# Welcome to BugBase Docs

If you want to know how things work at BugBase, these docs will help you to understand the product so that you can easily navigate through your hacker-powered security program.

## Overview

**BugBase** is platform that seamlessly hosts **Bug Bounty Programs** for companies across the world by connecting them to skilled, freelance ethical hackers who identify flaws in their public-facing software, for a bounty.

{% embed url="<https://bugbase.ai>" %}

## Quick links

{% content-ref url="/pages/T53mcgbjVEESo7gfszFi" %}
[What we do](/overview/what-we-do)
{% endcontent-ref %}

{% content-ref url="/pages/0OBx2tmYQDssQqVvsg2u" %}
[Our Features](/overview/our-features)
{% endcontent-ref %}

{% content-ref url="/pages/j9Ymo0mnn0VkW5eu6ex9" %}
[Changelogs](/overview/changelogs)
{% endcontent-ref %}

## Get Started

We've put together some helpful guides for you to get setup with our product quickly and easily.

{% content-ref url="/pages/wrYP4taxG5qlGwCFh9OF" %}
[Company Guide](/company-guide/create-a-company-account)
{% endcontent-ref %}

{% content-ref url="/pages/L4F3pnQP73eHMJBQnYR6" %}
[Bounty Hunter Guide](/bounty-hunter-guide/bounty-hunter-dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/NecviZz76QqcavnkzXS2" %}
[Report Lifecycle](/report-lifecycle/bug-report)
{% endcontent-ref %}


# What we do

BugBase is a curated marketplace for ethical hackers that helps businesses and startups set up bug bounty and vulnerability disclosure programmes.

{% hint style="info" %}
BugBase is World's first **continues vulnerability assessment platform**, which assists organisations in staying safe by providing an all-in-one platform for continuous and comprehensive security testing.
{% endhint %}

## What are Bug Bounties?

A **bug bounty** is a deal offered by businesses and organisations in which cybersecurity experts can receive **recognition and monetary compensation** in return for reporting bugs within the software security infrastructure of these enterprises.

A software **bug** is an error, flaw or fault in computer software that causes it to produce an incorrect or unexpected result, or to behave in unintended ways.

They plague modern day businesses on a day-to-day basis as critical bugs can often have detrimental repercussions on their operations. In extreme cases bugs can even lead to the leakage of important data if a black hat hacker is able to infiltrate into the software infrastructure of the company.


# Changelogs

BugBase pushes out features continuously, here's all the updates in the platforms at one place.

Find out what's changed or is new on BugBase!

### July 2026

**1. Linear Integration**

* You can now connect **Linear** to your BugBase program and track your reports as Linear issues, right alongside your existing JIRA, Asana and Github integrations.
* Enable **Auto-create** to open a Linear issue automatically — choose whether it triggers when a report is **submitted** or once it's been **triaged** — or create one manually from any report with a single click. The Linear issue link then appears directly on the report.
* Configure the **Linear status** and **default assignee** that created issues should be opened with, so reports land in your workflow exactly where you want them.

Learn more here - [Linear](/integrations/linear)

### December 2024

**1. Report tabs & filter updates**

* The Reports section for both Program and Bounty Hunter users has been enhanced to help you focus on the most important reports. Additionally, new filters and sorting options have been added, allowing you to customize your view.

Learn more about these here:

For Program Managers - [Program Reports Section](/program-guide/bug-bounty-dashboard/program-reports-section)

For Bounty Hunters - [Bounty Hunter Reports Section](/bounty-hunter-guide/bounty-hunter-reports-section)

<figure><img src="/files/qFNeAASTXgEm1gkkeU0m" alt=""><figcaption></figcaption></figure>

**2. Whitelisting bounty hunters on assets**

* Companies can now whitelist **bounty hunters' credentials (phone, email, or both)** on specific assets.
* Companies can now enable whitelisting for **credential vaults**. [Require Whitelisting for a Credential](/company-guide/credential-vaults/require-whitelisting-for-a-credential)

Learn more about these here:

For program managers - [Whitelist](/company-guide/whitelist)

For bounty hunters - [Whitelist](/bounty-hunter-guide/programs-directory/whitelist)

<figure><img src="/files/BNSm3nyhzPL1PkzhPRuq" alt=""><figcaption></figcaption></figure>

**3. Collaboration on Private Programs**

Enables users to manage collaboration preferences, allowing communication with other bounty hunters in **private programs**.

Learn more - [Collaborate](/bounty-hunter-guide/programs-directory/collaborate)

<figure><img src="/files/1fB4IAgiLemkpwSgoLz3" alt=""><figcaption></figcaption></figure>

### November 2024

**1. Editable Report Title (Program only feature)**

* Program managers with the necessary permissions can now edit report titles using the edit icon next to the title.

<figure><img src="/files/wFTPVGwog9pE1rADOS7p" alt=""><figcaption></figcaption></figure>

**2. New Report Status Label - Under Program Review**

* We have introduced a new Report Status Label - **Under Program Review** to have better visibility for the reports pending action/review from the Program Admins after the initial Triage by BugBase.
* Learn more here [Program Reports Section](/program-guide/bug-bounty-dashboard/program-reports-section)

<figure><img src="/files/9HNrsjfoNeCGCqXeGytO" alt=""><figcaption></figcaption></figure>

**3. Custom Report Tags (Program only feature)**

* We have introduced custom report tags which helps Program Managers to filter reports based on custom tag names.
* Learn more about Report Tags here: [Report Tags](/company-guide/company-settings/customization/report-tags)

<figure><img src="/files/evF7f849HuX9FzoFqr5l" alt=""><figcaption></figcaption></figure>

**4. Redesigned Scope Groups in Program Policy**

* Introducing the updated Scope Groups design which brings clarity on the In-Scope and Out-of-Scope assets along with eligibility for Bounty or Swags.

<figure><img src="/files/gdnKqAkVFaCBW1lnFpcI" alt=""><figcaption></figcaption></figure>

**5. Custom Hall of Fame Addition**

* Programs can now add custom hall of fame members on their policy page to acknowledge any researchers that are not a part of BugBase.

<figure><img src="/files/P4RQjaXotekAxNg7NMab" alt=""><figcaption></figcaption></figure>

### October 2024

**1. Program Statistics on Policy Page**

* Program statistics like average first response time/triage time/resolution time are now visible on program pages.

<figure><img src="/files/NxhX4asXg6xs2koRmVu6" alt=""><figcaption></figcaption></figure>

### March 2024

**1. Leaderboard Enhancements: Country Filter and Search Functionalities**

* Improved Leaderboard Design: The design of the leaderboard has been updated for enhanced usability and aesthetics.
* Country Filter and Default Setting: Added a country filter allowing users to filter leaderboard results by country. Default filter setting is "Global," displaying all individuals on the leaderboard initially.
* Search Functionality: Search bar for easy lookup of specific individuals on the leaderboard.

<figure><img src="/files/BRbgVOooGVXM6d8YhNoS" alt=""><figcaption></figcaption></figure>

**2. Bounty Assignment Approval System**

* Companies can now designate certain individuals who require approval for bounty assignment.
* Users marked for approval will not be able to assign bounties directly but will require approval from authorized individuals.
* Requested bounties will be visible to program users.
* Users who do not require approval for bounty assignment can accept or deny bounty requests from those requiring approval.

<figure><img src="/files/HvlKuccLU69a3mQtJfXY" alt=""><figcaption></figcaption></figure>

**3. Asset Assignment and Restricted Access Control**

* Companies can now assign specific assets to designated assignees within BugBase.
* Users have restricted access to reports, bugs, etc., for the assets they have been assigned to.
* This feature ensures heightened security and privacy by limiting access to sensitive information to only those with explicit authorization.

<figure><img src="/files/XNnPK2f3kyiD3y8JDZ7X" alt=""><figcaption></figcaption></figure>

**4. Asset-Focused Insights Filtering**

Users can now view insights tailored to specific assets or projects. This feature enables users to focus on insights relevant to their assigned assets or projects, optimizing decision-making and efficiency.

<figure><img src="/files/7reTjsnxYXAWYITS0ofk" alt=""><figcaption></figcaption></figure>

**5. Move Reports between programs in an organisation**

Company & Program Admins can now move reports across programs in the same organization, this allows companies to segregate the reports based on a particular asset, brand and confidentiality (Public or Private)

<figure><img src="/files/x1gdRimk1lMhSlQm7KJX" alt=""><figcaption><p>Move reports in an organization</p></figcaption></figure>

**6. Improved UI for settings page**

BugBase has updated its Settings page, moving the navigation menu to the left for easier access. Everything you're used to is still there, but now it looks cleaner and more organized. This change makes it simpler for both hackers and companies to navigate and customize their preferences.

<figure><img src="/files/E5oxVL9r4GXuwyUYxNQX" alt=""><figcaption></figcaption></figure>

### February 2024

**1. On-demand VPN Servers for Testing Private Assets**

Companies can now launch VPN Servers managed by BugBase for testing private assets by whitelisting their In-Scope testing assets to the VPN server. This includes logging of bounty hunter traffic, rate-limiting, blacklisting particular routes, geolocation restrictions etc.

<figure><img src="/files/O4dM61bewZykQ9oYYjSU" alt=""><figcaption></figcaption></figure>

**2. Timezone Preference**

* Users can now personalise their experience by setting their preferred timezone within their profiles.
* This feature adjusts the display time on users' screens to match their chosen timezone selection.
* Users have the flexibility to select any timezone from the available options, ensuring accurate time representation throughout the platform.

<figure><img src="/files/Uk2LfdPYY2WDgd6UXr7c" alt=""><figcaption></figcaption></figure>

**3. New Hacker Profile**

* **Overall Design Overhaul:** The profile page has been streamlined for a cleaner and simpler aesthetic, enhancing usability and focus on key information.
* **Bug Submission Graph:** Introduction of a graphical representation of bug submissions. This visual element allows hackers to quickly see their reporting activity over time, making it easier to track submissions and identify periods of high or low activity.
* **Activity Timeline (Hacktivity):** The 'Hacktivity' section has been transformed into a timeline format, providing a chronological view of a hacker's activities within each year. This makes it easier to follow the history of one's contributions and achievements.
* **Redesigned Badges:** Badges have received a new design, likely to improve visual appeal and distinguish the achievements they represent more clearly

<figure><img src="/files/VUCXzTxRKV4s5PBGtmkr" alt=""><figcaption><p>New Profile page</p></figcaption></figure>

<figure><img src="/files/84H8yMDbITkmTIwTJq0s" alt=""><figcaption><p>Hacktivity timeline in hacker profile</p></figcaption></figure>

<figure><img src="/files/C9zUdy7tna5nQXoQZyyU" alt=""><figcaption><p>badges in hacker profile</p></figcaption></figure>

### January 2024

**1. Competition Reminder Trigger**

Companies can now set up triggers to notify all users one day before, 30 minutes before, and when the competition starts.

<figure><img src="/files/vwUSlFTg6cZtMsiAEsLE" alt=""><figcaption></figcaption></figure>

### December 2023

**1. Program side notifications filters by hackers and bug report**

Companies can now filter notifications received by their programs and mark them as read.

<figure><img src="/files/I4YszQ2FnsGw9hCtodXp" alt=""><figcaption></figcaption></figure>

### November 2023

#### 1. Public Global Leaderboard for bounty hunters

The Global Leaderboard is now Public on <https://bugbase.in/leaderboard>! Go ahead and flaunt your hacking skills and reputation by sharing the leaderboard with your friends and show them how cool you are :sunglasses:

<figure><img src="/files/Y2it8Rqi7ygWZQAl9Gyl" alt=""><figcaption></figcaption></figure>

#### 2. Bounty Hunter Feed (Previously Notifications)

Now the hacker feed is available, where the user can see all the feed customised according to their activity. It includes upcoming programs, details about their bug reports, important announcements as well as any invitation to private programs.

