# disclose/bug-bounty-platforms

A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.

Repository: https://github.com/disclose/bug-bounty-platforms
Canonical: https://ross.abutalabs.com/products/bug-bounty-platforms
Homepage: https://disclose.io/platforms/
Language: Python
License: CC0-1.0
License Family: permissive
Last push: 2026-08-11T02:39:38+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 97, release rhythm 35, longevity 100
- inputs: {"age_days": 1866, "days_push": 22, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1101, forks 216 (observed 2026-08-28T04:03:35.678147+00:00)

## What it is
A community-maintained, CC0-licensed catalog of every known bug bounty platform, vulnerability disclosure platform, and crowdsourced security platform active on the Internet, with structured metadata per platform. It is part of the disclose.io project and powers the browsable directory at disclose.io/platforms.

## Use cases
- find bug bounty platforms to run a program on
- list of vulnerability disclosure platforms
- where can I report a vulnerability to a government
- compare crowdsourced security platforms with leaderboards
- find web3 and AI security bounty platforms
- research data on bug bounty ecosystem
- find official channels to disclose a security bug

## When to choose
- you need an open, structured, regularly updated dataset of disclosure platforms
- you want CC0 data you can freely reuse in tools or research
- you need coverage of government VDPs and niche ecosystem platforms

## When to avoid
- you need a platform to actually host your bounty program rather than a directory of them
- you need program-level scope details rather than platform-level info (see directory.disclose.io)
- you need real-time program status guarantees

## Facets
- artifact type: dataset
- maturity: active
- function: security, developer-tools, documentation
- domain: security, awesome-lists, developer-tools
- platform: cli, cross-platform
- tags: bug-bounty, vulnerability-disclosure, crowdsourced-security, curated-list, open-data, disclose-io, safe-harbor, web-server

## Member repositories
- disclose/bug-bounty-platforms (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:35.678147+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:45:42.303088+00:00, confidence not recorded.
  - readme: https://github.com/disclose/bug-bounty-platforms (fetched 2026-08-28T04:03:35.678147+00:00, sha 80b394102949)
  - homepage: https://disclose.io/platforms/ (fetched 2026-08-29T12:48:58.719179+00:00, sha a3c0cb2a0749)
  - site_page: https://disclose.io/docs (fetched 2026-08-29T12:48:58.728662+00:00, sha 3f885788d678)
  - site_page: https://disclose.io/ (fetched 2026-08-29T12:48:58.730463+00:00, sha d0ec954f9388)
- Data as of 2026-08-30T08:39:29.467469+00:00.
