Rooted
Bug bounty board

Pick a target, stay in scope, ship a report worth points.

Programs are presented like a hunting board: clear surface, clear rules, clear intake. Rooted rewards confirmed reports with platform points by severity, then writes the result to your public ledger.

Programs
27
Report reward
+100-1500
Safe harbor
4
Platform rewards

A confirmed bug is the fastest way up the ladder.

Submit here, we verify, and points are released the moment the finding is confirmed. Reports are the only track with no ceiling — the one kind of proof that cannot be bought, ground out or generated.

low
+100
medium
+300
high
+700
critical
+1500
Web appsAPIsCloudMobileIdentityReport scoring
AA

Aafje

Full

geldersevallei.nl / coordinated security research

92signal

Healthcare-adjacent reports must stay on public web surfaces and test accounts. Do not access patient data, attempt persistence, disrupt care systems or test physical facilities.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
AA

Aarts

Full

aarts.info / coordinated security research

92signal

Research is limited to Aarts-owned public web properties, login forms, exposed APIs and configuration issues visible without intrusive scanning. No social engineering, spam or data extraction.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
AC

Aarts CC

Full

aarts.cc / coordinated security research

92signal

Research should stay on owned web applications, account recovery, public APIs and access-control boundaries. Do not perform destructive tests or access data that is not yours.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
AC

Aarts Cloud

Full

aarts.cloud / coordinated security research

92signal

Target cloud control panels, account flows, DNS and hosting-adjacent APIs owned by Aarts Cloud. Keep tests non-destructive and prove impact with synthetic accounts.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
AA

Aalten

Partial

aalten.nl / coordinated security research

70signal

Municipal digital services, public forms, authentication flows and exposed APIs are the practical focus. Avoid service disruption, citizen data access, phishing and physical testing.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is non-hostile language, but confirm the scope before you test.
Disclosure
The timeline may be defined by the policy, or not stated at all.
View programSubmit reportPolicyhttps://www.aalten.nl/digitale-kwetsbaarheid-melden
A2

A2x

Partial

a2x.io / coordinated security research

68signal

Test public application and API surfaces that handle accounting exports, integrations and tenant-level authorization. Keep activity to owned accounts and avoid bulk actions against connected platforms.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is non-hostile language, but confirm the scope before you test.
Disclosure
The timeline may be defined by the policy, or not stated at all.
AA

Aal Army

Partial

aal.army / coordinated security research

67signal

Focus on public web routes, contact forms, auth/session issues and exposed files on Aal-owned domains. Avoid automated high-volume scanning and any attempt to access private records.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is non-hostile language, but confirm the scope before you test.
Disclosure
The timeline may be defined by the policy, or not stated at all.
AS

Aaron Schaal

Basic

aaron-schaal.de / coordinated security research

48signal

Focus on public portfolio/application surfaces, contact forms, session handling and exposed configuration. Keep testing lightweight and do not attack third-party services.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicypostmaster@aaron-schaal.de
2G

2GoSoftware

Basic

your.software / coordinated security research

47signal

Focus on owned web applications, customer account flows, session handling, exposed files and API authorization. Keep testing low volume and limited to your own accounts.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicytechniek@2gosoftware.nl
AA

AASV

Basic

aasv.org / coordinated security research

47signal

Focus on public membership web surfaces, account flows, forms and exposed files. Do not scrape member data, spam forms or test payment abuse.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
2B

2BrightSparks

Basic

2brightsparks.com / coordinated security research

45signal

Research should focus on public product websites, download/update flows, account pages and exposed configuration. Avoid malware-like payloads, license abuse and destructive testing.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicysecurity@2brightsparks.com
41

411HomeRepair

Basic

411homerepair.com / coordinated security research

45signal

Research is limited to public web pages, forms, authentication/session behavior and obvious data exposure on owned assets. No spam, scraping, phone contact abuse or destructive payloads.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicyabuse@411homerepair.com
50

50plusmatch

Basic

50plusmatch.nl / coordinated security research

45signal

Focus on account registration, profile visibility controls, messaging boundaries and privacy-impacting web flaws using test accounts. Do not contact real users or scrape profiles.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
AA

A1 Agency

Basic

a1.agency / coordinated security research

45signal

Test public agency websites, client intake forms and exposed assets owned by A1 Agency. Do not target customer systems, third-party vendors or production data.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicyhttps://a1.agency/.well-known/security.txt
A1

A11k

Basic

a11k.net / coordinated security research

45signal

Research should stay on public web assets, auth/session handling and exposed configuration. Avoid high-volume scans, phishing, credential stuffing and third-party services.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
A2

A2Group

Basic

a2group.llc / coordinated security research

45signal

Focus on owned websites, login flows, exposed documents and API boundaries. No physical attacks, social engineering, malware, persistence or access to non-public customer data.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
A3

A3Security

Basic

a3security.org / coordinated security research

45signal

Research is limited to A3Security-owned public assets, contact flows and exposed security.txt-linked systems. Avoid disruptive scans and any access to third-party data.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
A5

A5CT

Basic

a5ct.com / coordinated security research

45signal

Focus on public web properties, admin exposure, session issues and configuration mistakes that can be shown safely. Do not brute force, spam or exfiltrate real data.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
AN

AA.net

Basic

aa.net.uk / coordinated security research

45signal

Focus on public customer portal flows, account/session boundaries, exposed configuration and non-destructive network-adjacent findings. Do not disrupt connectivity or customer services.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
AA

AACapacity

Basic

aacapacity.nl / coordinated security research

45signal

Research should cover owned public websites, forms, file exposure and simple access-control bugs. Avoid client environments, email abuse and destructive payloads.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
AB

ABAB

Basic

mijnaaff.nl / coordinated security research

45signal

Test public account flows, form handling, exposed files and tenant authorization using synthetic data only. Do not access financial, payroll or customer records.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
AA

Aapkerala

Basic

aapkerala.org / coordinated security research

45signal

Research should stay on public web pages, forms, session handling and exposed files. Avoid political content abuse, spam, scraping or any disruption to public communications.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicyhttps://aapkerala.org/.well-known/security.txt
AA

Aardbodem

Basic

debasteinijmegen.nl / coordinated security research

45signal

Test only owned public web routes, contact forms, auth/session behavior and exposed files. Avoid high-volume crawling, real user data and third-party infrastructure.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicyjohn.pulles@aardbodem.nl
AA

Aareon

Basic

aareon.com / coordinated security research

45signal

Focus on public websites, customer portal authentication, API authorization and tenant separation in real-estate software workflows. Use test accounts only and avoid customer data.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
AA

Aarreha

Basic

aarreha.ch / coordinated security research

45signal

Research should focus on public websites, login surfaces, exposed documents and misconfiguration. Do not access sensitive records, disrupt service or test physical security.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
AF

Abakus Fahrschulen

Basic

abakus-fahrschulen.de / coordinated security research

45signal

Focus on booking, contact and public web functionality owned by the organization. Avoid student data, payment abuse, spam and destructive testing.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.
View programSubmit reportPolicyhttps://abakus-fahrschulen.de/.well-known/security.txt
AB

Abax

Basic

abax.com / coordinated security research

45signal

Test public fleet-management web surfaces, login flows, account authorization and API boundaries using accounts you control. Do not access vehicle, location or customer operational data.

Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Disclosure
Not guaranteed. Read the policy before you start.