For researchers & the companies they protect

Find the flaw.Prove the impact.Get paid.

datacoconut is where serious researchers hunt real targets and companies run public, private and VDP programs. Clear scope, honest triage, fair bounties by severity — and reputation you carry everywhere.

$1.2M+
Bounties paid
2,400+
Valid findings
1.8d
Avg. first response
datacoconut · triage streamLIVE
researcher@datacoconut:~$submit --program northwind
datacoconutMODEL DC-1200 · TRIAGE
CRITauth bypass on /api/v2/token/refresh$8,000HIGHstored XSS in dashboard comments$3,000HIGHSSRF via webhook URL validator$3,000CRITRCE in image-processing worker$12,000LOWreflected XSS on ?q= search param$150HIGHprivilege escalation via role param$4,500CRITJWT signature not verified$9,000LOWverbose error leaks stack trace$150CRITauth bypass on /api/v2/token/refresh$8,000HIGHstored XSS in dashboard comments$3,000HIGHSSRF via webhook URL validator$3,000CRITRCE in image-processing worker$12,000LOWreflected XSS on ?q= search param$150HIGHprivilege escalation via role param$4,500CRITJWT signature not verified$9,000LOWverbose error leaks stack trace$150
Program types
Public · Private · VDP
Triage
Managed or self-serve
Reputation
Two-sided & verified
Researchers
A learn-to-earn path
Trusted by security teams at
Equitas Small Finance BankOLACREDCostcoCholamandalamSamsungBurger KingFlipkart
01How it works

One end-to-end flow, from scope to payout.

The whole platform is a single loop: a company publishes a program, researchers test authorized targets, findings are triaged and validated, and fixes are verified before a bounty is paid.

  1. 01

    Publish a program

    Companies define scope, rules, eligibility and a severity-to-bounty table, then publish public, private or VDP programs.

    → scope + severity table

  2. 02

    Discover & test

    Researchers find programs, read the scope, and test only authorized targets under a clear responsible-testing policy.

    → authorized test window

  3. 03

    Report & triage

    Structured, evidence-backed reports enter a validation queue: valid, invalid, duplicate or needs-info, with a full discussion thread.

    → validated finding

  4. 04

    Reward & resolve

    Companies set severity and bounty, fix, and request a retest. Researchers earn and build verified, portable reputation.

    → bounty paid + retest

A finding's lifecycle
Submitted→Triage→Needs info→Valid→Severity→Bounty→Remediation→Retest→Resolved

02Portals

Every role gets its own console.

Five focused surfaces, one system of record. Each side sees exactly the workflow it needs — no more, no less.

Security researchers

Researcher portal

Discover programs, submit reports, and track rewards, reputation and learning.

Security teams

Company portal

Create programs, review reports, and manage researchers, remediation and bounties.

Platform analysts

Triage portal

Validate findings, classify, and manage duplicates, severity, SLAs and communication.

Operations

Admin portal

Operate users, programs, reports, payments, challenges, disputes and platform health.

Public & researchers

Public marketplace

Program discovery, researcher profiles, rankings and selected public disclosures.

03For companies

A security program console, not a giant SOC.

Publish a program in minutes with authorization that is impossible to misunderstand, then manage every finding to closure from one clean review workflow — no spreadsheets, no shared inboxes.

Set up a programIn minutes
Program typesPublic / Private / VDP
Pay only forValid findings
01

Unambiguous scope

In-scope and out-of-scope assets and prohibited techniques, stated explicitly on every program — authorization is never left to guesswork.

02

Managed triage

Optional expert validation classifies findings and handles duplicates and severity before anything reaches your engineers.

03

Remediation & SLAs

Track owners, response and resolution times, and request a retest — all from a single report view.

04

Program reputation

Transparent signals — responsiveness, bounty fairness and scope clarity — attract stronger researchers to your program.

01

Real, clear targets

Search by company, technology and vulnerability type. Know exactly what is authorized before you send a single request.

02

Structured reports

A guided form for title, asset, type, steps, impact and evidence — simple for first-timers, ready for triage.

