Bug Bounty Calculator
What each input does
| Input | Effect on the payout |
|---|---|
| Program maturity | Sets the minimum and maximum bounty for each severity band, from public bounty tables and platform reports. Edit the table to match your policy. |
| Severity or CVSS score | Selects the row of the payout table. A CVSS score maps to a band: 9.0 and above is Critical, 7.0 to 8.9 is High, 4.0 to 6.9 is Medium, below 4.0 is Low. |
| Asset criticality | Core assets pay the full range. Secondary assets pay half. Peripheral assets pay a quarter. |
| Proof of concept | Adds 25 percent to the geometric midpoint of the adjusted range. The result is rounded to the nearest 50 dollars and capped at the maximum. |
Worked examples
Open an example to see every input filled in. Change any value from there.
| Example | Inputs |
|---|---|
| Stored XSS in checkout | Established program, High severity, core asset, proof of concept included. |
| Remote code execution at a bank | Top tier program, CVSS 10.0, core asset, proof of concept included. |
| IDOR in an internal tool | Mature program, Medium severity, secondary asset, no proof of concept. |
| Open redirect on a demo site | Starter program, Low severity, peripheral asset, no proof of concept. |
| Budget for a first private program | Starter preset, 20 percent platform fee, 15 percent reserve. |
| Budget for a public launch | Established preset, twice the expected findings in year one, 25 percent reserve. |
| Budget for a self-hosted mature program | Mature preset, no platform fee, 10 percent reserve. |
How the estimate works
Payout mode starts from a benchmark payout range for the severity of the finding at a program of your maturity. The asset criticality multiplier lowers the range for secondary and peripheral assets. The recommended amount is the geometric midpoint of the range, plus a 25 percent bonus when the report includes a working proof of concept. Typical awards cluster near the low end of published ranges, so the midpoint is a realistic anchor.
Budget mode multiplies the expected number of valid findings per severity by the payout range, then adds the platform fee and a reserve. The low and high columns use the minimum and maximum payouts. The expected column uses the geometric midpoint.
Benchmark payout tables
| Program | Critical | High | Medium | Low |
|---|---|---|---|---|
| Starter | $1,500 – $5,000 | $500 – $1,500 | $150 – $500 | $50 – $150 |
| Established | $5,000 – $15,000 | $1,500 – $5,000 | $500 – $1,500 | $150 – $500 |
| Mature | $15,000 – $50,000 | $5,000 – $15,000 | $1,500 – $5,000 | $300 – $1,500 |
| Top tier | $50,000 – $250,000 | $15,000 – $50,000 | $5,000 – $15,000 | $1,000 – $5,000 |
Benchmarks are derived from public bounty tables and platform reports. They are planning estimates, not a recommendation for any single program. Edit the tiers to match your own policy.
Setting bounty tiers
- Tie tiers to CVSS bands so researchers can predict the award. Use the CVSS calculator to score a report before you pay.
- Publish the table in your policy. Ambiguous payouts drive disputes and reduce researcher trust.
- Pay more for the assets you care about most. A critical in a marketing site does not deserve a core-application payout.
- Budget a reserve. Launch months and scope expansions produce spikes in valid reports.
- Reduce the bounty bill at the source. Continuous testing before release removes the findings that cost the most.
Frequently asked questions
Keep exploring
Start testing in minutes
Connect your GitHub repos and domains, and get fully set up in a few clicks.