<figure><img src="/files/NELAd4xdz3mihnSmaL0F" alt=""><figcaption></figcaption></figure>

#### 3. Campaigns

Now a company has the chance to create a customized campaign with their preferences and release it.This option can be accessed from the sidebar and the main screen would show the list of completed and ongoing campaigns.

once the details are filled up it shows a preview of the campaign to be released.

<figure><img src="/files/GC6MjJ0lH340RgNs1CLy" alt=""><figcaption><p>Campaign Section</p></figcaption></figure>

### October 2023

#### 1. Confirming Priority on Bug Reports

Upon submission of a bug report by a security researcher/bug bounty hunter, our system initiates a priority validation process. A designated triager or the program representative reviews the submitted vulnerability to confirm whether its assigned priority accurately reflects its potential risk and impact. Once the priority is confirmed, the corresponding bounty is assigned based on this validated priority, ensuring that critical vulnerabilities are addressed promptly and rewards are distributed fairly.

<figure><img src="/files/yFtA5Oz8NIycZO3vRdH6" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/jxUv14mD7e7soGAuqne2" alt=""><figcaption></figcaption></figure>

### September 2023

#### 1. **Multi-Language Support for Bug Bounty Program Policy**

Users can now read our Bug Bounty Program Policy in multiple languages. This feature aims to make our platform more accessible and inclusive for our global user base.

* Supported Languages: English, Hindi, Telugu, Bengali, Gujarati, Kannada, Malayalam, Marathi, Tamil, Spanish, French, German, Chinese (Simplified) and Dutch.
* Language selection is available at the top-right corner of the Bug Bounty Program Policy card.

<figure><img src="/files/nObFLMhF6V7xZRNpR7V3" alt=""><figcaption><p>Users can choose the language of the policy</p></figcaption></figure>

#### 2. **Multiple Email Notifications for Companies**

Companies can now specify different group of email addresses for various types of notifications. This feature allows for better organization and quicker response times for critical issues.

* **Bug Report Notifications**: Companies can now designate a specific email address to receive all notifications related to bug reports.
* **Program-Related Notifications**: Set up a separate email address for notifications concerning program updates, new features, and announcements.
* **Pentest-Related Notifications**: Choose an email address to receive all notifications related to penetration testing activities and reports.
* **Payment Notifications**: A separate email address can be set up to receive all payment-related notifications, such as transaction confirmations and invoices.

***To use this feature:*****&#x20;Navigate to Company Settings Page >> Click on Manage Email Notifications**

<figure><img src="/files/4m7udYk6yx7n3jmNcHXj" alt=""><figcaption><p>Manage email notifications</p></figcaption></figure>

### August 2023

#### 1. Change Report priority by company

Now, company can view a report and have the option to change the priority of the specific report according to their discretion.

<figure><img src="/files/Y5GjWL7ha2mo8EWWAQgT" alt=""><figcaption></figcaption></figure>

#### 2. Last seen internal activity on bug report

The last seen internal activity on any bug report is visible now in report chat thread.

<figure><img src="/files/5BpZiSxC6yOq7WLvJQCF" alt=""><figcaption></figcaption></figure>

### July 2023

#### 1. Request Program Activity Report

Now, companies can ask for a performance report of a specific program within a desired period of time from the program dashboard. This generates a program activity report for the requested time.

<figure><img src="/files/K1dgc5B99lOTJapI5WvA" alt=""><figcaption></figcaption></figure>

### June 2023

#### 1. Notification Email Mapping

Companies can now assign separate emails for receiving notification on different categories of events. Which will allow hassle free communication.

<figure><img src="/files/Uw8mucT1cxav22pTCPLG" alt=""><figcaption></figcaption></figure>

#### 2. Filter report trends chart by time period in Insights page

Now, companies can use the filter in **`Report trends`** sections to view statistics for the selected time period.

<figure><img src="/files/EwK8mXYNZTIbBkzLASpZ" alt=""><figcaption></figcaption></figure>

#### 3. RBAC for competition programs

Role Based Access Control (RBAC) is now available for `competition` programs as well. Every organisation member can have access to different actions based on their role.

<figure><img src="/files/OvAJRNaKiAEDKHFxWLGb" alt=""><figcaption></figcaption></figure>

#### 4. Assign rewards modal updated design

Now, companies can select the type of reward they want to assign to the security researcher by selecting any of the three options provided.

<figure><img src="/files/Ij0N4SGdk4Z8f9klnNXd" alt=""><figcaption></figcaption></figure>

### May 2023

#### 1. Asset Based Credential Management for Companies

Companies can now import testing credentials for a particular asset on the BugBase Dashboard itself and assign them the Bug Hunters Seamlessly!

<figure><img src="/files/g0MQ122GWPkKK4wBRMJY" alt=""><figcaption><p>Credential Vaults</p></figcaption></figure>

{% content-ref url="/pages/AXRTCtDlzCTFiiSNE8l2" %}
[Credential Vaults](/company-guide/credential-vaults)
{% endcontent-ref %}

#### 2. Assigning Thanks to Bug Reporters

BugBase is excited to announce the introduction of a new feature - **"Assign Thanks"** on Platform. This feature allows program owners to express their gratitude and appreciation to the reporters who have contributed to improving the security of their applications. In addition to assigning monetary rewards for valid bug reports, program owners now have the option to assign thanks to reporters as a way of acknowledging their efforts and valuable contributions.

<figure><img src="/files/6M2mWrvwAPIcRXfUCZoC" alt=""><figcaption><p>Assigning Thanks to Reporter</p></figcaption></figure>

<figure><img src="/files/1JKDhTWOsbyXd4PhbehS" alt=""><figcaption><p>Thanks message on Report</p></figcaption></figure>

{% content-ref url="/pages/YrwG5mCjVTxEMOcwb7Hi" %}
[Assigning Thanks to Reporters](/program-guide/bug-bounty-dashboard/program-reports-section/assigning-thanks-to-reporters)
{% endcontent-ref %}

#### 3. JIRA Cross-Sync Toggle

<figure><img src="/files/oYOZkywqWGIZSZzRGv2J" alt=""><figcaption><p>JIRA Configuration</p></figcaption></figure>

Program Admins can now choose if they want Cross-Sync with JIRA. Cross-Sync basically updates and changes performed on JIRA on BugBase and Vice-Versa this includes comments, status changes etc.

### April 2023

#### 1. Added a section for Top Programs in insights dashboard

<figure><img src="/files/rVlSBBGSU5LfMHqwlrGn" alt=""><figcaption><p>Revamped Insights Dashboard</p></figcaption></figure>

Now the insights dashboard contains top 3 performing programs of the company along with the activity and bugs submitted in the current month.

#### 2. Response Generation through ChatGPT on Report Chat

<figure><img src="/files/Tt59KY5ghVpyrWhcqLks" alt=""><figcaption><p>Generate response through ChatGPT</p></figcaption></figure>

You can now generate replies using **ChatGPT** on any Bug Report on BugBase,which enables you to generate clear AI driven responses for frequently asked questions and customer inquiries without spending time crafting individual responses.

{% content-ref url="/pages/zhKhRdu4SAK1iaMa2kZZ" %}
[Response Generation through ChatGPT on Report Chat](/bounty-hunter-guide/bounty-hunter-reports-section/response-generation-through-chatgpt-on-report-chat)
{% endcontent-ref %}

#### 3. Multi Factor Authentication for all accounts on BugBase

<figure><img src="/files/XHPhlcJrRRaHTjO31OVt" alt=""><figcaption><p>MFA Login Screen</p></figcaption></figure>

For increased security, the Multi-factor authentication (MFA) has been added to BugBase. All users can now set-up MFA via an Authenticator App or through Email.

{% content-ref url="/pages/diurO0oQDIcUhCZ4ygP7" %}
[Multi-Factor Authentication](/company-guide/company-settings/security-and-authentication/multi-factor-authentication)
{% endcontent-ref %}

#### 4. Authentication through Single Sign On \[SSO - SAML2.0]

<figure><img src="/files/UK8vDDlvfEnTysSotmT6" alt=""><figcaption><p>SSO - SAML2.0</p></figcaption></figure>

Company Accounts can now setup login through **SSO** where organization members can use their Identity Provider email to sign-in to BugBase and access the Dashboard.

{% content-ref url="/pages/5vSXYr2L1cbEX6BOejcq" %}
[SSO with SAML](/company-guide/company-settings/security-and-authentication/sso-with-saml)
{% endcontent-ref %}

#### 5. Bounty Hunter Preferences in Settings

<figure><img src="/files/UbuMM7QDTIt6168KCntb" alt=""><figcaption><p>Bounty Hunter Preferences</p></figcaption></figure>

Added **Shipping Address** and **T-Shirt Size** Preference for **Bounty Hunters.**

{% content-ref url="/pages/2DFpKeLgyxXgCOuYpZvq" %}
[Settings](/bounty-hunter-guide/settings)
{% endcontent-ref %}

#### **6. Payout Page Updated Design (Programs only)**

<figure><img src="/files/JzEJJbjVJbFulZEiwM77" alt=""><figcaption><p>View all Rewards Assigned</p></figcaption></figure>

<figure><img src="/files/xfahVfqykgrD4s7q9RC3" alt=""><figcaption><p>Specific Rewards Page</p></figcaption></figure>

Now **Program Admins** can view **Shipping Address** for the assigned swags in their specific **Reward Details** page, this reduces the complexity of asking the address on the Report Chat. Additonally Program Admins can enter **Shipping Details**, this can be a **Tracking URL** for swags or any **instructions updating the reporter** on the whereabouts of the swag assigned.

####

### March 2023

#### 1. Added Swag & Bounty Tags while viewing a single Program

<figure><img src="/files/yUTfsbthiobWj52nnjaa" alt=""><figcaption></figcaption></figure>

Bounty Hunters can now get information about the rewards offered by a program on BugBase by looking at Swags and Bounty Tags

#### 2. Embed Attachments in the Proof Of Concept section while Creating a Report

<figure><img src="/files/kLaXq5SsFo9IjgTU3YJQ" alt=""><figcaption></figcaption></figure>

Now the POC Section supports inline markdown attachments upload for easier understanding of the Report

#### 3. Updated Chat Message Box with Quick Actions (Only for Company Accounts)

<figure><img src="/files/2AYt1edwhLFWOHbhz1oT" alt=""><figcaption><p>New Chat Box Layout</p></figcaption></figure>

#### 4. Add Custom Quick Actions for Quicker Response (Only for Company Accounts)

<figure><img src="/files/GlDzRjbsxoFZkMysGoVt" alt=""><figcaption><p>Custom Quick Actions</p></figcaption></figure>

Now Program managers can create custom quick actions for faster responses to the bug reporters

#### 5. Role Based Access Control \[RBAC] (Only for Enterprise Company Accounts)

<figure><img src="/files/sSuOdQTbbAJjfm3eXGKa" alt=""><figcaption><p>Roles &#x26; Permissions</p></figcaption></figure>

Invite members to your organization and assign them roles with limited permissions to access the various BugBase Dashboards

### February 2023

#### 1. Bookmark/Save Programs

<figure><img src="/files/ATpum7gRs3RUkEUyzveL" alt=""><figcaption></figcaption></figure>

Hackers can now save time by bookmarking their frequently used programs. The bookmarked programs can be easily accessed in the "**saved**" tab of the Programs page, eliminating the need to search repeatedly.

