intigriti
Vulnerability Disclosure Programs and Bug Bounty Programs
Pages
4
Time to read
3 mins
Publication
Language
English
Pages
4
Time to read
3 mins
Publication
Language
English
This document is a guide that outlines the features and differences between Vulnerability Disclosure Programs (VDP) and bug bounty programs offered by Intigriti. It describes the compliance aspects of VDP, which meets industry standards and supports ISO/IEC 29147:2018, and the legal framework that provides assurance to contributors against legal actions when reports are made in good faith. The guide details the real-time vulnerability management capabilities, centralized communication through the platform, and the cultural approach of encouraging reporting without fear of repercussions. It also contrasts the reward systems, noting that VDPs do not promise rewards while bug bounties incentivize researchers with monetary rewards based on the severity of reported vulnerabilities. Additionally, the document discusses the quality assurance process handled by Intigriti, ensuring that only valid and unique reports are escalated to businesses, and highlights the different levels of researcher expertise attracted to each program type.