.

Responsible disclosure

Wärtsilä Vulnerability Disclosure Program

Wärtsilä Vulnerability Disclosure Program

Manufacturing Industrial

Wärtsilä is a global leader in smart technologies and complete lifecycle solutions for marine and energy markets.

Responsible disclosure

University of Basel VDP

University of Basel VDP

Education

Founded in 1460, the University of Basel is the oldest university in Switzerland. Once a center of European humanism, it is now a highly research-oriented, internationally accessible institution that emphasizes life sciences and medicine. Situated at the intersection of Switzerland, Germany, and France, the university is at the center of the science and innovation hub in the Basel region. As a comprehensive university, it brings together the full range of academic disciplines. Its seven faculties offer a wide range of bachelor’s, master’s, and doctoral programs that prepare students for demanding careers in a changing world. Today, the University of Basel has approximately 13,000 students from more than 100 countries, including around 3,000 doctoral candidates. As a modern research university, it devotes considerable resources to knowledge and technology transfer, actively supporting young academics and researchers. It also maintains strong partnerships and collaborative ties. The University of Basel has garnered international recognition for its exceptional academic achievements. It is ranked among the world’s top 150 universities and the top 15 in the German-speaking countries.

Responsible disclosure

Tekion VDP

Tekion VDP

Software

Tekion (https://tekion.com/) is a modern, cloud-native platform transforming the automotive retail industry. Our flagship product, Automotive Retail Cloud (ARC), seamlessly connects dealerships, OEMs, and consumers through an intelligent and secure ecosystem. As security is core to our mission, we are launching this VDP program in collaboration with Intigriti to proactively identify and fix potential vulnerabilities. Through this, we aim to strengthen our platform’s security and ensure the safety of our users’ data through responsible disclosure.

Responsible disclosure

Attentia VDP

Attentia VDP

Business and Professional Services

Attentia provides integrated HR, payroll, prevention & protection and well‑being services to Belgian organisations. We welcome responsible security research to help us strengthen our systems. Please report vulnerabilities affecting Attentia assets (web applications, APIs, and customer portals) via our secure reporting channel. Do not access, copy, or exfiltrate personal payroll or health data; avoid tests that could disrupt payroll processing.

Responsible disclosure

Atolls Vulnerability Disclosure Program (VDP)

Atolls Vulnerability Disclosure Program (VDP)

Financial Services and Insurance

Atolls (formerly Global Savings Group) is Europe's largest shopping engagement platform, helping millions of consumers find, compare, and act on savings, cashback, and deals across 20+ countries. We operate major brands like Coupon.com, iGraal, Shoop, and hotukdeals, connecting thousands or retailers with shoppers to drive informed, money-saving purchasing decisions.

Responsible disclosure

CARIAD VDP

CARIAD VDP

Software

CARIAD SE is the automotive software company of the Volkswagen Group, responsible for developing secure, scalable, and future‑proof digital platforms and software solutions for vehicles and mobility services across the Group’s brands. CARIAD SE is committed to maintaining a high level of cybersecurity across its products, services, and infrastructure. To support this objective, CARIAD SE establishes this Vulnerability Disclosure Program in collaboration with Intigriti. This program provides an open and structured channel for security researchers, ethical hackers, and external stakeholders to responsibly disclose potential vulnerabilities identified in externally accessible CARIAD systems, services, and interfaces. These may include web applications, APIs, cloud environments, IT infrastructure, and connected vehicle interfaces. Despite comprehensive internal security measures, vulnerabilities may still exist. All reported vulnerabilities are handled in accordance with CARIAD’s centrally governed vulnerability management and incident response processes. Researchers are expected to conduct all activities responsibly and in compliance with this policy. We welcome the global security research community and appreciate your contributions to improving the security of our systems. By participating in this program, you help us strengthen the resilience of our digital ecosystem and protect our users, partners, and products.

Responsible disclosure

T&C Required

Coveo Public Bug Bounty

Coveo Public Bug Bounty

Software

Coveo delivers AI-powered search and recommendations across websites, apps, and enterprise systems. Our platform includes automated crawlers, customer-supplied Python execution, and large-scale AI/GenAI infrastructure, plenty of interesting attack surface. If you find real security impact in these areas (or elsewhere), we want to hear from you. Please review the scope carefully so eligible reports can be rewarded appropriately.

Bug bounty program

2FA Required

View program

$100 – $5,500