Once a hacker submits a bug report, the program is automatically bookmarked for easy access in the future. This allows for quick and efficient follow-up on resolved bugs, and helps to keep track of all reported issues. The integration of bug reporting and program saving makes the process seamless and efficient, ensuring that hackers can focus on what they do best.

#### 2. Changing Status for Bug Reports is now easy!

It is now even simpler to change a report's status with the new design update for changing the bug report status.

<figure><img src="/files/bNTbgpvyuWsEq1ppN1nD" alt=""><figcaption></figcaption></figure>

### January 2023

#### 1. New Hacker Email Alias

Hackers can now use a unique email alias to receive notifications from BugBase.

This alias can be used to create testing accounts and may be necessary for certain testing purposes.

This alias is automatically assigned in the form of `[username]@teambugbase.com`.

#### 2. Reporting Lifecycle Change

We have made some changes to the reporting lifecycle.

Now all reports will be in one of the following states:

**Open State**

* **Draft** \[Awaiting Submission - Editable State]
* **New** \[Report Submitted]
* **Triaged** \[Report Assigned to a Program Representative]

**Closed State**

* **Resolved** \[Report Resolved by the Program]
* **Duplicate** \[Report Marked as Duplicate]
* **Invalid** \[Report Marked as Invalid]
* **Informational** \[Report Marked as Informational]

#### 3. New Hacktivity Reputation Table

Researchers can now track all their reputation history in the Hacktivity Reputation Table located in their profile page.

<figure><img src="/files/t9ylVLnWnashi2WWPGWU" alt=""><figcaption></figcaption></figure>

This can be found in the profile page of a security researchers `https://bugbase.in/profile/[username]`.

#### 4. Integration with SumoLogic

Now Enterprise Customers can log events from BugBase onto their SumoLogic Collectors seamlessly with one click!

![](/files/ENhDRhSD5ZyDFMqLbVcP)

### December 2022

#### 1. Fresh Look for your Hacker Profile!

We have revamped the hacker profile page with a clean and modern look.

Visit your profile page at `https://bugbase.in/profile/[username]`

<figure><img src="/files/oSCb3bo5aNfGrBio1aVV" alt=""><figcaption></figcaption></figure>

* Now you can see your top-ranked competitions!
* Your success rate and total bounty earned is now visible on your profile.
* Added few more Report statistics like closed reports, total reports and ongoing reports.
* Hall of Fame mentions are now visible on your profile.
* Badges earned are now visible on your profile.
* Social media links can now be added to your profile!

#### 2. Draft Reports & Number of Reports

Hackers can now save their reports as drafts. This will help hackers to save their reports as drafts and continue working on it later.

Additionally hackers can now see the number of reports under each status.

Reports can be saved as drafts by clicking on the **Save as Draft** button while submitting a report.

<figure><img src="/files/dCH9bkBdFUyKOFdG8JNX" alt=""><figcaption></figcaption></figure>

#### 3. Hacker Reporting Flow Updations

We have made some changes to the reporting flow for hackers.

**3.1. Vulnerability Endpoint**

We have added a new section **Vulnerability Endpoint** to the reporting flow. This section will help hackers to pin-point the endpoint where the vulnerability was found.

<figure><img src="/files/LeMKEYO7558dyguomfo4" alt=""><figcaption></figcaption></figure>

**3.2. Report Summary**

We have added a new section **Report Summary** to the reporting flow. This section will help hackers to provide a brief summary of the report.

<figure><img src="/files/6tf6LWkpwrA1xKmxRpKc" alt=""><figcaption></figcaption></figure>

**3.3. Report Vulnerability Impact**

We have added a new section **Report Vulnerability Impact** to the reporting flow. This section will help hackers to provide a brief summary of the impact of the vulnerability.

<figure><img src="/files/Hcaqd0X5SqSSnFRtbEY3" alt=""><figcaption></figcaption></figure>

**3.3. Syntax Highlighting in Markdown**

We have added syntax highlighting in the markdown editor. This will help hackers to write better reports with proper syntax highlighting.

<figure><img src="/files/P4Mw97uetgxVOce21uLP" alt=""><figcaption></figcaption></figure>

#### 4. Assign Reports to your Team & Track Reports Seamlessly

Companies can now assign reports to their team members. This will help companies to assign reports to their team members and keep track of the reports.

![](/files/TV7EbkatcYXD5jFot0fd)

#### 5. Collaboration in Reports

Hackers can invite other hackers to collaborate on their reports. This is only allowed if the program allows collaboration. This will help hackers to collaborate with other hackers on their reports and give more insights on the report.

<figure><img src="/files/RjafurMbAa9DKUcIGaCy" alt=""><figcaption></figcaption></figure>

### November 2022

#### 1. Introducing 3 New Tiers for companies

BugBase now has 3 Tiers for companies curated to fit your needs. You can now choose between the Free, Pro and Enterprise tiers.

* **Free** - Companies can host unlimted **Vulnerability Disclosure Programs (VDPs)** free of cost and receive real-time notifications for new vulnerabilities.
* **Professional** - Has everything that the Free tier has, plus the ability to host upto 2 **Managed Bug Bounty** or **Private Bug Bounty** programs. This tier also includes Integrations that directly connect BugBase with your existing tools like **Webhooks**, **JIRA**, **Slack**, **MS Teams** and more.
* **Enterprise** - Has everything that the Professional tier has, plus the ability to host upto 4 **Managed Bug Bounty** or **Private Bug Bounty** programs. This tier also includes **Managed Rapid Triage**, a dedicated **Security Analyst**, **Priority Support** and much more!

To view the full list of features, visit our [Pricing Page](https://bugbase.in/plans).

<figure><img src="/files/9kRqQiQvoO0IyNHGrnJS" alt=""><figcaption></figcaption></figure>

#### 2. The all new VDP Program

Companies can now host their own **Vulnerability Disclosure Programs (VDPs)** on BugBase. VDPs are a great way to receive real-time notifications for new vulnerabilities and also to build a strong relationship with the security community.

To start with creating a program, join BugBase by [clicking here](https://bugbase.in/register-company).

<figure><img src="/files/PrrmI1s1dNyfzjJUTWRZ" alt=""><figcaption></figcaption></figure>

### October 2022

#### 1. Secondary Notification Email

Now companies can configure an alternate email address to receive notifications.

This is useful for receiving notifications on a group email address or a specific team email rather than a personal email address.

* All notifications will be sent to the primary email address by default.
* If you want to receive notifications on the secondary email address, you can enable it in the [settings page](https://bugbase.in/company/settings/profile).

<figure><img src="/files/kQ1lJ99EWReQ00iwUmsr" alt=""><figcaption></figcaption></figure>

### September 2022

#### 1. All new Insights Dashboard

Now companies can efficiently analyse all the important statistic on the dasboard itself.

* Check the number of resolved and unresolved reports
* Insights of latest critical reports
* Report trends with respect to the severity of the report.
* Quickly get a glimpse of the risk factor, total vulnerabilities and issues.

<figure><img src="/files/2gdyAPfYFovvOvp5rCMZ" alt=""><figcaption></figcaption></figure>

#### 2. Add assets across programs:

Companies can now add all domains and subdomains as "assets" on BugBase and monitor bugs and vulnerabilities on specific assets. These assets can be used to create programs. Assets can be seamlessly managed on the asset dashboard.

<figure><img src="/files/q9ajhZPBU7kA7NaLKUuC" alt=""><figcaption></figcaption></figure>

#### 3. Risk level analysis

Companies can now have a quick glance of the total risk factor, this is done by all analysing the severity of all the bugs/vulnerabilities that have been reported.

<figure><img src="/files/W687dDul1AlzofwpMbrb" alt=""><figcaption></figcaption></figure>

### August 2022

#### 1. New workflow integrations to our integrations suite.

* **Asana Integration:** Now companies can seamlessly harness the power of Asana and transfer a bug report as a task, directly onto their Asana Project. A default section needs to be selected in the configuration, the bug report will automatically get created in the chosen default section.\
  Read this [guide](/integrations/asana) to learn more about the Asana integration.
* **GitHub Integration:** Now, a bug report can now be directly transferred to any selected GitHub repository. A new issue will be created in the selected repository to help companies efficiently track the reports.\
  Read this [guide](/integrations/github) to learn more about the GitHub integration.

<figure><img src="/files/X9Zevt57hf6JZI9RszzD" alt=""><figcaption></figcaption></figure>

We now support integrations with:

1. Jira
2. GitHub
3. Asana
4. Slack
5. Microsoft Teams
6. Webhooks

#### 2. Introducing Light Theme on BugBase

The entire platform is now available in dark and light themes.

<figure><img src="/files/MizE0ioGMMV2meALgASf" alt=""><figcaption></figcaption></figure>

#### 3. Revamped UI for onboarding a New Program

The new UI provides a seamless interface for creating a new program. Added a new and intuitive timeline based onboarding

#### 4. Added support for zip and mp4 files:

* Hackers can now submit Zip and Mp4 along with their bug reports
* Companies can upload zip and mp4 files as questions for the competitions

***

### July 2022

#### 1. Grouping of Assets / Scopes

Now you can group assets and scopes together and have a common bounty for each group.

<figure><img src="/files/zBKdRQiWtanUunwGqii6" alt=""><figcaption></figcaption></figure>

#### 2. New KYC System for Security Researchers

Now security researchers can verify their paymet via our KYC system.

This also gives them a `KYC Verified` tag which companies can use to pay bounties

Researchers can save their details and `Request for KYC Verification`

<br>


# Our Features

BugBase keeps businesses safe by providing an all-in-one platform to perform continuous and comprehensive security testing.

## Features we offer

### **1. Vulnerability Disclosure Program**

Provide ethical hackers across the world a legal channel to report their security findings to you. Having a VDP in itself makes a company **ISO 29147 Compliant**

### **2. Managed Bug Bounty Program**

An active crowdsourced security initiative. We streamline the process by **filtering bug reports**, managing payouts and more so that you can focus on resolving bugbase

### **3. Managed Private Programs**

Engage with verified, **skilled and elite ethical hackers** in our **Apollo Community** for fast-paced vulnerability assesment reports and see results in real-time

### **4. CTF Hosting & Hiring Challenges**

Recruitment of top security engineers is made easy by hosting a **competition** or **CTF** on the BugBase platform.

### **5. Enterprise Pentesting and VAPT**

Enterprise VAPT done right following **OWASP, NIST, NIC, SANS and CERT-In** guidelines covering all **compliance** requirements

### **6. One-Click Integrations**

Instantly integrate with your SDLC management software like **JIRA**, **Slack**, **MS Teams** and more, making active cybersecurity a part of your **workflow**

### **7. Rapid Report Triage**

BugBase's security team filters out spam, false positive and duplicate reports. Only **valid** and **unique** reports that matter to you are shared with **prioritised vulnerabilities**.


# Programs at BugBase

BugBase helps you host various crowdsourced security operations in one comprehensive dashboard where you can track, identify and mitigate vulnerabilities with ease.

## Program Types

There are 4 types of programs that can be hosted on BugBase

{% content-ref url="/pages/a12q8r5mk2zRoCGVqBEY" %}
[Vulnerability Disclosure Program (VDP)](/overview/programs-at-bugbase/vulnerability-disclosure-program-vdp)
{% endcontent-ref %}

{% content-ref url="/pages/uu2PvynzRbkM82WLTLY2" %}
[Bug Bounty Program](/overview/programs-at-bugbase/bug-bounty-program)
{% endcontent-ref %}

{% content-ref url="/pages/qWchP3hNtx8wUx76Bz1n" %}
[Private Bounty Program](/overview/programs-at-bugbase/private-bounty-program)
{% endcontent-ref %}

{% content-ref url="/pages/9U4oamEQ9k6aVclDYb96" %}
[Pentest Program (VAPT)](/overview/programs-at-bugbase/pentest-program-vapt)
{% endcontent-ref %}


# Vulnerability Disclosure Program (VDP)

Hosting a VDP is a great way to keep your application well protected and secured.

