# Bug Bounty **Domain:** Cybersecurity incentives **Doc Type:** Developed Practice Node **Maturity:** Developed **Collection:** [[collections/Gamification|Gamification Collection]] ## Definition A **bug bounty** is an authorized program that offers recognition or payment for responsibly reporting software vulnerabilities within published scope. The bounty converts adversarial discovery into a governed market with rules, evidence requirements, and remediation. ## Significance Bug bounties supply actual consequence to planner-tier play: a real defect is found and fixed, a researcher gains status or income, and an organization learns where its defenses fail. Authorization, safe harbor, and disclosure terms determine whether the channel is credible. ## Sources - CISA, [Vulnerability Disclosure Policy Template](https://www.cisa.gov/resources-tools/resources/vulnerability-disclosure-policy-template) ## Routes [[wiki/Capture the Flag|Capture the Flag]] · [[wiki/Red Teaming|Red Teaming]] · [[wiki/Non-Substitutability|Non-Substitutability]]