Bug Bounty Programs

Below is a list of public bug bounty programs. Through a bug bounty program, companies can tap into a global network of ethical hackers who continuously test a wide range of digital assets within the defined scope.

Bug bounty programs reward ethical hackers with financial incentives when valid vulnerabilities are discovered.

Industry

Program type

Sort by

Search

Revolut VDP

Revolut VDP

Financial Services and Insurance

Revolut is a financial technology company that offers banking services. It offers accounts featuring currency exchange, debit cards, virtual cards, interest-bearing "vaults", commission-free stock trading, crypto, commodities, and other services to over 60M customers. Please visit our website for more information: www.revolut.com

Responsible disclosure

VTM GO

VTM GO

Media and Entertainment

VTM GO offers a lot of strong Flemish and exclusive international series & films for free. From news and news to the most powerful fiction and reality shows.

Bug bounty program

€25 – €2,200

Citymesh Responsible Vulnerability Disclosure Program

Citymesh Responsible Vulnerability Disclosure Program

Telecommunications

Welcome to the Responsible Vulnerability Disclosure Program of Citymesh. Citymesh is one of the Telecommunication Operators in Belgium. Citymesh helps its customers with the implementation, integration, and maintenance of network infrastructure. Citymesh wants to offer its customers quality connectivity solutions that help them achieve their business goals.

Responsible disclosure

Speakap Responsible Disclosure

Speakap Responsible Disclosure

Business and Professional Services

Since 2010, Speakap has helped more than 400 companies across 120 countries, 42 languages, and many time zones, reach their full potential with more productive employees. With an award-winning, easy-to-use employee app, Speakap empowers company leaders to share the right content with the right people at the right time. Speakap boasts very high adoption rates with users logging in almost 6x a day for 50+ seconds per time.

Responsible disclosure

De Morgen

De Morgen

Media and Entertainment

De Morgen has a broad view of the news with attention to political current affairs, culture and media. The editors are critical, dig deeper and often make the news of the day under the motto more insight, more salmon. De Morgen is aiming for an open-minded audience that is looking for qualitative news coverage, background and interpretation of the news. The newspaper looks young and fresh and has won international prizes with its design.

Bug bounty program

€25 – €2,200

Tempo-Team

Tempo-Team

Business and Professional Services

Tempo-Team offers daily new and varied jobs for every level and field.

Responsible disclosure

DPG Media

DPG Media

Media and Entertainment

DPG Media is a leading media group in Flanders, Netherlands and Denmark that knows how to touch viewers, surfers, readers and listeners with impressive stories, lightning fast news and sparkling entertainment.

Bug bounty program

€25 – €500

BMW Group Automotive

BMW Group Automotive

Manufacturing Consumer

The BMW Group looks forward to working with the security community to find vulnerabilities in order to keep its products and customers safe and secure. We are committed to working with you to verify, reproduce, and respond to legitimate reported vulnerabilities covered by this policy. Within this program bounties can be received by reporting vulnerabilities that are in the scope of program and marked as “Eligible”. Please take note of the current scope outlined below.

Bug bounty program

€100 – €15,000

Water-Link

Water-Link

Energy Utilities and Waste

All life needs water. Both people, their company and their environment must at all times have water in the right quantity, of the right quality, at the right time. This water must be supplied within the safety of well-thought-out infrastructures for supply and discharge of water. Water-link wants to inspire everyone to fully tap into the strengths of water. Water-link is a Flemish public organisation that directly or indirecty provides drink water to more than 3 million people.

Bug bounty program

€50 – €5,000

Humo

Humo

Media and Entertainment

Humo brings high-profile cover stories and revealing interviews and files. And that with a characteristic approach: reliable information, a critical attitude and a sense of humor and self-relativity. The reader is treated every week on articles about television, society, sports, culture and pop, sharp columns and quirky discussions of TV programs, books, films and music.

Bug bounty program

€25 – €2,200

Nexuzhealth

Nexuzhealth

Hospitals and Healthcare

Website + Android Apps + iOS Apps Android Apps KWS Companion The application is only to be used by doctors and no logon information will be given. mynexuz CPV The application is only to be used by personnel of UZ Leuven responsible for transport of patients and no logon information will be given. mynexuzhealth app This application is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. iOS Apps KWS Companion The application is only to be used by doctors and no logon information will be given. Website mynexuzhealth website This website is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. In order to be able to logon to the mynexuzhealth website and app, an ethical hacker will need to request one or more logon credentials via the platform. You can request this information via support (support@intigriti.be). The information they will receive is - A user ID of 8 numbers - A PIN code of 4 numbers - A QRCode

Sustainable

Bug bounty program

Up to €4,000

Het Laatste Nieuws

Het Laatste Nieuws

Media and Entertainment

HLN.be is the number one news site in Flanders. 24/7 news with a focus on current events, sports and entertainment. The editors know how to keep their finger on the pulse at all times: on average every 4 minutes a new article appears on the news site. Readers consume their news more and more fragmented through their social media, so it is important for HLN to stay top of mind with its own app.

Bug bounty program

€25 – €2,200

Mobile Vikings

Mobile Vikings

Telecommunications

True Vikings never entered the battlefield without their helmets. And we believe a secure environment, just like free access to open communication, is a worldwide human right. But even the best Viking Drakkars may sometimes encounter vulnerabilities. Brave sailors who discover leaks should be honored - not executed. Together with you and our broad community, we want to create a secure and safe environment for everyone.