> Connect with the right researchers who help you identify and mitigate bugs and vulnerabilities in your application.

{% content-ref url="/pages/3UchUr1fprTJmkl37DPj" %}
[Create a Program](/company-guide/programs-dashboard/create-a-program)
{% endcontent-ref %}

## Features

#### Policy Design

The BugBase internal security team helps you create the perfect program policy to get started.

#### Report Inbox & Chat Resolution

Interact with security researchers on the Report chat section, resolve reports with their help

#### Integrations

BugBase provides integrations with popular SDLC management software like JIRA & Slack to provide a seamless experience and reduce the mean time to respond.


# Bug Bounty Program

An active crowdsourced security initiative. We filter bug reports so you do not waste time on distinguishing signal from noise

> This program covers all features from the [Vulnerability Disclosure Program](/overview/programs-at-bugbase/vulnerability-disclosure-program-vdp)

{% content-ref url="/pages/3UchUr1fprTJmkl37DPj" %}
[Create a Program](/company-guide/programs-dashboard/create-a-program)
{% endcontent-ref %}

## Features

#### Reward Structure

BugBase will help you create the perfect reward structure according to your budget.

#### Managed Conversations

The BugBase in-house security team triages and manage all incoming reports, so you can focus on fixing bugs and improving your application, rather than going through tons of reports and trying to figure out which ones are valid.

#### Managed Payouts

We handle all payouts and invoicing, so you don't have to worry about paying out researchers.


# Private Bounty Program

Private Bug Bounty program is an invite only bug bounty program where companies can choose to invite particular ethical hackers to test their application.

> **Private Bug Bounty Program** is Ideal for **first time testing** of production applications and **non-publicly accessible** targets such as staging environments, applications requiring credential access, or devices and fast-pace testing

A private program covers all features of a [Bug Bounty Program](/overview/programs-at-bugbase/bug-bounty-program) including managed triage, insights and more! Elite ethical hackers are given the opportunity to test

{% content-ref url="/pages/3UchUr1fprTJmkl37DPj" %}
[Create a Program](/company-guide/programs-dashboard/create-a-program)
{% endcontent-ref %}

## Features

#### Top Talent Pool

Access to Globally top vetted bug bounty hunters and cybersecurity researchers

#### Private Report Inbox & Chat Resolution

Interact with security researchers on the Report chat section, resolve reports with their help


# Pentest Program (VAPT)

Get an in-depth analysis of the security of your application and reduce any probability of a security breach.

Team Bugbase is equipped to perform enterprise security testing, offering a wide range of services that help organizations identify and fix security vulnerabilities. Our testing methodology is based on the OWASP Top 10 and NIST SP800-53 standards, as well as CERT-In and NIC guidance. We use a variety of penetration testing techniques to find vulnerabilities, exploit them and provide you with remediations.

Our internal elite security team is capable of testing:

1. Black Box Web Application Security Testing
2. Black Box Android Application Security Testing
3. Black Box iOS Application Security Testing
4. White Box Code Review

{% hint style="info" %}
PDF security report is available **3-4 weeks** after starting engagement. Certificate of security is only rewarded when P1 and P2 vulnerabilities have been resolved and sufficient proof has been provided.
{% endhint %}

### Commercials

The commercials for VAPT vary depending on the size and number of the applications to be tested

Please write to us at <queries@bugbase.in> or fill out the form on <https://bugbase.in/demo> for a quote


# Bug Report

A Report that is submitted on BugBase has comprehensive information about a vulnerability. Below are a few pointers that may help you to understand on how to analyse a report on BugBase

A Bug Report has the following information in it:

1. **Report Title**
2. **Report ID**
3. **Vulnerability Category**
4. **Affected Asset**
5. **Affected URL (Optional)**
6. **Severity Score (CVSS)**
7. **Priority (Based on Severity Score)**
8. **Vulnerability Impact**
9. **Proof Of Concept (POC) of the Vulnerability**
10. **Brief Summary of the Vulnerability**
11. **Attachments along with the POC (Optional)**
12. **Status of the Report**
13. **Reporter Details (Username of the Reporter)**

The company representative can converse with the reporter about the details of the vulnerability and discuss impact and remediations.

A Chat Functionality is provided in the Report View for a quick doubt resolution with the report in case more context is required on the **POC**.

Bug Reports can also be shifted to a different program in the same organization - companies usually do this to segregate reports by scope or confidentiality.

{% hint style="info" %}
Reporters are provided with an alias email by **BugBase,** in the format ***\[username]@teambugbase.com***, on which the reporter can receive emails. If any sensitive information is to be shared with the reporter, you can use the alias email to contact them.
{% endhint %}

Next, know more about the [**Report Lifecycle and Status**](/report-lifecycle/report-status)


# Report Status

Each Report on BugBase has a status associated with it to identify the stage of a particular vulnerability from submission to resolution

### Open Report Stages

The following stages indicate that a bug report is still open and has not been resolved:

**New**

When a bug report is first submitted, it is in the New stage. This stage is used to indicate that the bug report has not been reviewed by the program team yet.

The New stage is also indicates that the bug report has not been reviewed by the security team and is yet to be validated/triaged.

**Triaged**

When a bug report is triaged, it is moved to the Triaged stage.

This stage indicates that the bug report has been reviewed by the security team and is under going resolution.

{% hint style="info" %}
Marking a report **Triaged** rewards the bounty hunter with ***+10 points***
{% endhint %}

{% hint style="info" %}
Additionally, incase the **Proof Of Concept** is not clear the the security team, an additional label asking for **More Context** can be added to the report.
{% endhint %}

### Closed Report Stages

When a bug report is complete and no further action is needed, it is typically shifted to the Closed stage.

**Resolved**

The report is valid, and the program team has successfully addressed the impactful issue it describes. No further dialogue with the bounty hunter is needed, and the report can be considered complete and closed.

{% hint style="success" %}
Marking a report **Resolved** rewards the bounty hunter with additional points ranging from ***0-30 points*** depending on the **Severity** of the issue.
{% endhint %}

**Duplicate**

A duplicate issue is one that has already been reported previously. To ensure fairness and transparency, duplicates should be appropriately linked to the original report.

Handling duplicates:

1. **On BugBase**: Link the duplicate to the original by searching by the report ID or title.
2. **Different platform**: Add a reference ID and a screenshot as proof of the original report.

{% hint style="info" %}
Marking a report **Duplicate** rewards the bounty hunter with additional points ranging from ***0-7 points***
{% endhint %}

**Invalid/Spam**

The report does not describe a valid issue or vulnerability. When marking a report as invalid, security teams should provide a clear explanation of the reason. This feedback helps hackers understand the requirements more clearly.

Common reasons for invalid reports include issues or assets being out of scope or lacking sufficient evidence to demonstrate impact.

{% hint style="danger" %}
Marking a report **Invalid** will deduct ***5*****&#x20;points** from the bounty hunter.
{% endhint %}

#### Informational

An informational bug doesn’t cause operational issues or errors in the program but may offer useful insights for developers or users without affecting the software's normal functioning.

{% hint style="info" %}
Marking a report **Informational** does not reward the bounty hunter with any points.
{% endhint %}

{% hint style="warning" %}
Note: After 14 days of shifting the report status to a Closed Stage the report is automatically closed - this means that the chat window or any report actions will not be accessible.
{% endhint %}

### Report Status Label

A report status label provides additional context about the current state or requirements of a bug report

#### More Context Required

The report requires additional information from the bounty hunter to clarify certain aspects or provide more details.

#### Program Review Requested

The report is currently awaiting review by the program managers. The program team will assess the details of the report, and take the appropriate next steps.

#### Spam

Spam reports are flagged as invalid and given an additional status label for spam.

{% hint style="danger" %}
If the report is marked as **Spam**, the bounty hunter will have ***15*****&#x20;points** deducted.
{% endhint %}


# Invite Organization Members to BugBase (RBAC)

Learn how to set up Role-Based Access Control on your BugBase Dashboard and invite your team members.

**Note:** This feature is available only to **Enterprise Tier customers.**

### Pre-requisites

* BugBase Company Account with an Enterprise Plan.
* BugBase user accounts for team members.

### Inviting Members to Your Organization

1. Visit **`Settings`** **>> `People`** from your company dashboard on BugBase.

<figure><img src="/files/lBa5v0kOhwbkjYVESghj" alt=""><figcaption></figcaption></figure>

2. Click **`Invite Members`** and provide the email of the member you want to invite to your organization.

{% hint style="info" %}
Member emails should be the same domain as the company.
{% endhint %}

<figure><img src="/files/xA5oRXa8eMehkz066lLA" alt=""><figcaption></figcaption></figure>

3. Invited members will receive an invitation email, and you can view the list of members and their current status on the same page.

### Assigning Assets to Members

1. Visit **`Settings`** **>> `People`** from your company dashboard on BugBase and click on **`Manage Member`** from the Actions dropdown.

<figure><img src="/files/2ine3YnlO91kOd99rZSm" alt=""><figcaption></figcaption></figure>

2. Select the assets from the `"Asset Access"` dropdown that the user should have access to. You can also select if the member should apply for approval before assigning a bounty for a report by clicking on the checkbox.

<figure><img src="/files/FfvfsvcfC0nGvziCsQmw" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/YGohP9SVu51DFeyu0N7Y" alt=""><figcaption></figcaption></figure>

3. Click on **"Save".**

{% hint style="warning" %}
Note: Invited Users by default have **no assets** assigned to them, for triaging purposes assign them the required assets
{% endhint %}

### Assigning Roles to Members

1. Visit **`Settings`** **>> `Manage Access`** from your company dashboard on BugBase.

<figure><img src="/files/xBDG9oMBhKXD5IDK9rpC" alt=""><figcaption></figcaption></figure>

### **Giving Access to the Company Dashboard**:

1. Click on the company and **`"Invite Members"`** to add members and grant them access to your company dashboard.
2. Select the member from the dropdown, choose the role you want to assign, and click on **Assign Role** (e.g., **"Root User"** for full company dashboard access; this does not give access to all programs. To give access to all programs, select the **"Full Access"** role).

<figure><img src="/files/1rLKF6mkVJuP7qGcFXQi" alt=""><figcaption></figcaption></figure>

### **Giving Access to a Program Dashboard**:

1. Click on any program and **`"Add Member"`** to add members and grant them access to the selected program dashboard.
2. Select the member from the dropdown, choose the role you want to assign, and click on **Assign Role** (e.g., **"Program Admin"** for full program access).

<figure><img src="/files/gjls522yQWmFdwUJLXMP" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
You can choose from the Default Roles or create a Custom Role as per your requirement from **`Settings`** **>> `Roles & Permissions`**.
{% endhint %}

Learn more about Roles from the [Roles and Permissions](/company-guide/company-settings/roles-and-permissions) section.

{% hint style="success" %}
And that's it! 🎉 Congratulations you have successfully invited a member and assigned a role to them.
{% endhint %}


# Setup a Campaign for better program engagement

Learn how to set up a Time-Based Campaign on your BugBase Bug Bounty Programs to improve engagement.

