Bugrater Crew
“Love the fam! we support the bug hunter community by providing a place to facilitate open coms about the industry”
Attack surface intelligence
BugRater reads the whole bug bounty field as a live market: which programs are heating up as reports pour in, which are under-hunted while intake is still healthy, and what their surface is exposing right now. Stop guessing where to spend the night.
Signal intelligence
We enumerate each program's surface and flag what deserves a second look. Not findings, leads: the exposed thing worth the first hour of your night.
Exposed configs and secrets
Config files, env dumps, and keys reachable on the live surface.
Staging and pre-prod high
The softer builds behind a program, where controls slip.
Login and admin panels
Auth surfaces and consoles worth a closer look.
Live-probed hosts
Across 3,049 subdomains enumerated so far.
Freshest exposures
Hosts unlock with a subscription. See what's inside →
Three ways in
The board
Scan it in your browser
The full rated board, every program's drill-down, and the live exposure feed. Where to hunt tonight, no setup.
Open the board →The API
Pull it into your recon
Ten endpoints, metered by the call, with $200 of usage included every month. Wire the intel into your own tooling.
Read the API docs →Daily digests
Wake up to your shortlist
A quiz picks your programs and the asset types you care about, then a personalized brief lands each morning. Preferences rolling out.
Included · see the offer →The public record
Every vendor security release names the researchers behind it. We index every line, CVEs and the recognitions that carry no CVE at all, with an identifier you can quote.
From the people who worked them
Every review answers the same questions: how many reports, what was paid, how long the first reply took, whether they would go back. So two programs can be compared instead of merely described.
“Love the fam! we support the bug hunter community by providing a place to facilitate open coms about the industry”
“Triage overall left me relatively disappointed, but by equal measures, relived. I reported a remote code execution to this program in May, the H1 analyst team reviewed and downgraded the severity from critical to high on account of double-counting the UI:R co…”
“Reporting to the NASA Vulnerability Disclosure Program on Bugcrowd is an incredibly rewarding experience. The security team is highly professional, and they genuinely value the efforts of the community in keeping their massive infrastructure secure. Receiving…”
“Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status…”
“Majorly I participate in Google VRP mostly as a casual and daily user rather than doing dedicated, aggressive bug hunting. Most of the security flaws I have reported came from normal day to day usage of Google products rather than active deep scanning. The sh…”
“I've spent a significant amount of time testing Personio and interacting with their security team through responsible disclosure. Overall, the experience has been positive. The security team is professional, communicates clearly, and is willing to discuss tec…”
“As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs a…”
“NASA VDP is triaged by Bugcrowd team before handing it over to NASA officials for confirmation. I noticed that Bugcrowd's bot such as teapot_bugcrowd tends to mark report submissions as N/A. This was the case with my accepted report that earned me the NASA's …”
Where credit is recorded in public
When a vendor ships a security release it names the researchers behind it: CVEs and additional recognitions alike. We record every line, CVE or not, with a BugRater ID you can quote. If your name is here, the credit is yours to claim: instantly, and durable on your profile.
New · a native Mac app
Research Tracker runs on your Mac. Your agents report findings to it over a local API, and each one is appended to a BugRater project: shared, attributed, append-only. On an encrypted project the content is sealed on your machine before it is sent, so a finding becomes evidence of who established what, without handing us the finding itself.
Write one
Every researcher is carrying a set of rules nobody wrote down for them. This program disputes valid scope. That one downgrades every severity. This one is slow but pays above market and will actually argue the technical detail with you. Each of those was paid for with a month of work, or a report that died, or a duplicate filed six hours late.
Writing it down is what turns a private scar into something the next person reads before they spend the month. And because every review answers the same questions, yours does not sit alone as an anecdote. It moves the program's grade, its median response time, and the strengths and concerns other researchers see first.
Post under your handle or anonymously. Either way it is account-backed, so a review here costs something to write. That is exactly why it is worth reading.
What happens after you post
14 strengths and 14 concerns, the same list on every program. That is what makes them countable rather than quotable.
Who builds this
That single fact is the whole design. A platform earns its money from the companies it hosts, so the moment a researcher's account of a program is inconvenient, the platform has a customer to keep and you do not. We have no such customer.
This is built by someone who submits reports and waits, who has had a month's work closed informative in an hour, and who has watched a duplicate land six hours ahead of him. Every decision beside this was made by someone who expected to be on the receiving end of it.
Security researcher · builds and maintains BugRater
3 published CVEs · reviews on this site under the same handle →
A company cannot delete a review of itself
Claiming a profile buys one thing: a reply, published under the company's name, beneath the review it answers. There is no takedown path, and moderators cannot post in a company's voice either.
We do not hold your unpatched findings
Private report detail is encrypted at rest with a key that is not in the database. A collaboration project goes further: keys are generated in your browser and we hold ciphertext we have no way to open. Not “will not”: cannot.
Your report cannot be traced back to you through the numbers
No detail is named in an aggregate until 3
reports from 2 different researchers say it. Below that
floor it folds into an unnamed residual, because a statistic of one is a disclosure wearing a
percentage sign.
Claiming your own credit does not wait on us
The vendor printed your name in their own advisory. A moderator standing between you and that adds no truth to it. Only delay. Claims are instant; disputes are the exception we review, not the rule.
The brief
Occasional briefs built from real researcher reviews: which programs are worth your time, what the numbers say, and the pieces we publish. No spam.