How to launch a private bug bounty program: a step-by-step guide
By Kike Gandia · Co-Founder & CEO, OSCP
A private bug bounty program is the safest entry point into the bug bounty ecosystem for most companies. Instead of opening the platform to thousands of researchers at once, you invite a select, controlled group you already know. This guide covers every step to correctly launch a private program, from defining scope to managing your first reports.
Private vs public bug bounty: what's the difference
In a private program, only the researchers you invite can participate. In a public one, any researcher registered on the platform can test. Private is more controllable; public generates more volume and diversity of findings.
Start with a private program if you don't have experience managing reports, your security team is small, or you don't have budget for large-scale bounties. Move to public once you've handled at least 50-100 private reports and built robust triage processes.
Step 1: defining the scope
Scope is the most important part of the program. Clearly define what's in-scope and what's out-of-scope.
Include: an explicit list of domains, applications, APIs and IP ranges; the types of vulnerabilities accepted; rules of engagement (no DoS, no exfiltration of real data).
Exclude: third-party infrastructure, vulnerabilities with no demonstrable impact, social engineering of employees, physical attacks. The more explicit you are, the fewer useless reports you'll receive.
Step 2: setting up the bounty table
Indicative bounty ranges by severity:
- Critical (CVSS 9.0+): €2,000-10,000+
- High (CVSS 7.0-8.9): €1,000-3,000
- Medium (CVSS 4.0-6.9): €300-1,000
- Low (CVSS <4.0): €100-300 or recognition without payment
If you don't have a budget for bounties, consider starting with a VDP without financial rewards. Many researchers participate if the hall of fame and public recognition are genuine.
Step 3: choosing the platform and researchers
HackerOne and Intigriti have large pools of verified researchers you can invite to your private program. YesWeHack is a good option for European companies. Bugcrowd has a strong community in the English-speaking market.
Platforms let you invite researchers with specific profiles (track record in similar technologies, platform reputation). Start with 5-20 trusted researchers before expanding.
Step 4: internal preparation before launch
The most common mistake is launching the program without having the internal process ready. Define who receives the reports, who validates them, who makes severity decisions, and how much time each step gets. Without this process, the program will generate chaos instead of security.
FAQ
How much does it cost to launch a private bug bounty program?
The main costs are: the platform fee (varies by provider, from free up to thousands per month for enterprise platforms), bounties paid to researchers (highly variable based on findings), and the internal or external cost of report management. A small, well-managed private program can start with a very limited budget if the scope and process are right.
How long does a private bug bounty program take to produce results?
The first reports usually arrive within the first few days. The most interesting findings appear in the first 4-8 weeks, once researchers have had time to do a deep analysis of the scope. Programs with no findings after 3 months usually point to a scope problem (too restrictive) or a bounty problem (not competitive enough).
Do I need an internal security team to manage a bug bounty?
Not necessarily. Many companies outsource report management to specialized triage services that act as a middle layer between researchers and the development team. This dramatically reduces internal workload and improves the quality of responses to researchers.
Related service
Related content
Sources
- OWASP Web Security Testing Guide (WSTG) — the official reference methodology
- INCIBE — Pentesting and security testing guide for businesses
We help you launch and manage your first private bug bounty program