### Pre-requisites

* User account on BugBase

{% hint style="info" %}
You can view all campaigns in **campaigns** page from company dashboard
{% endhint %}

{% hint style="info" %}
To start a new campaign click on **Create New Campaign** button
{% endhint %}

<figure><img src="/files/2kC4B4O1s766UFxsZDvm" alt=""><figcaption><p>Create New Campaign button in campaigns page</p></figcaption></figure>

Clicking the "Create New Campaign" button will display a form as illustrated below.

<figure><img src="/files/KoS74eW6l6jUPt3NVZZ1" alt=""><figcaption></figcaption></figure>

* The first step is to fill campaign identifier, this would be your campaigns title/name.
* Select the program that you would like to set up a campaign for better program engagement.
* Select the particular block that best describes your objective for this campaign.
* Click Initiate Campaign button. This will redirect to a new page where you will be asked for a few more details to finish setting up the campaign.

The page you are redirected into will look similar to this.

{% hint style="warning" %}
If you don't see this page, you can view it on **campaigns > (select your campaign shown in the list)** from your company dashboard.
{% endhint %}

<figure><img src="/files/ugMxxVpWTOcdAwu6FyCG" alt=""><figcaption></figcaption></figure>

*Here, previously filled details will appear along with some other fields.*

{% hint style="warning" %}
Remember, you can only make any change to this form if the campaign is ***not completed*** already.
{% endhint %}

* The very first one is program username, which would be pre-filled.
* Select the scope of the campaign, ie, choose the asset that should be targeted through this campaign.
* Now, you can customise the bounties you are allotting in this campaign, by clicking on select bounty table.

*Upon clicking on select bounty table it will look like this.*

<figure><img src="/files/PVTHTfMaM2dTVEUI9ANR" alt=""><figcaption></figcaption></figure>

* Click on Add Custom Bounty Values and it will show you a popup same as this.

<figure><img src="/files/zvUD7JssUjWwqJJrDYew" alt=""><figcaption></figcaption></figure>

* *Here you can provide the custom bounties you intent on giving in this campaign. Once finished, click on the add button, and it will show the bounty table box again, select your base bounty value from bounty table.*
* You can increase the base bounty amount if you click on the multiplier box below, it will be a list where you can select the amount of times you like the bounty to be increased to based on their priority.
* Then, you can select the time window where you would like the campaign to be active. If you select the start now option above the start date and end date box, it will set the campaign to start right after you complete this form and upon completing the end time that you select from the calendar shown to you, the campaign will cease to be active.
* Next you can provide any information to the security researcher that you think will be relevant while the bounty hunter is trying to penetrate the asset you listed.

<figure><img src="/files/P96PQZH1uOjB7YDPReg5" alt=""><figcaption></figcaption></figure>

* Upon completing all these details, you can see a preview of the campaign with all the details you entered. If you find any of these not accurate, you can scroll up and make changes in the form.

<figure><img src="/files/dEEhj4Q03LdUXtiS9Xon" alt=""><figcaption></figcaption></figure>

* When you click on the Save Campaign button at the end of the form your campaign will go live at the start time you specified with all the details.
* You can always come back and edit the end time of the campaign, if it's not completed already

{% hint style="success" %}
And that's it. You have successfully created a campaign 🎉.
{% endhint %}

{% hint style="info" %}
In case you have any queries, Please reach out to use at <queries@bugbase.in>
{% endhint %}


# Submit a Bug Report on BugBase

Learn how to submit a bug report for a program listed on BugBase as a security researcher.

### Pre-requisites

* User Account on **BugBase**. You can [**Register here!**](https://bugbase.in/register)

### Submitting a report

1. Login to your BugBase account and visit **`Programs`** page.

<figure><img src="/files/bw9PvLGjqkl2KuVMOxiy" alt=""><figcaption></figcaption></figure>

2. Click on the program on which you want to submit the bug report from the list of all available programs.

<figure><img src="/files/trmbHiDXGwseW8HbadP0" alt=""><figcaption></figcaption></figure>

3. After reading the Program Policy and Scopes carefully, click on the **`Submit Report`** button.

<figure><img src="/files/5N8xRF6RKciFDNb0Yxxj" alt=""><figcaption></figcaption></figure>

4. Enter the `Scope`, `Vulnerability Type`, `Severity`, `Summary`, `Attachments` and other details about the bug.

{% hint style="info" %}
You can use the **CVSS Calculator** to determine the severity of your bug.
{% endhint %}

<figure><img src="/files/OVdscYGPiQp5o0ZpKlOl" alt=""><figcaption></figcaption></figure>

5. Review all report details before the final submission by clicking on **`Submit Report`**.

{% hint style="success" %}
And that's it! 🎉 Congratulations on submitting a new Bug Report on **BugBase**.
{% endhint %}

{% hint style="info" %}
You can also draft the report and view it later by clicking on **`Save As Draft`** button.
{% endhint %}


# Create a Bug Bounty Program on BugBase

Learn how to create and setup a Bug Bounty Program on BugBase

### Pre-requisites

* Company Account on **BugBase**. You can [**Register here!**](https://bugbase.in/register)

### Create a Bug Bounty Program

1. Login to your BugBase account and visit **`Programs`** page from your company dashboard.
2. Click on the create new Program button.
3. Select the type of Bug Bounty program you want to create.

{% hint style="info" %}
Private Bug Bounty is ***Exclusive for selected researchers.***
{% endhint %}

{% hint style="info" %}
Public Bug Bounty is will be ***open to entire BugBase bounty hunter community.***
{% endhint %}

1. **Enter username** for the program you wish to create.
2. **Define scope of your program**

{% hint style="info" %}
Click on **Add an Asset** button to create a new asset.
{% endhint %}

**Defining scope in your program** ( Create scope groups ).

* Enter scope group name
* Select the type of scope group label
* select if the scope group should be in-scope or out of scope

{% hint style="warning" %}
**In scope** - bounty hunters ***are allowed*** to penetrate the scope group\
**Out scope** - bounty hunter ***are not allowed*** to penetrate the scope group
{% endhint %}

* Select if swags are given along with bounty on successful report submission
* Enter the bounty values provided based on report priority
* Select multiple assets you wish to add to the scope group.

{% hint style="info" %}
To create a new scope group click on the **"Create New Scope Group"** button
{% endhint %}

* Click on the next button

3. **Define participation guidelines:**

* Check yes if you want reports on issues outside the scope
* Check yes if your program abide by conduct for good-faith security research
* Check yes if you wish to give the opportunity to the hacker to request to make the reports public after resolution
* Click next

4. **Provide specific areas of concern**. (This could include any surface like login/registration page, any panel etc.

* Click next

5. **Provide additional details**

* Select the type of activities you want the researcher to get into while they are working on your program.
* Select the type of environments your assets are running in, you can select multiple values if there are multiple assets
* Select the technologies and frameworks used on these assets you selected before.

**Rules of Engagement**

* Check yes if you want to collect all the IPs of the reporters in this program
* Check yes if you want to allow multiple researchers to collaborate with one another while testing your program
* Specify a custom user agent the hacker should include in their requests to your asset to track
* Enter the max number of requests allowed per second
* Specify a custom header the hacker should use to track their activities
* Click next

6. **Brand your program**

* Upload a program image
* Select a colour for program banner
* Fill out program name (this should be different from program username you entered before.
* Write a program tagline for hackers to see when they view program
* Mention the program website (Mention your main website)
* Write a description for your program

7. **Schedule your program Launch**

* Select when you want your program to go live from calendar
* click next

8. **Review your program**

* Check all the details you filled in all these steps and you can go back and edit any of these section if you click on the edit icon in their respective section
* You can also go back to the respective section if you click on the left sidebar by clicking on the section you want to go back to.

{% hint style="info" %}
Click on the **Save and Continue Later** button if you want to resume creating the program in another time.
{% endhint %}

{% hint style="success" %}
You have successfully created your Bug Bounty program with BugBase 🎉
{% endhint %}


# Download the mobile app

Bugbase offers a mobile app that can be installed directly from your browser

**Bugbase** offers a mobile app that can be installed directly from your browser, providing an app-like experience on your mobile device without the need for traditional app stores. Follow these steps to install the Bugbase mobile app:

#### Step 1: Open the Website

* Open the browser on your mobile device.
* Navigate to [https://bugbase.ai](https://bugbase.ai/).

#### Step 2: Add to Home Screen

* Access the browser options by tapping the **Menu** button (usually symbolized by three dots or lines).
* Tap on **Add to Home Screen** from the menu.
* You may be prompted to name the shortcut before adding it. You can name it "Bugbase" or any name you prefer.
* Confirm by tapping **Add**.

#### Step 3: Install the App

* Once added to your home screen, the Bugbase icon will appear amongst your other apps.
* Tap on the Bugbase icon to open the app in a full-screen experience, similar to any other installed app.

#### Step 4: Use the App

* After opening the app, you can log in with your credentials or sign up to access all features available on the Bugbase platform.
* Enjoy the seamless experience of participating in bug bounties right from your mobile device!

#### Note:

* The process of adding the app to your home screen might vary slightly depending on the browser and the operating system (iOS, Android) of your mobile device.
* For iOS users, open the website in Safari, tap the share icon at the bottom of the screen, and then select **Add to Home Screen**.

For further assistance or any issues with installation, please contact our support team at <queries@bugbase.ai>


# Create a Company Account

We at BugBase have made it really easy to create a company account. All you need to do it fill a 2 step form to register your account with BugBase

## Basic Details

Fill in some basic details about your Company

<figure><img src="/files/IcbHTkxaakTA8SUGNG72" alt=""><figcaption><p>Register Company Form - Step 1</p></figcaption></figure>

## BugBase Account Details

Choose a **username** for your account (preferably your company name in **lowercase**) and entering your **password**.

Once this step is completed, all that is

<figure><img src="/files/DQtIOjldpxDwT4YimZDq" alt=""><figcaption><p>Register Company Form - Step 2</p></figcaption></figure>

## Verify Email

Lastly, check your inbox for a verification email and you should be redirected to the login page.

<figure><img src="/files/OUXaDShBXgYjDzUmglAK" alt=""><figcaption><p>Verify Register Email</p></figcaption></figure>

And that's it!

You can now start **Creating Programs** by logging into your account


# Navigation

Here is an overview for navigation that can be found in the Bugbase platform

### **Insights Dashboard**

The insights dashboard provides a **comprehensive overview** of **vulnerabilities** throughout all the programs with the help of **graphs**, **charts** and **risk statistics** to improve security practices.

<figure><img src="/files/W3NDyD1Jp6QX2i4WUuFw" alt=""><figcaption></figcaption></figure>

{% content-ref url="/pages/khuNinhRSsg6GMasZsmw" %}
[Insights Dashboard](/company-guide/insights-dashboard)
{% endcontent-ref %}

### **Assets Dashboard**

The Assets Dashboard in Bugbase allows program managers to easily manage and **track** their assets, with features like **adding**, **editing**, **deleting**, and **labeling assets** to improve understanding.

<figure><img src="/files/sue1hVpahgKvlJdJsheL" alt=""><figcaption></figcaption></figure>

{% content-ref url="/pages/csMKsT2QZY0Rdi7O6X5z" %}
[Assets Dashboard](/company-guide/assets-dashboard)
{% endcontent-ref %}

### View All Programs

Programs section in BugBase allows program managers to view all ongoing and under review programs. It also allows them to sort programs based on their types, making it easy to find and manage specific programs.

<figure><img src="/files/IZB57PCZWCoU8KEUuDcb" alt=""><figcaption></figcaption></figure>

{% content-ref url="/pages/F5Nh96UcXaqTHwdTFkuy" %}
[Programs Dashboard](/company-guide/programs-dashboard)
{% endcontent-ref %}

### **Billings & Plans**

All the billings, transactions history, add-ons in one place. Companies can upgrade their tiers and purchase add-ons from this section.

