# Bug Bounty

A program that rewards independent security researchers for finding and responsibly reporting vulnerabilities.

A **bug bounty[↗](/bug-bounty)** program is a formal initiative where an organization invites independent security researchers to find and report vulnerabilities in its software or systems, offering financial rewards based on the severity of what's discovered. It turns responsible disclosure[↗](/responsible-disclosure) into a structured, incentivized process.

Bug bounty programs let organizations tap into a much larger and more diverse pool of researchers than any internal security team could match, often catching flaws that automated scanning or internal testing missed. Platforms like HackerOne and Bugcrowd manage these programs for thousands of companies, handling researcher payouts and coordinating disclosure.
