Understanding Public and Private Bug Bounties and Vulnerability Disclosure Programs
ID: ec6daa68-7568-59e1-9f94-ed2252179989
STIX ID: report--ec6daa68-7568-59e1-9f94-ed2252179989
Feed Name: HackerOne Blog
**Executive summary:** This blog post explains the differences between bug bounty programs and vulnerability disclosure programs (VDPs), how incentives and recognition differ, and the considerations for running public versus private programs (including when to start private to manage submission volume or protect sensitive assets). It advises that organizations may run both types with different scopes and highlights regulatory drivers and practical guidance for choosing the appropriate program model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
