Bug Bounty Programs

Below is a list of public bug bounty programs. Through a bug bounty program, companies can tap into a global network of ethical hackers who continuously test a wide range of digital assets within the defined scope.

Bug bounty programs reward ethical hackers with financial incentives when valid vulnerabilities are discovered.

Industry

Program type

Sort by

Search

PeopleCert VDP

PeopleCert VDP

Education

PeopleCert is the global leader in the assessment and certification of professional and language skills, partnering with multi-national organisations and government bodies to develop and deliver market leading exams worldwide. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities.

Responsible disclosure

Visma Responsible Disclosure

Visma Responsible Disclosure

Software

Visma delivers software that simplifies and digitizes core business processes in the private and public sector. With presence across the entire Nordic region along with Benelux, Central and Eastern Europe, we are one of Europe’s leading software companies. We want to engage with responsible security researchers around the globe to further secure our services. This program is dedicated for all Visma assets (services, products, web properties).

Sustainable

Responsible disclosure

Nestlé VDP

Nestlé VDP

Manufacturing Consumer

In Nestlé we believe in the power of food to enhance quality of life for everyone, today and for generations to come. IT Security is a top priority for us, we are committed to work with security researchers across the globe to help protect our systems and our customers' data from malicious activity and to further improve cyber security across our organization.

Responsible disclosure

Canada Post + Purolator - Responsible Disclosure Program

Canada Post + Purolator - Responsible Disclosure Program

Transportation and Logistics

Canada Post is the country’s leading provider of business-to-consumer delivery. Reaching more than 16.2 million addresses, and operating the country’s largest retail network of over 6,200 post offices. Purolator is Canada’s leading integrated freight, parcel and logistics solutions provider. Purolator continues to expand its reach and renowned service levels and reliability to more people, more businesses and more places across the country and around the world.

Responsible disclosure

Intel®

Intel®

Manufacturing Consumer

Intel® Bug Bounty Program Intel Corporation believes that forging relationships with security researchers and fostering security research is a crucial part of our Security First Pledge. We encourage security researchers to work with us to mitigate and coordinate the disclosure of potential security vulnerabilities. By submitting your report, you agree to the terms of the Intel® Bug Bounty Program. Intel reserves the right to alter the terms and conditions of this program at its sole discretion.

Bug bounty program

View program

$250 – $100,000

Soundtrack Your Brand

Soundtrack Your Brand

Media and Entertainment

Soundtrack Your Brand offers music streaming services for businesses. We serve small customers like the café around the corner or larger brands like McDonald’s. Through our service customers have total control over the music and can manage locations across the world. We provide a wide variety of playback options, from mobile apps to custom hardware, that our customers use to play music at their venues. They manage their account, music and locations via our web app.

Bug bounty program

View program

€50 – €3,500

Mobile Vikings

Mobile Vikings

Telecommunications

True Vikings never entered the battlefield without their helmets. And we believe a secure environment, just like free access to open communication, is a worldwide human right. But even the best Viking Drakkars may sometimes encounter vulnerabilities. Brave sailors who discover leaks should be honored - not executed. Together with you and our broad community, we want to create a secure and safe environment for everyone.

Bug bounty program

View program

Up to €5,000

Fing Bug Bounty Program

Fing Bug Bounty Program

Software

Fing device recognition is the foundation of digital products. Just from the MAC address, Fing can recognise all wireless and wired devices in home, office or enterprise networks by type, make, model and OS (name and version). Fing device intelligence and knowledge give you full visibility of your connected environment. The free Fing App identifies connected devices, troubleshoots network and device issues, detects network intruders and runs Wi-Fi and internet speed tests anywhere.

Bug bounty program

View program

€50 – €3,500

Vlerick Business School

Vlerick Business School

Education

Vlerick Business School is an international business school at the heart of Europe. We offer fully-accredited, world class education programs combining a healthy mix of theoretical knowledge and practical insight.

Responsible disclosure

Personio

Personio

Business and Professional Services

Personio is Europe's leading HR Software for SMEs - your one-stop HR solution with automated processes, seamless integrations, and data-driven insights. Our Security Team knows that a solid Bounty Program helps build customer trust in our platform. So we are looking forward to working with you to help hold our platform up to the highest of standards.

Bug bounty program

View program

€50 – €5,000

SimScale

SimScale

Manufacturing Consumer

SimScale is a browser-based, online engineering simulation platform that provides powerful modeling and simulation capabilities. With in-browser 3D visualization, scalable on-demand computing capacity, the SimScale platform enables a new way of using simulation technology. SimScale integrates a broad variety of simulation software tools for structural mechanics, fluid dynamics, and thermodynamics. The SimScale team and our partners are constantly expanding the features of the platform.

Bug bounty program

View program

€250 – €6,000

Moralis VDP

Moralis VDP

Software

Moralis is a blockchain technology platform providing developers with backend infrastructure for building and scaling decentralized applications (dapps). This page is a safe way for you to communicate found bugs in a responsible way. All contributions are highly appreciated.

Responsible disclosure

Digitaal Vlaanderen

Digitaal Vlaanderen

Public Services

"Digitaal Vlaanderen" is the IT and digital transformation departement within the Flanders’ governmental IT. Positioned as the digital gateway and data broker between all Flemish government entities, we want to be at the top of our game. Our security ought to be too. For this program we are focusing at first instance on some of our main assets.

