CalculatorsRuns in your browser

Bug Bounty Calculator

Free bug bounty calculator. Estimate a fair payout for a finding by severity and asset criticality, or model the annual budget for a bug bounty program.

Program · Step 1 of 4
Program maturity
How established is the program? The preset sets the payout table.
Recommended payout
$3,400
Established program. High severity. Range $1,500$5,000.
HighCore asset ×1+25% proof of concept
Payout matrix
Recommended award for every severity and asset criticality with the Established payout table and the proof-of-concept bonus. Select a cell to estimate that combination.
SeverityCore ×1Secondary ×0.5Peripheral ×0.25
CriticalCVSS 9.0 – 10.0
HighCVSS 7.0 – 8.9
MediumCVSS 4.0 – 6.9
LowCVSS 0.1 – 3.9

Ranges without the proof-of-concept bonus, for your program policy page.

Payout table
Minimum and maximum bounty per severity for core assets, in US dollars. The Established preset fills these values. Edit them to match your own policy.
Critical CVSS 9.0 – 10.0
High CVSS 7.0 – 8.9
Medium CVSS 4.0 – 6.9
Low CVSS 0.1 – 3.9

What each input does

InputEffect on the payout
Program maturitySets the minimum and maximum bounty for each severity band, from public bounty tables and platform reports. Edit the table to match your policy.
Severity or CVSS scoreSelects the row of the payout table. A CVSS score maps to a band: 9.0 and above is Critical, 7.0 to 8.9 is High, 4.0 to 6.9 is Medium, below 4.0 is Low.
Asset criticalityCore assets pay the full range. Secondary assets pay half. Peripheral assets pay a quarter.
Proof of conceptAdds 25 percent to the geometric midpoint of the adjusted range. The result is rounded to the nearest 50 dollars and capped at the maximum.

Worked examples

Open an example to see every input filled in. Change any value from there.

ExampleInputs
Stored XSS in checkoutEstablished program, High severity, core asset, proof of concept included.
Remote code execution at a bankTop tier program, CVSS 10.0, core asset, proof of concept included.
IDOR in an internal toolMature program, Medium severity, secondary asset, no proof of concept.
Open redirect on a demo siteStarter program, Low severity, peripheral asset, no proof of concept.
Budget for a first private programStarter preset, 20 percent platform fee, 15 percent reserve.
Budget for a public launchEstablished preset, twice the expected findings in year one, 25 percent reserve.
Budget for a self-hosted mature programMature preset, no platform fee, 10 percent reserve.

How the estimate works

Payout mode starts from a benchmark payout range for the severity of the finding at a program of your maturity. The asset criticality multiplier lowers the range for secondary and peripheral assets. The recommended amount is the geometric midpoint of the range, plus a 25 percent bonus when the report includes a working proof of concept. Typical awards cluster near the low end of published ranges, so the midpoint is a realistic anchor.

Budget mode multiplies the expected number of valid findings per severity by the payout range, then adds the platform fee and a reserve. The low and high columns use the minimum and maximum payouts. The expected column uses the geometric midpoint.

Benchmark payout tables

ProgramCriticalHighMediumLow
Starter$1,500 – $5,000$500 – $1,500$150 – $500$50 – $150
Established$5,000 – $15,000$1,500 – $5,000$500 – $1,500$150 – $500
Mature$15,000 – $50,000$5,000 – $15,000$1,500 – $5,000$300 – $1,500
Top tier$50,000 – $250,000$15,000 – $50,000$5,000 – $15,000$1,000 – $5,000

Benchmarks are derived from public bounty tables and platform reports. They are planning estimates, not a recommendation for any single program. Edit the tiers to match your own policy.

Setting bounty tiers

  • Tie tiers to CVSS bands so researchers can predict the award. Use the CVSS calculator to score a report before you pay.
  • Publish the table in your policy. Ambiguous payouts drive disputes and reduce researcher trust.
  • Pay more for the assets you care about most. A critical in a marketing site does not deserve a core-application payout.
  • Budget a reserve. Launch months and scope expansions produce spikes in valid reports.
  • Reduce the bounty bill at the source. Continuous testing before release removes the findings that cost the most.

Frequently asked questions

Start testing in minutes

Connect your GitHub repos and domains, and get fully set up in a few clicks.