03

Fair rewards

Transparent severity and bounty decisions, visible payout status, and a two-sided rating that holds companies accountable too.

04

Verified reputation

Valid findings, severity mix, acceptance rate and skill badges build a profile you carry across every program.

04For researchers

Find real work. Earn. Build a name.

datacoconut is built as a growth engine for legitimate researchers — from your first lab to your first critical finding and every bounty after. Free to join, fair by design.

Joining & reportingAlways free
Every decisionExplained & appealable
Your reputationPortable across programs
Browse programsMore for researchers →
05The report, structured

Simple for first-timers. Ready for triage.

One guided form captures everything a triager needs to make a fair, fast decision — no back-and-forth guessing.

01

Title

A clear one-line summary of the vulnerability.

02

Affected asset

The exact in-scope target or endpoint.

03

Vulnerability type

IDOR, XSS, SSRF, auth bypass and more.

04

Steps to reproduce

Clear, repeatable steps a triager can follow.

05

Impact

Why the issue matters, in real terms.

06

Evidence

Screenshots, requests, responses, video or PoC.

07

Researcher severity

An optional severity recommendation.

new report · northwinddraft
01Title
Auth bypass on /api/v2/token/refresh
02Affected asset
api.northwind.example/v2/token/refresh
03Vulnerability type
Broken authentication
04Steps to reproduce
1. POST a refresh token belonging to another tenant …
05Impact
Full account takeover without user interaction.
06Evidence
3 files · request.har, poc.mp4, screenshot.png
07Researcher severity
LowMediumHighCritical
AI — assist, optional

Helps structure and suggest a category — never invents proof or decides.

06Learn & labs

A path from learning to real bounty participation.

Hands-on labs and challenges build verified skills, then move researchers into live programs where those skills earn real rewards.

Learn→Practice→Solve→Earn badge→Join bounty
Guided labs

Beginner to advanced

Progressive labs across web, API, auth and cloud, with completion tracking.

CTF mode

Timed challenges

Solve real-world scenarios for scores and a place on the challenge board.

Skill badges

Proof of skill

Achievements attach to your researcher profile and signal specialization.

Learn to earn

Straight into bounties

Take proven skills directly into live programs and start finding real bugs.

07Hall of Fame

Ranked on quality, not volume.

View full Hall of Fame →
RankResearcherValidCriticalReputationBounty earned
01@r00tcause183279,801$248,900
02@nullbyte161228,860$212,400
03@shibateam143198,180$190,050
04@parseltongue128157,855$164,300
05@ghostpackets119127,100$148,700
08Trust & safety

A marketplace that moves money runs on trust.

Explicit authorization

Every program states scope and prohibited activity. Authorization is never silently changed.

Verified accounts

Researcher and organization verification appropriate to risk, with KYC before real payouts.

Full audit trail

Every important decision is traceable, with an immutable report timeline.

Secure evidence

Proof and attachments are stored securely and shared only with the right parties.

Anti-abuse controls

Spam, duplicate and fabricated-evidence controls keep the signal high.

Appeals & disputes

A clear dispute workflow for both sides when a decision is contested.

09FAQ

Questions, answered.

What is a bug bounty program?+

A program is a company's invitation for researchers to test defined targets under clear rules, and to be rewarded for valid vulnerabilities based on severity.

Do I need to pay to submit reports as a researcher?+

No. Researchers join for free, discover programs, and earn bounties on valid findings. Companies pay to run programs and, optionally, for managed triage.

What happens after I submit a report?+

It enters triage, where it is validated as valid, invalid, duplicate or needs-info. Valid findings receive a severity and bounty decision, then move through remediation and retest to resolved.

Is my testing authorized?+

Only within a program's stated scope and rules. datacoconut makes in-scope and out-of-scope targets and prohibited techniques explicit, and authorization is never silently changed.

Does AI make the final decision on my report?+

No. AI is kept small and supportive — it can help structure a report and suggest a category. It never invents proof or makes the final validity or severity decision.

One trusted workflow,from scope to payout.