Custom bounties allow you to reward submissions with a flexible payout amount instead of being limited to predefined bounty tiers. This gives you additional control when standard severity-based rewards do not align with your internal scoring mechanisms, policies, considering other relevant factors.
π Subscriptions: Premium, Enterprise
Set a custom bounty amount
βοΈRoles: Company Admin, Program Admin, Program Editor
You can set a custom bounty amount when resolving a submission.
Open a submission that is ready to be accepted.
Click Accept.
Enter a custom bounty amount.
Enter the desired reward value between 0 and 500,000.
Confirm the action to apply the custom bounty.
The custom amount is applied directly to the submission and overrides the suggested bounty amount, which is calculated based on the severity or CVSS score and the bounty tier of the asset.
π‘Note: Once a custom bounty has been set, changing the severity or CVSS score will no longer automatically update the bounty amount, since the reward has been manually adjusted.
After a custom bounty is set, you can still adjust the bounty like any other reward by changing the submission status to Pending, as long as the payout has not yet been processed.
You can track all bounty modifications in the submission activity log, in PDF exports, and through the external API.
β
Best practices
Clearly document your custom bounty calculation methods or internal policies, especially since researchers are accustomed to rewards based on severity or CVSS scores. Include this information in the Reward policy section under the Bounties area of your program to ensure transparency.
Use the optional message to the researcher when setting a custom bounty to explain how the reward was determined. This helps set expectations and builds trust.
Consider using a standardized message template that refers researchers to your Reward policy section, while allowing room for personalization when needed.
Apply custom bounties consistently across similar submissions to maintain fairness and predictability for researchers.
