● Bug bounty · Vulnerability disclosure

Every serious finding
deserves a proper hearing.

RootBounty is where companies publish what they want tested and independent researchers report what they find — in a structured format, under clear rules, with every account behind two-factor authentication.

For researchers

Hunt, report, get credited.

  1. Read a program’s guidelines and scope before you touch anything.
  2. Submit a report with CWE, a CVSS 4.0 vector and a reproducible proof of concept.
  3. Follow triage in the open: every resolved finding lands on the program’s public hacktivity.
  4. Ten certified findings unlock posts and stories in the community.
For companies

Be tested by people who care.

  1. Register your organisation. Our team verifies it before anything goes live.
  2. Choose a paid bug bounty or a vulnerability disclosure program (VDP).
  3. Publish guidelines and scope; each program is reviewed before launch.
  4. Triage reports, talk to researchers and pay bounties from one inbox.
The report

One format. Written in Markdown.

Every submission has the same eight parts, so triage starts from facts instead of follow-up questions.

01 Title
What is broken, where, and what it allows.
02 CWE
The weakness class, from MITRE’s catalogue.
03 CVSS 4.0
A scored vector, calculated as you pick the metrics.
04 Description
Where the flaw lives and why it happens. Markdown.
05 Impact
What an attacker gains and who is affected.
06 Environment
Versions, accounts, browser, configuration.
07 Proof of concept
Steps anyone on the team can reproduce.
08 Attachments
Screenshots, captures, scripts — scanned and private.
Security

Two factors for everyone

An authenticator app or an emailed code after every password. Recovery codes for the day you lose your phone.

Review

Companies are verified

Company accounts and every program are checked by the RootBounty team before they reach researchers.

Disclosure

Public, when it’s safe

Hacktivity shows who found what and its status. Details stay private until a report is closed.