Responsible disclosure

Here Technologies

Here Technologies

Transportation and Logistics

HERE Technologies, is a global company that’s rooted in the evolution of digital maps and location technology. We offer a location data and technology platform, that moves people, businesses and cities forward by harnessing the power of location. The HERE platform caters to a variety of tasks related to bringing your own data, map, service, logic and algorithms for location enrichment.

Sustainable

Bug bounty program

View program

Up to €2,000

PDQ bug bounty program

PDQ bug bounty program

Software

At PDQ our mission is to make device management simple, secure, and pretty damn quick. We know how important the security of our products is. We're a bunch of former sysadmins ourselves. Every decision we make revolves around ensuring our products are safe to use for managing your devices, which is why we have a bug bounty program. It’s a true win-win: We improve the security of our products, and you reap the rewards.

Bug bounty program

View program

€50 – €3,500

BMC

BMC

Business and Professional Services

BMC is number one in connecting professionals

Responsible disclosure

SBB - Swiss Federal Railways

SBB - Swiss Federal Railways

Transportation and Logistics

💥 Christmas Promotion: Double Bounties Under the Tree 🎄🔐 — Dates: 17.11.–14.12.2025 The Swiss Federal Railways (SBB) operates one of the most complex and digitally integrated transportation systems in Europe. Our infrastructure spans mission-critical systems including real-time scheduling, ticketing, passenger and freight information. These systems are supported by a diverse set of platforms, APIs, mobile and web applications, and cloud-native services. To ensure the resilience and integrity of our digital ecosystem, we are operating a Bug Bounty program aimed at identifying and mitigating security vulnerabilities before they can be exploited. We invite ethical hackers and security researchers to rigorously test our systems within a defined scope and under responsible disclosure guidelines. Program Objectives: Identify vulnerabilities that could compromise the confidentiality, integrity, or availability of SBB systems or customer data. Validate the robustness of authentication, authorization, and session management mechanisms. Detect insecure configurations, exposed services, or flawed implementations in APIs, web/mobile apps, and backend systems. Strengthen the security posture of our cloud infrastructure. Why Participate? Contribute to the security of critical swiss infrastructure Collaborate with a transparent and responsive security team Receive recognition and monetary rewards based on impact and severity

Bug bounty program

View program

€25 – €6,666

KU Leuven Responsible Disclosure Program

KU Leuven Responsible Disclosure Program

Education

At KU Leuven, we are committed to maintaining high standards of security for our systems and user data. We value the research and expertise of security researchers and ethical hackers who help us identify potential vulnerabilities before they can be exploited. Therefore, we would like to invite you to help us in this effort. Our Responsible Disclosure Program allows working closely with security researchers to identify vulnerabilities. By participating in our program, you are helping us maintain the security and integrity of our systems, ensuring a safer experience for all. KU Leuven appreciates the effort and commitment of all contributors, as long as the vulnerability is within scope, is detected without intrusive testing, and follows the disclosure guidelines. Thank you for your contribution to our security! Note: We may award a bonus if we determine that a serious vulnerability has been discovered and the quality of the report meets our standards for thoroughness and clarity. Recent Bonus Awards: - 2022: €2000 - 2023: €2500

Responsible disclosure

DataCamp

DataCamp

Education

DataCamp’s mission is to democratize data skills for everyone. Companies and teams of every size use DataCamp to close their data skill gaps and make better data-driven decisions. Data science and analytics are rapidly shaping every aspect of our lives and our businesses. There is incredible power in data—but only if you know what to do with it. DataCamp teaches 1,600+ companies and 7 million individuals from 180+ countries the skills they need to work with data in the real world.

Bug bounty program

View program

€25 – €1,500

Lansweeper Bug Bounty Program

Lansweeper Bug Bounty Program

Software

Lansweeper is an IT asset management software provider helping businesses better understand, manage and protect their IT devices and network. Lansweeper helps customers minimize risks and optimize their IT assets by providing actionable insight into their IT infrastructure at all times, offering trustworthy, valuable, and accurate insights about the state of users, devices, and software.

Bug bounty program

View program

€50 – €6,000

Water-Link

Water-Link

Energy Utilities and Waste

All life needs water. Both people, their company and their environment must at all times have water in the right quantity, of the right quality, at the right time. This water must be supplied within the safety of well-thought-out infrastructures for supply and discharge of water. Water-link wants to inspire everyone to fully tap into the strengths of water. Water-link is a Flemish public organisation that directly or indirecty provides drink water to more than 3 million people.

Bug bounty program

View program

€50 – €5,000

Intergamma

Intergamma

Retail

Intergamma is the biggest DIY retailer of The Netherlands and Belgium with three brands: GAMMA Nederland, GAMMA België, and KARWEI. We have almost 400 DIY stores and operate three eCommerce websites. Our strategy is to be the best omnichannel retailer of the Netherlands and Belgium. This means offline and online are converging, and eCommerce is a growth market. Therefore a secure platform is paramount. For more information on our organization please visit https://www.intergamma.nl/

Bug bounty program

View program

€50 – €5,500

VRT

VRT

Media and Entertainment

Flemish Radio and Television Broadcasting Organization bugbounty program

Bug bounty program

View program

€100 – €2,000

Het Laatste Nieuws

Het Laatste Nieuws

Media and Entertainment

HLN.be is the number one news site in Flanders. 24/7 news with a focus on current events, sports and entertainment. The editors know how to keep their finger on the pulse at all times: on average every 4 minutes a new article appears on the news site. Readers consume their news more and more fragmented through their social media, so it is important for HLN to stay top of mind with its own app.

Bug bounty program

View program

€25 – €2,200