Table of Contents

Picking a Program

Choosing the right target is as important as the testing itself.

What to Look For

Program Health Check

Before committing time, send 1-3 small reports and watch how they respond:

Program Selection Checklist

  1. [ ] Scope is large enough to be worth months of investment
  2. [ ] Payouts are fair and consistent
  3. [ ] Team is responsive to reports
  4. [ ] Test with a small simple bug first (XSS/CSRF) to gauge response
  5. [ ] Only go deep if the first report is handled well
  6. [ ] Max 3-6 programs at a time

VDPs vs Paid Programs

See Also