Bug bounty program

Up to €5,000

ING Responsible Disclosure

ING Responsible Disclosure

Financial Services and Insurance

Responsible Disclosure indicates ING’s continued commitment to improve its security posture. As part of this process, we work closely with security researchers to identify and report vulnerabilities they find within our systems. ING appreciates security researchers efforts in reporting vulnerabilities on its systems as long as the discovered vulnerability is in scope, detected without the use of intrusive testing techniques, and follows the disclosure guidelines below:

Responsible disclosure

Twago

Twago

Business and Professional Services

twago operates itprojects.talent-community.com talents can sign up, join pools and apply for jobs or projects.

Responsible disclosure

HRS Group VDP

HRS Group VDP

Leisure and Hospitality

As a pioneering force in the business travel sector, our company has redefined the landscape of corporate lodging and travel management through our innovative Lodging-As-A-Service platform. We facilitate seamless and secure experiences in lodging procurement, workspace management, and financial transactions for our global clientele. In an era marked by rapid technological advancements and stringent data protection standards, our commitment to maintaining robust information security is not only a regulatory mandate but a cornerstone of our customer trust and business excellence. Our purpose is to revolutionize the business travel experience through our Lodging-As-A-Service platform, providing seamless, secure, and efficient lodging management, workspace solutions, and payment processing for businesses operating globally.

Responsible disclosure

RGF BE - VDP

RGF BE - VDP

Business and Professional Services

RGF Staffing Belgium is part of global player RGF Staffing, one of the world's largest HR services providers, with activities in Australia, Asia, Europe and North America. With a focus on digital platforms, we allow our candidates & customers using selfservice solutions we provide. As an HR company, a lot of PII-data is managed internally. We want to be an example within the market to guarantee the confidentiality of our data, following the highest information security & privacy standards.

Responsible disclosure

Libelle

Libelle

Media and Entertainment

Libelle.nl is the online platform for everything women want to know, from personal stories, the latest news about health & psyche to household tips and trends & videos that you should not miss.

Bug bounty program

€25 – €2,200

Het Parool

Het Parool

Media and Entertainment

Het Parool is a Dutch regional newspaper that started in the Second World War as a social-democratic tinted resistance newspaper.

Bug bounty program

€25 – €2,200

KU Leuven Responsible Disclosure Program

KU Leuven Responsible Disclosure Program

Education

At KU Leuven, we are committed to maintaining high standards of security for our systems and user data. We value the research and expertise of security researchers and ethical hackers who help us identify potential vulnerabilities before they can be exploited. Therefore, we would like to invite you to help us in this effort. Our Responsible Disclosure Program allows working closely with security researchers to identify vulnerabilities. By participating in our program, you are helping us maintain the security and integrity of our systems, ensuring a safer experience for all. KU Leuven appreciates the effort and commitment of all contributors, as long as the vulnerability is within scope, is detected without intrusive testing, and follows the disclosure guidelines. Thank you for your contribution to our security! Note: We may award a bonus if we determine that a serious vulnerability has been discovered and the quality of the report meets our standards for thoroughness and clarity. Recent Bonus Awards: - 2022: €2000 - 2023: €2500

Responsible disclosure

Algemeen Dagblad

Algemeen Dagblad

Media and Entertainment

With around 900 editors Algemeen Dagblad (AD) has become the largest journalistic organization in the Netherlands, offering both national and extensive regional news coverage.

Bug bounty program

€25 – €2,200

Azena

Azena

Manufacturing Consumer

We are an award-winning German startup with locations in Munich, Eindhoven and Pittsburgh. We are 100% funded by the Bosch Group. Our goal is to be the leading open platform and marketplace for smart security and safety solutions. The platform we offer is based on a camera operating system that powers cameras from various manufacturers on the market. It connects to our Application Store where leading video analytics development companies offer cutting-edge apps.

Responsible disclosure

DHL Group Vulnerability Disclosure Program

DHL Group Vulnerability Disclosure Program

Transportation and Logistics

DHL Group is a global logistics company providing services in express delivery, freight transportation, supply chain management, e-commerce solutions, as well as postal and parcel services. As part of our commitment to security, we invite researchers to participate in our vulnerability disclosure program, helping us ensure protection of our systems. Join us in identifying and reporting potential vulnerabilities to maintain the highest standards of security for our customers and partners.

Responsible disclosure

SBB - Swiss Federal Railways

SBB - Swiss Federal Railways

Transportation and Logistics

The Swiss Federal Railways (SBB) operates one of the most complex and digitally integrated transportation systems in Europe. Our infrastructure spans mission-critical systems including real-time scheduling, ticketing, passenger and freight information. These systems are supported by a diverse set of platforms, APIs, mobile and web applications, and cloud-native services. To ensure the resilience and integrity of our digital ecosystem, we are operating a Bug Bounty program aimed at identifying and mitigating security vulnerabilities before they can be exploited. We invite ethical hackers and security researchers to rigorously test our systems within a defined scope and under responsible disclosure guidelines. Program Objectives: Identify vulnerabilities that could compromise the confidentiality, integrity, or availability of SBB systems or customer data. Validate the robustness of authentication, authorization, and session management mechanisms. Detect insecure configurations, exposed services, or flawed implementations in APIs, web/mobile apps, and backend systems. Strengthen the security posture of our cloud infrastructure. Why Participate? Contribute to the security of critical swiss infrastructure Collaborate with a transparent and responsive security team Receive recognition and monetary rewards based on impact and severity

Bug bounty program

€25 – €5,000