<figure><img src="/files/JZH4qv6lq0PI5R01eifz" alt=""><figcaption></figcaption></figure>

### Bounty Bin

Companies can manage their **payouts** via this page, **top-up** their bounty bin amount and start **paying out** researchers

<figure><img src="/files/Gk1ER7S0hGEwrWfaqviA" alt=""><figcaption><p>Bounty Bin</p></figcaption></figure>

{% content-ref url="/pages/HVLiTTFuVOJunmeR6Jnk" %}
[Bounty Bin](/company-guide/bounty-bin)
{% endcontent-ref %}

### Company Settings

Companies can edit their **profile**, **manage passwords**, **manage members** in their **organisation**, **manage access** to programs from their settings

<figure><img src="/files/5ZYVfFucQQWPlYJxTJqH" alt=""><figcaption></figcaption></figure>

{% content-ref url="/pages/UZ9q9OmqikUbDJYNfwsv" %}
[Company Settings](/company-guide/company-settings)
{% endcontent-ref %}


# Assets Dashboard

The Assets Dashboard in Bugbase allows program managers to easily manage and track their assets, with features like adding, editing, deleting, and labeling assets to improve understanding.

The Assets Dashboard is a user-friendly feature that streamlines the asset management process, helping program managers to stay organised and on top of their bug bounty program.

<figure><img src="/files/8b7lTicTM95zkXDNFM4H" alt=""><figcaption></figcaption></figure>

### Adding an Asset

Adding an asset is easy, simply click the "Create Asset" button, fill in the necessary details such as the asset name, URL, asset type, and labels and click the "Save" button. In case of websites, the URL is to be filled, and in case of mobile applications, the link to the respective app store is to be filled. Labels can be added to an asset, such as development, staging, or stack environment, to help hackers better understand the assets. This allows them to identify and report vulnerabilities more efficiently.

<figure><img src="/files/CVnpc0XBn3paP2XyGUZ3" alt=""><figcaption></figcaption></figure>

### Editing an Asset

Editing an asset is just as simple, by clicking pencil button next to existing asset name from the list, program manager can make necessary changes to the asset information. The program managers can also delete an asset by clicking on the cross button next to the asset name. This feature makes it easy for program managers to keep track of their assets, ensuring that all information is up-to-date and accurate, making it easier for hackers to identify and report vulnerabilities.

<figure><img src="/files/fviQRD0Z1hSboi7BvFZ5" alt=""><figcaption></figcaption></figure>


# Credential Vaults

BugBase enables importing testing credentials for assets and assigning them to program members and Bug Hunters.

A Credential Vault contains **sets of testing credentials** for a particular asset on BugBase. These vault credentials can be imported on your BugBase Dashboard via a CSV file

Companies can manage their credentials and assign credential sets to Bug Hunters on their respective programs.

You can view all **Credential Vaults** in the Asset Page itself

<figure><img src="/files/Oxih5Eq7ahKhfvxSbdJ3" alt=""><figcaption></figcaption></figure>

## Quick Setup

Follow these setup guides to get started with Credential Management on BugBase

### 1. Creating a Credential Vault

{% content-ref url="/pages/XAZ3bxjNoJZu9JsdnK2U" %}
[Creating a Credential Vault](/company-guide/credential-vaults/creating-a-credential-vault)
{% endcontent-ref %}

### 2. Adding Credentials to Vault

{% content-ref url="/pages/YqYd5yLr6X8KKZ4S8Zp8" %}
[Adding Credentials to Vault](/company-guide/credential-vaults/adding-credentials-to-vault)
{% endcontent-ref %}

### 3. Connecting Credential Vault to an Asset

{% content-ref url="/pages/7pKBvxit5CEDBUbQ3fAE" %}
[Connect Credential Vault to an Asset](/company-guide/credential-vaults/connect-credential-vault-to-an-asset)
{% endcontent-ref %}


# Creating a Credential Vault

Learn how to create a Credential Vault

### 1. Navigate to Credentials Tab on your BugBase Dashboard

After Logging In, Click on the **Assets Dashboard** Icon and **Choose Credentials Tab**

<figure><img src="/files/oM8vsza5O0KRlCAWyrAD" alt=""><figcaption></figcaption></figure>

Click on Create a Vault

### 2. Add Details for the Vault

<figure><img src="/files/WkW1CwKWFPUnSY4Lpk7q" alt=""><figcaption></figcaption></figure>

Details Include:

1. **Vault Name** - Descriptive Name for the Credential Vault
2. **Instructions** - Any Instructions to be given to Bug Hunters on how to go about using the assigned credentials
3. **Vault Type** - There are mainly two types of **Vault Type - Static & Dynamic** more about them below.

### 3. Choosing a Suitable Vault Type

#### Static Vault

Credentials in these vaults are non-assignable and if claimed the whole credential set will be available to the Bug Hunter.

Generally a static vault would be created in-case testing credentials remain the same for a long period of time.

#### Dynamic Vault

Credentials in these vaults are assignable and only one particular credential set can be claimed by the Bug Hunter

Generally a dynamic vault would be created in-case testing credentials need to be curated for a specific privilege level for a particular user.

There are **Assignment Preferences** for a **Dynamic Vault:**

<figure><img src="/files/fXh4oPmxUOqheV0BJ5Lm" alt=""><figcaption></figcaption></figure>

1. **Auto-Assign Credentials:** When a Bug Hunter requests to claim a credential set, any unassigned credential set is automatically assigned to the Bug Hunter. Incase there is no credential to claim the company would be e-mailed to add more credential sets.
2. **Request Based Assign:** When a Bug Hunter requests to claim a credential set, a notification to the company is sent in order to assign a credential set to the Bug Hunter.

{% hint style="success" %}
And That's It! :tada: Congratulations you've successfully created a **Credential Vault.**
{% endhint %}

Now Up Next is adding credential sets to a Vault


# Adding Credentials to Vault

Learn how to add Credential Sets to a Credential Vault

### 1. Navigate to Credentials Tab

Select a Vault in which you would like to import Credentials into.

<figure><img src="/files/vAX4j4XnaaIMDbT09S3r" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
In this case we are using a **Dynamic - Request Based Assign** Vault Type
{% endhint %}

### 2. Click on Add Credentials

<figure><img src="/files/avghY8qgsdIMSbrhi9O6" alt=""><figcaption></figcaption></figure>

### 3. Choose and Upload your Credentials in CSV Format

<figure><img src="/files/REq8rOTEy4DK5OGGZjIp" alt=""><figcaption></figcaption></figure>

#### How to structure & upload credentials?

Follow the steps below to structure & upload your credentials in a CSV File.

1. Download the[ Sample CSV](https://bugbase.s3.ap-south-1.amazonaws.com/util/sample.csv) template and fill in the credentials you would like to add.
2. Enter the credentials which you would like to assign to bug hunters, you can add custom fields such as - *API Keys, Access Tokens, Username, Passwords etc*.
3. Once the Credentials CSV file is ready, upload it below (Only CSV Files supported upto 25MB).

{% hint style="danger" %}
For request-based dynamic vaults, the CSV file must include a **"bugbaseusername"** column containing the user's BugBase platform username for proper assignment.
{% endhint %}

### 4. Preview Uploaded Credentials

Once the uploaded CSV is in a correct format, Credentials would show up in a table.

<figure><img src="/files/A6gjDLRIHmwkpwvl9ySa" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
:tada: Congratulations you've successfully **Added Credentials to a Credential Vault**
{% endhint %}


# Connect Credential Vault to an Asset

Learn how to connect a Credential Vault to a Company Asset

{% hint style="info" %}
**NOTE:** Only **1 Dynamic Credential Vault** can be linked to a particular asset
{% endhint %}

### 1. Navigate to the Assets Dashboard

Click the **Edit Icon** of the Asset to which you want to connect a Credential Vault.

<figure><img src="/files/mmbaBkhkA6aXFOHmLvgK" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
In this case we are using a **Dynamic - Request Based Assign** Vault Type
{% endhint %}

### 2. Select the desired Credential Vault

A **Credential Vault** dropdown should populate all the credentials in the company, you can select the credential vault you wish to connect this asset with.

<figure><img src="/files/BS7NnKDSrlQaTO7jA4Xy" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
:tada: Congratulations you've successfully **Connected a Credential Vault with an Asset**
{% endhint %}


# Require Whitelisting for a Credential

Enable the "Require Whitelisting" feature on Dynamic Credential Vaults to ensure only authorized users can request or claim credentials

{% hint style="info" %}
Whitelisting is only applicable for **Dynamic Credential Vaults**.
{% endhint %}

### Enable whitelisitng on a dynamic credential vault:

1. Navigate to the Credential Vaults and choose the desired **Dynamic Vault**.
2. Edit Credential Vault and toggle the choice for "**Require Whitelisting**"
3. Save the changes

<figure><img src="/files/jODWe4BTgA4J3p8Fp4Gy" alt=""><figcaption></figcaption></figure>

User will then be prompted to submit a whitelisting request when trying to request for credentials. This request can then be approved by the company on whitelist section. [Whitelist](/company-guide/whitelist)

When request for whitelist is approved for a user:

1. **Auto-Assign Vaults:**
   * If credentials are available, the system will automatically assign them to the user.
   * If no credentials are available, the user will be provided the option to click **Claim Asset** to manually proceed.
2. **Request-Based Vaults**:
   * A credential request will be automatically generated on the linked vault. A CSV file using user's BugBase username can be uploaded to assign the credential.


# Resolving Issues on Credentials

Security Researchers raise issues on credentials

### Steps to Access and Manage Credential Issues

#### Step 1: Navigate to the Credential Vault Page

* Open the program and locate the **Credential Vault Page**.

#### Step 2: View Reported Issues

* In the credential vault, find the **Issues Column** within the credentials table. This column displays all reported issues.

<figure><img src="/files/dCB9l7MWIHN356aT255H" alt=""><figcaption></figcaption></figure>

#### Step 3: Access Issue Details

* Click on the specific issue you wish to review. This will open the **Credential Issue Report**, which includes the reporter's information and details regarding the issue.

#### Step 4: Resolve the Issue

* After reviewing the issue, you can take action to resolve it. Provide a **resolution note** outlining how the issue was addressed.
* Once the issue is resolved, you can close it. This will notify the security researcher.

<figure><img src="/files/GfZYfq1mn76qby7fkan7" alt=""><figcaption></figcaption></figure>


# VPN Servers

BugBase enables companies to create and manage VPN servers for secure testing of sensitive assets by Bug Hunters.

A VPN server acts as a secure gateway for a specific group of asset, ensuring controlled access and monitoring of testing activities conducted by Bug Hunters.

These VPN servers can be set up and configured directly from your BugBase Dashboard.

You can view and configure all **VPN servers** from the Assets page in the Company Dashboard.

You control exactly what a VPN exposes and to whom: whitelist **company assets or custom URLs**, keep servers **hidden from bug hunters until you explicitly make them visible**, and **test a server yourself** before rolling it out.

