Bug Bounty Programs

Below is a list of public bug bounty programs. Through a bug bounty program, companies can tap into a global network of ethical hackers who continuously test a wide range of digital assets within the defined scope.

Bug bounty programs reward ethical hackers with financial incentives when valid vulnerabilities are discovered.

Industry

Program type

Sort by

Search

Water-Link

Water-Link

Energy Utilities and Waste

All life needs water. Both people, their company and their environment must at all times have water in the right quantity, of the right quality, at the right time. This water must be supplied within the safety of well-thought-out infrastructures for supply and discharge of water. Water-link wants to inspire everyone to fully tap into the strengths of water. Water-link is a Flemish public organisation that directly or indirecty provides drink water to more than 3 million people.

Bug bounty program

€50 – €5,000

Humo

Humo

Media and Entertainment

Humo brings high-profile cover stories and revealing interviews and files. And that with a characteristic approach: reliable information, a critical attitude and a sense of humor and self-relativity. The reader is treated every week on articles about television, society, sports, culture and pop, sharp columns and quirky discussions of TV programs, books, films and music.

Bug bounty program

€25 – €2,200

Nexuzhealth

Nexuzhealth

Hospitals and Healthcare

Website + Android Apps + iOS Apps Android Apps KWS Companion The application is only to be used by doctors and no logon information will be given. mynexuz CPV The application is only to be used by personnel of UZ Leuven responsible for transport of patients and no logon information will be given. mynexuzhealth app This application is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. iOS Apps KWS Companion The application is only to be used by doctors and no logon information will be given. Website mynexuzhealth website This website is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. In order to be able to logon to the mynexuzhealth website and app, an ethical hacker will need to request one or more logon credentials via the platform. You can request this information via support (support@intigriti.be). The information they will receive is - A user ID of 8 numbers - A PIN code of 4 numbers - A QRCode

Sustainable

Bug bounty program

Up to €4,000

De Lijn

De Lijn

Transportation and Logistics

De Lijn is the Flemish public transportation company dedicated to giving their customers a comfortable and quick ride. Due the fact that we use the latest IT equipment and servers is our security ought to be at the top of our game. For this program we are putting the focus at our web clients, APIs and of course the mobile application.

Responsible disclosure

Altera

Altera

Manufacturing Consumer

Altera is a leading global semiconductor company known for its innovation in programmable logic devices (PLDs), including field-programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), and related software tools.

Bug bounty program

$500 – $30,000

Sqills

Sqills

Transportation and Logistics

Sqills provides the leading inventory, reservation, and ticketing system for the bus and rail industry – S3 Passenger. At Sqills we are on a constant journey of innovation, discovery and global market leadership. Our corporate website provides general information about Sqills.

Sustainable

Bug bounty program

Up to €2,500

Het Laatste Nieuws

Het Laatste Nieuws

Media and Entertainment

HLN.be is the number one news site in Flanders. 24/7 news with a focus on current events, sports and entertainment. The editors know how to keep their finger on the pulse at all times: on average every 4 minutes a new article appears on the news site. Readers consume their news more and more fragmented through their social media, so it is important for HLN to stay top of mind with its own app.

Bug bounty program

€25 – €2,200

Mobile Vikings

Mobile Vikings

Telecommunications

True Vikings never entered the battlefield without their helmets. And we believe a secure environment, just like free access to open communication, is a worldwide human right. But even the best Viking Drakkars may sometimes encounter vulnerabilities. Brave sailors who discover leaks should be honored - not executed. Together with you and our broad community, we want to create a secure and safe environment for everyone.

Bug bounty program

Up to €5,000

ING Responsible Disclosure

ING Responsible Disclosure

Financial Services and Insurance

Responsible Disclosure indicates ING’s continued commitment to improve its security posture. As part of this process, we work closely with security researchers to identify and report vulnerabilities they find within our systems. ING appreciates security researchers efforts in reporting vulnerabilities on its systems as long as the discovered vulnerability is in scope, detected without the use of intrusive testing techniques, and follows the disclosure guidelines below:

Responsible disclosure

Twago

Twago

Business and Professional Services

twago operates itprojects.talent-community.com talents can sign up, join pools and apply for jobs or projects.

Responsible disclosure

HRS Group VDP

HRS Group VDP

Leisure and Hospitality

As a pioneering force in the business travel sector, our company has redefined the landscape of corporate lodging and travel management through our innovative Lodging-As-A-Service platform. We facilitate seamless and secure experiences in lodging procurement, workspace management, and financial transactions for our global clientele. In an era marked by rapid technological advancements and stringent data protection standards, our commitment to maintaining robust information security is not only a regulatory mandate but a cornerstone of our customer trust and business excellence. Our purpose is to revolutionize the business travel experience through our Lodging-As-A-Service platform, providing seamless, secure, and efficient lodging management, workspace solutions, and payment processing for businesses operating globally.

Responsible disclosure

RGF BE - VDP

RGF BE - VDP

Business and Professional Services

RGF Staffing Belgium is part of global player RGF Staffing, one of the world's largest HR services providers, with activities in Australia, Asia, Europe and North America. With a focus on digital platforms, we allow our candidates & customers using selfservice solutions we provide. As an HR company, a lot of PII-data is managed internally. We want to be an example within the market to guarantee the confidentiality of our data, following the highest information security & privacy standards.

