Parameter

What is Bug bounty / VDP?

Bug bounty and vulnerability disclosure programs

The difference between a bug bounty and a VDP, how each program runs, where they fall short, and how they fit next to pentesting.

01Introduction

Outside researchers will find bugs in your software whether you invite them or not. A disclosure program decides whether they report those bugs to you, and a bounty decides whether they're paid to look.

02What is Bug bounty / VDP?

A vulnerability disclosure program (VDP) is a public policy that tells researchers how to report security issues, promises not to pursue good-faith reporters legally, and commits to a response. It is often published through a security.txt file (RFC 9116) and follows ISO/IEC 29147 and 30111.

A bug bounty adds payment: researchers earn a reward for valid, in-scope findings, usually scaled by severity. Programs are commonly run through platforms such as HackerOne and Bugcrowd. US federal agencies have been required to run a VDP since CISA's Binding Operational Directive 20-01.

03How Bug bounty / VDP works

Both programs share the same intake pipeline.

  1. 1.

    Publish scope and rules

    Define which assets are in scope, what testing is allowed, safe harbor terms and, for a bounty, the reward table.

  2. 2.

    Triage reports

    Deduplicate submissions, reproduce them and rate severity, often with CVSS.

  3. 3.

    Remediate and reward

    Route valid issues to engineering, pay the bounty and confirm the fix.

  4. 4.

    Disclose

    Agree on a disclosure date with the researcher and, where appropriate, publish an advisory.

04Threats and risks

Crowdsourcing has real limits as a primary control.

  • Noise

    A large share of submissions are duplicates, out of scope or invalid, and each one costs triage time.

  • Uneven coverage

    Researchers hunt where payouts are easy; authenticated flows and deep logic get less attention.

  • No audit evidence

    A bounty doesn't produce the scoped, dated report that SOC 2 or PCI DSS auditors ask for.

  • Unpredictable cost

    Payouts and platform fees vary with how many bugs are found.

05How Parameter helps

Parameter finds and proves bugs before a researcher does, so the program receives fewer and harder reports.

  • Systematic coverage

    The pentesting agents test every role, endpoint and workflow on each release, not just the lucrative ones.

  • Verified before reporting

    Every finding comes with a working exploit, which removes the triage burden.

  • Side by side

    Compare the models on the HackerOne alternative and Bugcrowd alternative pages.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your Bug bounty / VDP program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.