<figure><img src="/files/3LG3cCWB701ioqeLX8sp" alt=""><figcaption><p>VPN Dashboard</p></figcaption></figure>

## Quick Setup

To get started with VPN servers on BugBase, follow these setup guides:

### 1. Create, configure and deploy a VPN server

{% content-ref url="/pages/cJ2ySYTqBXAX99q7tWHR" %}
[Create, Configure and Deploy VPN server](/company-guide/vpn-servers/create-configure-and-deploy-vpn-server)
{% endcontent-ref %}

### 2. Monitor Live Statistics and Logs

{% content-ref url="/pages/JSaNE58RdurpE01OSqQ0" %}
[Monitor Live Statistics and Logs](/company-guide/vpn-servers/monitor-live-statistics-and-logs)
{% endcontent-ref %}


# Create, Configure and Deploy VPN server

Learn how to configure and deploy a VPN server with all your assets on BugBase

## Pre-requisites

* Have a Company Account on BugBase

## Creating & Configuring a VPN Server

To create and configure a VPN server:

1. Login to your company dashboard.
2. Navigate to the **Assets** Page via the sidebar, then choose the **VPN** tab.
3. Click on "**Create VPN.**"<br>

   <figure><img src="/files/3LG3cCWB701ioqeLX8sp" alt=""><figcaption><p>VPN Dashboard</p></figcaption></figure>
4. Configure your VPN server by adding the following details:

   1. **Server name:** Assign a descriptive name to your VPN server.
   2. **Set rate limit:** Establish a rate limit for your VPN server to ensure optimal performance and prevent overuse. Add the rate limit in ***requests per minute.*** This helps in managing the server load effectively and ensures a stable connection for all authorised users.
   3. **VPN Server Location:** Select the countries from which you would like your bug hunters to have access.
   4. **Domains:** Choose all your sensitive domains. You can include an active time range for testing this domain and also add blacklist routes.

   <figure><img src="/files/v0CTVAOZf8u4Umi0xo1V" alt=""><figcaption><p>Create VPN server</p></figcaption></figure>

   \
   **Adding domains to VPN server**

   **( You can add multiple targets to a VPN server )**

   1. **Select an asset,** ***or*** **enter a custom URL:** For each target you can either pick one of your company assets from the dropdown, **or** type a **custom URL / host / IP** in the *"Or whitelist a custom URL"* field. A custom target can be a bare host (`app.example.com`), an IP (`10.0.0.5`), or a `host:port` (`app.example.com:8443`) — paths and non‑standard ports are supported.\
      *<mark style="color:green;">**Tip:**</mark>* Only the **host (and port)** is used for whitelisting — the VPN routes traffic to that host, so a full URL like `https://portal.example.com:444/app` is accepted and reduced to `portal.example.com:444`. [Click here to learn how to add assets.](/company-guide/assets-dashboard)
   2. **Active Time Range:** Specify an active time range when you want the bug hunters to access the target on a daily basis. The hours selected will default to the UTC timezone.
   3. **Add Blacklist Routes:** You can blacklist API routes that you do not want bug hunters to access, even through the VPN.<br>

   <figure><img src="/files/aHpHwOndTbt29tw0vdLr" alt=""><figcaption><p>Add Assets to VPN</p></figcaption></figure>

Once you have added all the details, click on **"Create VPN Server"** to create the server.

{% hint style="info" %}
Now, you have successfully configured your VPN Server. It's time to deploy the server. :tada::tada:
{% endhint %}

## Deploying the VPN server

1. Click on **"Deploy Server"** to deploy the server.\
   *<mark style="color:red;">NOTE:</mark>* <mark style="color:red;">Deployment might take 1-2 minutes. DO NOT CLOSE THE PAGE.</mark>
2. Once the server status changes to "<mark style="color:green;">**running**</mark>," your VPN server is ready for use.

<figure><img src="/files/n9DuXc9OEA7g68p1aMdJ" alt=""><figcaption><p>Deploy server</p></figcaption></figure>

## Whitelist the VPN's public IP

If your targets sit behind a firewall or IP allow‑list, allow the VPN server's **public IP** so traffic from bug hunters (which egresses through the VPN) can reach them.

1. On the VPN page, copy the **IP Address** shown for the server — this is the VPN's **public IP**.
2. Add that IP to your target's firewall / WAF allow‑list.

{% hint style="info" %}
All traffic from a connected bug hunter to your whitelisted targets leaves the VPN from this single public IP, so allow‑listing it is all that's needed. Only the targets you added are reachable through the VPN — everything else is blocked.
{% endhint %}

## Test the VPN yourself (sanity check)

Before exposing the VPN to bug hunters, you can generate your **own** connection profile to verify it works end‑to‑end.

1. On a **running** VPN server, click **"Download My Config"**.
2. Import the downloaded `.ovpn` file into any OpenVPN client and connect.
3. Confirm you can reach your whitelisted target(s) while connected — and that other destinations are blocked.

## Make the VPN visible to bug hunters

VPN servers are **hidden from bug hunters by default**. When you're satisfied with the configuration, expose it using the **"Visible to researchers"** toggle on the VPN page.

* **Off (default):** No bug hunter can see, download, or use the VPN — even on programs whose in‑scope assets it covers.
* **On:** Bug hunters who are accepted members of your program (and not blacklisted) can download the config and connect.

{% hint style="info" %}
Turning the toggle **off** at any time immediately revokes bug hunter visibility and access across every VPN endpoint.
{% endhint %}

## Updating the configuration

1. To update the configuration of the VPN server, simply update the values and click on\
   **"Re-deploy Server".**

<figure><img src="/files/QJ4dcLE2iT0YPapN1PxI" alt=""><figcaption><p>Re-deploy server</p></figcaption></figure>

## Stopping the server

1. When your server status is "<mark style="color:green;">**running**</mark>," click on the **"Stop Server"** button to stop the server.

<figure><img src="/files/1hiQ5fOVuw6Mvs6nLGCC" alt=""><figcaption><p>Stopped VPN server</p></figcaption></figure>


# Monitor Live Statistics and Logs

Monitor all the activities through the VPN server

## Monitor Live Statistics

### 1. **Accessing the Stats Page**

1. To view live statistics, go to your VPN servers list from company dashboard.
2. Click on the specific VPN you want to monitor.
3. Choose the **"Stats"** tab.

<figure><img src="/files/Rw6Lo3OWB8jip5BTSsqJ" alt=""><figcaption><p>VPN Live stats dashboard</p></figcaption></figure>

## 2. Features of Stats Page

In the stats page, you get access to the following details:

1. **Active VPN users:** Displays the total number of users currently connected to the VPN.
2. **Countries:** List of all the countries the users are from and number of users from each country.
3. **Global Heat Map:** Visualizes the distribution of users across the globe.
4. **Users per Country:** Shows a breakdown of users by country.
5. **User Connection Details:** Lists each user along with their connection since timestamp and click on the user to view more details.

<figure><img src="/files/BBWitLxqA1dBnKDutNbX" alt=""><figcaption><p>User details</p></figcaption></figure>

## Monitor Logs

### 1. **Accessing the Logs Page**

1. To view live logs, go to your VPN servers list from company dashboard.
2. Click on the specific VPN you want to monitor.
3. Choose the **"Logs"** tab.

<figure><img src="/files/z3lRchDI8mJEE2bCpYrI" alt=""><figcaption><p>Logs page</p></figcaption></figure>

## 2. Features of Logs Page

The Logs page shows the connections bug hunters make to your targets through the VPN. Each entry records:

1. **Timestamp:** The exact time the connection was made.
2. **Request URL / Destination:** The target host (and port) the bug hunter connected to.
3. **Username:** The bug hunter who made the connection.

You can filter the logs by username, destination host, and time range, and page through the results.

<figure><img src="/files/esyXJbRhpK8Cxhlj2pLJ" alt=""><figcaption><p>Log details</p></figcaption></figure>

{% hint style="info" %}
Logs are captured at the connection level (who connected to which target, and when) — bug hunter traffic is **not** decrypted, so encrypted request contents are never inspected or stored.
{% endhint %}

{% hint style="warning" %}
Statistics and logs populate only while bug hunters are connected and generating traffic. A newly deployed VPN with no active users will show empty stats and logs — this is expected.
{% endhint %}


# Programs Dashboard

An overview of all the programs hosted on BugBase

The Programs section in Bugbase allows program managers to view all ongoing and under review programs. It also allows them to sort programs based on their types, making it easy to find and manage specific programs.

The programs types are:

* VDP
* Bug Bounty
* Pentest
* Private Program
* Competitions

Program managers can click on "View Dashboard" button to view individual progams.

Program managers can also create new programs by clicking the "Create Program" button, providing a simple and straightforward way to launch new bug bounty programs.


# Create a Program

How to go about creating a program

{% hint style="info" %}
Pre-requisite: Have a **Company Account** on BugBase
{% endhint %}

{% content-ref url="/pages/9E9NQhwIg1plgHh2NFf5" %}
[Create a Company Account](/company-guide/create-a-company-account)
{% endcontent-ref %}

## All Programs

Once logged into your Company Account on BugBase. Navigate to the Programs Section.

<figure><img src="/files/IZB57PCZWCoU8KEUuDcb" alt=""><figcaption><p>Programs</p></figcaption></figure>

All your verified and under-review programs will appear here!

### Create a Program

1. Click on the "**+ Create New Program**" button beside the search bar.
2. Once clicked a modal will appear asking which program you want to create

   <figure><img src="/files/4yL7IYw6g5SrPTYkEMNQ" alt=""><figcaption><p>Create Program Modal</p></figcaption></figure>
3. Click on **Start** to continue to the onboarding screen
4. Go through the seamless onboarding experience and fill out all the required details, once submitted for review. Our Team usually verifies the program under 24 Hours.

{% hint style="info" %}
Verification of Programs are required only for **VDP**, **Bug Bounty** and **Private Bug Bounty** **Programs**
{% endhint %}


# Customer Support

24/7 Support Channel for Issues and Doubt resolution

BugBase Provides **24/7** chat support for clients.

<figure><img src="/files/hlu0WCaVcS8Qp1vbIvlK" alt=""><figcaption><p>Customer Support - Company</p></figcaption></figure>

For each client **customised customer support** is assigned based on their chosen plan. There are three types of service being provided.

We offer multiple convenient channels for clients to reach us and receive assistance:

1. **Email:** You can contact us at any time by sending an email to <queries@bugbase.in>. Our team is diligent in monitoring this inbox, ensuring timely responses to your inquiries.
2. **Chat:** Our 24/7 chat support service is available round the clock, providing you with immediate access to our support team. No matter when you need assistance, our chat support is here to help.
3. **Phone:** If you prefer a more personal touch, clients can reach us via phone during our business hours on working days. Our knowledgeable and friendly staff will be ready to assist you with any questions or concerns you may have.


# Bounty Bin

BugBase Bounty Bin helps you track and manage bounties paid to hackers across the globe!

{% hint style="warning" %}
This feature is available only to **Professional** & **Enterprise Tier Customers**
{% endhint %}

As soon as your BugBase account will be created and all the onboarding setup are completed, our team will create your **BugBase Bounty Bin** that acts as a bin from which we will be paying out the bounties.

## Add money to Bounty Bin

To top-up your Bounty Bin, you can simply follow the below steps:

1. Go to **Bounty Bin**
2. Now, Transfer funds to the **Bank Account number** or **UPI address** listed on the bounty bin page to add balance to your bin.

> Note: There is a limit to fund transfer via **UPI** which is **< Rs. 1,00,000**

## Manage transactions

From the Bounty Bin Page itself you will be able to:

1. Manage your Bounty Bin amount
2. Track all the bounty remitted to hackers - The typical time to remit payment to hackers is 2-7 days.
3. Download invoices for each pay out
4. Track history of bounty bin top-ups

With BugBase taking care of your payments, you don't have to worry about:

* KYC Verification of hackers
* Compliance
* Taxation


# Company Settings

Manage your company account from here

Edit your **Company Profile**, **Invite Members to your Organization**, **Manage Access** to programs. View & Track bugs by members assigned and more!

