HACKTRAINING
HomeProgramsHacktivityLeaderboardBlog
Login / Register
HomeProgramsHacktivityLeaderboardBlog
Login / Register
HACKTRAINING

India's premier bug bounty platform. Connecting ethical hackers with organizations to build a safer internet.

platform

  • Programs
  • Hacktivity
  • Leaderboard
  • Blog

resources

  • About
  • Disclosure Policy
  • Documentation
  • Contact

legal

  • Terms of Service
  • Privacy Policy
  • Safe Harbor

status

all systems operational

99.99% uptime · 24/7 triage

© 2026 HACKTRAINING·India's premier bug bounty platform·responsible disclosure

Frequently Asked Questions

Everything you need to know about the platform

Getting Started

A bug bounty program is an initiative by organizations to reward security researchers for responsibly discovering and reporting vulnerabilities in their systems. Companies define scope, rules, and bounty ranges, and researchers who find valid bugs receive monetary rewards.

Create an account as a Researcher, browse available programs, read their scope and rules carefully, then start testing. When you find a vulnerability, submit a detailed report with steps to reproduce. Our CVSS calculator helps you accurately assess severity.

Register as a Company, then click 'New Program' in your dashboard. Define your scope (which assets researchers can test), set bounty ranges for each severity level, and specify your program rules. Your program will be visible to all researchers once published.

Reporting

A strong report includes: a clear title, detailed description of the vulnerability, step-by-step reproduction instructions, proof of concept (screenshots/videos), impact assessment, and a CVSS score. The more detail you provide, the faster the triage process.

CVSS (Common Vulnerability Scoring System) is an industry-standard framework for rating the severity of security vulnerabilities. Our platform includes a built-in CVSS 3.1 calculator that automatically classifies vulnerabilities as None, Low, Medium, High, or Critical.

Your report enters the triage process. The company's security team reviews it, verifies the vulnerability, and may ask questions via comments. Reports go through statuses: New → Triaged → Accepted → Resolved. You'll receive notifications at each stage.

Bounties & Rewards

Each program sets its own bounty table with ranges for each severity level (Critical, High, Medium, Low). The exact amount within the range depends on impact, quality of the report, and the company's assessment.

Once your report is verified and marked as resolved, the company awards a bounty. You can track all your earnings and payout status on your Earnings page.

Yes! Resolved reports earn you reputation points based on the severity of the bug. Higher reputation unlocks leaderboard rankings and signals your expertise to companies looking for top researchers.

Security & Account

Yes. We support TOTP-based two-factor authentication. Go to Settings → Security to set up 2FA with any authenticator app (Google Authenticator, Authy, etc.).

Our safe harbor policy protects researchers who test in good faith within program scope. As long as you follow the program's rules and disclosure guidelines, you're protected from legal action. See our Disclosure Policy for full details.

You can update your profile information including display name, bio, and social links from Settings → Profile. Email changes require re-verification.