Who is paying for security research.
Every organisation running a program on datacoconut, what they have paid out, and what they publish about how they handle findings. Running one yourself? Start here.
Companies
9
Live programs
8
Bounties paid
$2,234,400
E-commerce & retail · United States
Auriga Retail welcomes research across its storefront, shopping apps and checkout API. Anything that lets an attacker change a price, take over an acc…
Financial services · Australia
darren@pisence.comdarren@pisence.comdarren@pisence.comdarren@pisence.comdarren@pisence.comdarren@pisence.comdarren@pisence.comdarren@pisence.comdarren…
Media & publishing · United States
Fable Media publishes long-form journalism behind a subscriber paywall. The reading experience, the subscriber account area and the editorial CMS are …
Healthcare · United States
Helios Health runs a vulnerability disclosure program. There is no monetary bounty, but every valid report is credited on our hall of fame and handled…
Financial services · United States
Meridian Bank runs an invite-only program for its retail banking web app and mobile banking clients. Access is granted after identity verification, an…
Cloud & infrastructure · United States
Northwind Cloud runs a public bug bounty program covering its production platform, public API and mobile apps. We reward valid, in-scope vulnerabiliti…
Payments & fintech · United States
Orbit Payments moves money for thousands of merchants, so anything touching authentication, authorization or settlement is treated as high impact. The…
Telecommunications · United States
Solstice Telecom runs a small invite-only program against its carrier APIs and cloud infrastructure. Scope is narrow and impact is high — the top payo…
Gaming & entertainment · United States
Vertex Gaming streams games from its own cloud, so both the player-facing platform and the session infrastructure behind it are in scope. Cheat develo…