Responsible disclosure

Say Technologies Bug Bounty Program

Say Technologies Bug Bounty Program

Financial Services and Insurance

Say unlocks the power of investor communications by working with broker-dealers to connect shareholders with the public companies they invest in.

Bug bounty program

Up to $10,000

Digitaal Vlaanderen

Digitaal Vlaanderen

Public Services

"Digitaal Vlaanderen" is the IT and digital transformation departement within the Flanders’ governmental IT. Positioned as the digital gateway and data broker between all Flemish government entities, we want to be at the top of our game. Our security ought to be too. For this program we are focusing at first instance on some of our main assets.

Responsible disclosure

Libelle

Libelle

Media and Entertainment

Libelle.nl is the online platform for everything women want to know, from personal stories, the latest news about health & psyche to household tips and trends & videos that you should not miss.

Bug bounty program

€25 – €2,200

Skoda Auto Bug Bounty Program

Skoda Auto Bug Bounty Program

Manufacturing Consumer

This Bug Bounty program is an official and first program run by Škoda Auto a.s. It is focused on the newest version of MyŠkoda mobile application available for iOS and Android. We appreciate the possibility to work with you either remotely or by joining us at the factory and testing the app within our cars! In advance, we thank you for your time and invite you to step into the era of a proactive approach to cyber security together! Škoda Auto a.s.

Bug bounty program

€200 – €5,000

Het Parool

Het Parool

Media and Entertainment

Het Parool is a Dutch regional newspaper that started in the Second World War as a social-democratic tinted resistance newspaper.

Bug bounty program

€25 – €2,200

KU Leuven Responsible Disclosure Program

KU Leuven Responsible Disclosure Program

Education

At KU Leuven, we are committed to maintaining high standards of security for our systems and user data. We value the research and expertise of security researchers and ethical hackers who help us identify potential vulnerabilities before they can be exploited. Therefore, we would like to invite you to help us in this effort. Our Responsible Disclosure Program allows working closely with security researchers to identify vulnerabilities. By participating in our program, you are helping us maintain the security and integrity of our systems, ensuring a safer experience for all. KU Leuven appreciates the effort and commitment of all contributors, as long as the vulnerability is within scope, is detected without intrusive testing, and follows the disclosure guidelines. Thank you for your contribution to our security! Note: We may award a bonus if we determine that a serious vulnerability has been discovered and the quality of the report meets our standards for thoroughness and clarity. Recent Bonus Awards: - 2022: €2000 - 2023: €2500

Responsible disclosure

Algemeen Dagblad

Algemeen Dagblad

Media and Entertainment

With around 900 editors Algemeen Dagblad (AD) has become the largest journalistic organization in the Netherlands, offering both national and extensive regional news coverage.

Bug bounty program

€25 – €2,200

Uphold

Uphold

Financial Services and Insurance

Uphold is a global digital financial platform that enables users to buy, sell, and trade a wide range of assets, including cryptocurrencies, traditional fiat currencies, and precious metals. Operating in 140+ countries and supporting 300+ assets, Uphold provides secure multi-asset trading, instant transactions, and enterprise financial solutions. As a blockchain business, trust and security are fundamental to our success. Our reputation and brand image depend on maintaining the highest security standards, which is why security is a top priority at Uphold. This bug bounty program is a key part of our commitment to proactively identifying and mitigating security risks before they can impact our users or financial systems. As a researcher, you will be analyzing Uphold’s web applications, APIs, and mobile platforms, which facilitate multi-asset trading, financial transactions, and account management. Your contributions will help protect user funds, ensure transaction integrity, and enhance authentication security in a highly regulated financial environment. Review the program scope, rules of engagement, and testing guidelines carefully before submitting a report. We reward well-documented, high-impact security findings that strengthen the safety of our platform and uphold the trust of our users.

Bug bounty program

Up to €6,000

Azena

Azena

Manufacturing Consumer

We are an award-winning German startup with locations in Munich, Eindhoven and Pittsburgh. We are 100% funded by the Bosch Group. Our goal is to be the leading open platform and marketplace for smart security and safety solutions. The platform we offer is based on a camera operating system that powers cameras from various manufacturers on the market. It connects to our Application Store where leading video analytics development companies offer cutting-edge apps.

Responsible disclosure

DHL Group Vulnerability Disclosure Program

DHL Group Vulnerability Disclosure Program

Transportation and Logistics

DHL Group is a global logistics company providing services in express delivery, freight transportation, supply chain management, e-commerce solutions, as well as postal and parcel services. As part of our commitment to security, we invite researchers to participate in our vulnerability disclosure program, helping us ensure protection of our systems. Join us in identifying and reporting potential vulnerabilities to maintain the highest standards of security for our customers and partners.

Responsible disclosure

SBB - Swiss Federal Railways

SBB - Swiss Federal Railways

Transportation and Logistics

SBB operates Switzerland's national railway network, providing passenger and freight transportation services. Welcome to our public Bug Bounty program. We are specifically looking for: * Leaking PII Data (customer) * Data manipulation High performance researcher may be invited to our private programs!

Bug bounty program

€25 – €5,000

Oda

Oda

Retail

Oda.com and Mathem.se is the leading online grocery storesin Norway and Sweden.

Bug bounty program

€75 – €4,000