Skip to main content

Program confidentiality levels

Updated today

Program confidentiality defines who can discover your program and who is allowed to participate. Choosing the right confidentiality level helps you control visibility, manage risk, and gradually scale researcher access as your program matures.

On the Intigriti platform, confidentiality settings are configured per program and determine how researchers can find, view, and interact with your program.

Manage program confidentiality

Roles: Company Admin, Program Admin

You can manage the confidentiality level of your program from the program settings.

  1. Open your program.

  2. Go to More > Settings.

  3. Select the desired confidentiality level.

Changes to confidentiality take effect immediately and impact how your program is discovered and accessed by researchers.

Confidentiality levels

Invite only

Invitation-only programs are accessible only to researchers you explicitly invite. You typically start with a small group of around 15 to 20 researchers and gradually expand access over time. This approach allows you to validate scope, processes, and reward structure while exposing your assets to a limited and trusted set of skills. As you invite more researchers with different expertise, the likelihood of uncovering diverse vulnerabilities increases.

Application

In application programs, all registered researchers on the platform can see that the program exists, but they must apply to participate. You control who is approved. Researchers need to log in and submit an application before they can view full program details.

โš ๏ธBeware: Application programs are also visible on the public Intigriti website, although detailed scope information remains hidden until access is granted.

Registered

Registered programs are visible to all researchers who are registered on the Intigriti platform. Any registered researcher can view the program details and create submissions. You can optionally restrict participation to ID-checked researchers only, which adds an extra layer of trust while keeping the program broadly accessible within the platform.

Public

Public programs are fully discoverable and listed on the public Intigriti website. Researchers still need to register on the platform to create submissions.

Best practices

  • Start with a more restrictive confidentiality level when launching a new program to validate scope, processes, and reward structure.

  • Gradually expand access as you gain confidence in your setup and internal handling capacity.

  • Clearly communicate any changes in confidentiality to your internal teams, as adjusting visibility can significantly impact the volume of incoming submissions and the workload for remediation and response teams.

Related articles

Did this answer your question?