# Bug Bounty
**Domain:** Cybersecurity incentives
**Doc Type:** Developed Practice Node
**Maturity:** Developed
**Collection:** [[collections/Gamification|Gamification Collection]]
## Definition
A **bug bounty** is an authorized program that offers recognition or payment for responsibly reporting software vulnerabilities within published scope. The bounty converts adversarial discovery into a governed market with rules, evidence requirements, and remediation.
## Significance
Bug bounties supply actual consequence to planner-tier play: a real defect is found and fixed, a researcher gains status or income, and an organization learns where its defenses fail. Authorization, safe harbor, and disclosure terms determine whether the channel is credible.
## Sources
- CISA, [Vulnerability Disclosure Policy Template](https://www.cisa.gov/resources-tools/resources/vulnerability-disclosure-policy-template)
## Routes
[[wiki/Capture the Flag|Capture the Flag]] · [[wiki/Red Teaming|Red Teaming]] · [[wiki/Non-Substitutability|Non-Substitutability]]