### Navigate

{% content-ref url="/pages/P2ekdPaIOyV0ZhClMeIy" %}
[Profile](/company-guide/company-settings/profile)
{% endcontent-ref %}

{% content-ref url="/pages/PT5IuZe23vBMGj0RdUyS" %}
[Organisation](/company-guide/company-settings/organisation)
{% endcontent-ref %}

{% content-ref url="/pages/VK0IOPWRrZYOqUI3g54F" %}
[Manage Access](/company-guide/company-settings/manage-access)
{% endcontent-ref %}


# Profile

Your profile page displays the following details of your organisation:

* Company Username
* Company logo
* Company Email
* Company Secondary Email
* Representative Name
* Contact Number
* Website Link
* Country of Origin

The root account can edit all these items on the profile page.

## Company Secondary Email

You can add a secondary email to your company where in you will be sent all the updates and notifications from team BugBase.

<figure><img src="/files/5ZYVfFucQQWPlYJxTJqH" alt=""><figcaption><p>Profile Section</p></figcaption></figure>


# Organisation

Add members to your organisation and track all activities.

{% hint style="warning" %}
This feature is available only to **Enterprise Tier Customers**
{% endhint %}

To manage your team members you can go to **Settings > People**. From here you can manage all users across your company.

{% hint style="info" %}
All root admin accounts can **add**, **edit** or **remove** any member from the company.
{% endhint %}

## Add Member

To invite any member or an employee to your BugBase account, you can simply:

1. Go to Settings > People.
2. Click on Invite Members.
3. Provide the email of the member that you want to invite. Note that email needs to have the same domain as your **company account email**.
4. Give them an identifier - An identifier can be a name, designation, or any other information that can be used to identify the invitee.
5. Click on send invite.
   1. The invitee will get a request to accept or reject the invite over email. Once the invite is accepted, they will be added to your BugBase company account.

Voila! You can now start giving them access to different programs and also check their activity on BugBase.

<figure><img src="/files/RjGjKuUl1pPE0RTXvLLr" alt=""><figcaption></figcaption></figure>

## MFA Status

You can also view if the member has enabled multi-factor authentication (MFA) on their BugBase account or not as an additional security measure.

<figure><img src="/files/C8X3NI8D2EAXuA11jr6h" alt=""><figcaption></figcaption></figure>

## Edit Member

To edit any member or an employee to your BugBase account, you can simply:

1. Go to Settings > People
2. Click on edit button.
3. Now you can edit the identifier that was previously assigned to the member.

<figure><img src="/files/FvNcLO9pkLTOvWtZH96c" alt=""><figcaption><p>Edit member</p></figcaption></figure>

## Delete Member

To delete any member or an employee to your BugBase account, you can simply:

1. Go to **Settings** > **People**
2. Click on the delete icon on a specific member.
3. Confirm your action - by deleting member from the company will revoke their access from all the programs that they have been added into.

<figure><img src="/files/7hvH5iYmfeYIfhLlo5ar" alt=""><figcaption><p>Delete member</p></figcaption></figure>


# Roles and Permissions

Create, View and Modify Roles and Permissions

{% hint style="warning" %}
This feature is available only to **Enterprise Tier Customers**
{% endhint %}

To manage your team members you can go to **Settings > Roles & Permissions**. From here you can manage all users across your company.

{% hint style="info" %}
All root admin accounts can **add**, **edit** or **remove** any Roles in the company
{% endhint %}

## View Default Roles

<figure><img src="/files/ZOOuFAyhXXNsnK9PMyfp" alt=""><figcaption><p>Predefined Roles</p></figcaption></figure>

BugBase Provides 4 default roles:

1. Security: All the permissions required for an account managing the triage process in the organization has actions on reports in the BugBase Dashboard
2. Root User: All the permissions required to access and modify the Company Dashboard. (Does not grant program dashboard permissions)
3. Program Admin: All the permissions required to access and modify a particular Program Dashboard (Does not grant company dashboard permissions)
4. Full Acccess: Has all the permission (Program and Company)

## Custom Roles

BugBase allows you to create custom roles, just click the **Create Custom Role** button to start creating a new role.

Enter a name for the new role, a short description and select the permissions provided.

<figure><img src="/files/XkzvkWfwOYtv2cYH5isZ" alt=""><figcaption></figcaption></figure>


# Security & Authentication

We offer various Security & Authentication Methods for extra security.

At BugBase, we understand the importance of security when it comes to managing your bug tracking system.

That's why we offer a range of **security and authentication** methods to ensure that your data is always secure and protected from unauthorized access. In this documentation, we will walk you through our security and authentication features, including **multi-factor authentication** through email and an Authenticator App also additionally Authentication through **SSO SAML**, and explain how you can implement them in your BugBase account to add an extra layer of security to your bug tracking system.

**Here are links on setting these features up:**

{% content-ref url="/pages/diurO0oQDIcUhCZ4ygP7" %}
[Multi-Factor Authentication](/company-guide/company-settings/security-and-authentication/multi-factor-authentication)
{% endcontent-ref %}

{% content-ref url="/pages/5vSXYr2L1cbEX6BOejcq" %}
[SSO with SAML](/company-guide/company-settings/security-and-authentication/sso-with-saml)
{% endcontent-ref %}


# Multi-Factor Authentication

Secure your account with Multi-Factor authentication

Multi-factor authentication (MFA) is a security system that requires users to provide multiple forms of authentication in order to access a system, application, or service. This adds an extra layer of security, making it more difficult for unauthorised users to gain access to sensitive information.

You can set up Multi-Factor authentication in one of the two ways. Firstly, using any authenticator app capable of generating Time-based One-Time Password (TOTP) authentication codes. You can use Google Authenticator or Duo Mobile or any other compatible application to generate the codes. Secondly, You can enable OTP based login via Registered Email Address. Everytime you try to login a OTP will be sent to your registered email and you have to verify it.

### Setup

> To enable Multi-Factor Authentication:

1. Navigate to Your **Company Dashboard > Settings > Security & Authentication.**
2. Choose any one of the Authentication type and Enable it.

<figure><img src="/files/24AsfTXpSRIMgHpWi2nk" alt=""><figcaption></figcaption></figure>

### MFA via Authenticator App

1. Toggle **Enable multi factor authentication via authenticator app**.
2. A modal would pop up on your screen, click on the **Setup** button to initiate MFA process.

<figure><img src="/files/qh4raY6czMXu8RHdu8Kw" alt=""><figcaption></figcaption></figure>

3. You will see a `QR code` and also a `Secret key` on the screen.

<figure><img src="/files/Oev7AFq8noTYIlcV3VzU" alt=""><figcaption></figcaption></figure>

4. You can either scan the `QR code` or enter the `Secret Key` and manually save it on your Authenticator app. Now you would be able to see the`BugBase (username)` account in your app.
5. Click **`Continue`** once you have added your account in the Authenticator app.
6. Enter the 6-digit code from the Authenticator app and click on `Verify`.

<figure><img src="/files/XsA7x1kfIZEORj94v944" alt=""><figcaption></figcaption></figure>

7. After successful verification, you will be logged out from your account and you will be asked to enter the 6-digit OTP every time you are logging in.

<figure><img src="/files/XHPhlcJrRRaHTjO31OVt" alt=""><figcaption></figcaption></figure>

### MFA via Email OTP

1. Toggle **Enable multi factor authentication via email**.
2. A modal would pop up on your screen, click on the **Setup** button to initiate MFA process.

<figure><img src="/files/g52EeCoxnlhAJMNsN2jw" alt=""><figcaption></figcaption></figure>

3. A One-Time Password will be sent to your registered email and Enter the OTP to complete the verification process.

<figure><img src="/files/Nk0LI9SevAdvl0qhnfAG" alt=""><figcaption></figcaption></figure>

> You can disable multi-factor authentication as well from **`Settings`** > **`Security`**.


# SSO with SAML

BugBase offers Single Sign-on through SAML ( Security Assertion Markup Language ) Integration with Okta and Google.

### Supported Providers

BugBase supports Single Sign-On (SSO) through Security Assertion Markup Language 2.0 (SAML 2.0) for these providers:

* [Okta](/company-guide/company-settings/security-and-authentication/sso-with-saml/okta-sso-setup-via-saml)

### Domain Verification

In order to configure single sign-on via SAML, you need to verify ownership of the domain for your program.

> To verify the ownership of domain:

1. Navigate to Your **Main Company Dashboard > Settings > Domains.**
2. Click on **Add New Domain.**

<figure><img src="/files/kgPgHoeujsATSzgJiovx" alt=""><figcaption></figcaption></figure>

3. Enter your domain and click **Save.**

<figure><img src="/files/8spv0B9IetNCP1fJ7vNI" alt=""><figcaption></figcaption></figure>

4. Now Add the TXT record shown on your Domain Management portal. After adding the TXT record click on **Verify**.

<figure><img src="/files/Pla0LE7y5kKBqQcRSudd" alt=""><figcaption></figcaption></figure>

> Once your domain is successfully verified, the status of your domain will be changed to *Verified*. You can continue to configure your SAML settings.

###

### Configuring Single Sign-On through SAML

### Setup

> To configure Single Sign-On through SAML:

1. Navigate to Your **Main Company Dashboard > Settings > Security & Authentication.**
2. Click on **Enable SAML single sign-on authentication.**

<figure><img src="/files/U4c4ZB66dOwWCtIBS5Gm" alt=""><figcaption></figcaption></figure>

3. A Set-up modal will pop-up, click on **Setup** **SAML**.

<figure><img src="/files/UK8vDDlvfEnTysSotmT6" alt=""><figcaption></figcaption></figure>

4. Next Click on **Enter Configuration**.

<figure><img src="/files/Zt1YsJd46YqKNqYZlmK4" alt=""><figcaption></figcaption></figure>

5. Enter the information from the third-party tool for the following fields:

<table><thead><tr><th width="193">Field</th><th>Details</th></tr></thead><tbody><tr><td>Domain</td><td>A Domain is required for SAML authentication. Select a Domain from the list of verified domains. This domain will be used to login with SSO.</td></tr><tr><td>Single Sign On URL</td><td>The URL from your SAML provider to initiate a single sign-on attempt, sometimes called the login URL.</td></tr><tr><td>X509 Certificate</td><td>The certificate from your SAML provider to verify the single sign-on response.</td></tr></tbody></table>

<figure><img src="/files/9gF54FKcf0Qdr7Szw9NJ" alt=""><figcaption></figcaption></figure>

6. Click **Save.**
7. Next you will asked to test your SAML Configuration, Clicking on **Test and Enable** will log you out of your current session and once you successfully login using SSO, your Single Sign-On will be Enabled.

<figure><img src="/files/YsQXlBhsS3v09ZaCzzbX" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Single Logout**: BugBase only supports logouts Identity Provider (IdP) initiated logouts, that is logging out of BugBase will not log you out of your SSO provider.
{% endhint %}


# Okta SSO setup via SAML

You can use your Okta credentials to sign in to BugBase.

### Configuring Single Sign-On through SAML using Okta

## Pre-requisites

1. Be an administrator of that your Okta Account.
2. All the Team members who will have access to sign in via Okta should have an Bugbase Account and should be a [member of your organization in BugBase](/company-guide/company-settings/organisation#add-member).

## Supported Features

The Okta/BugBase SAML integration currently supports the following features:

* SP-initiated SSO
* IdP-initiated SSO

## Configuration Steps <a href="#configuration-steps" id="configuration-steps"></a>

> To set up SSO via SAML for Okta:

1. Login in to your **Okta Application**.
2. Click on the **Admin** button on the top right corner.

<figure><img src="/files/CvpMFEFdyYSomJYl8SCi" alt="" width="354"><figcaption></figcaption></figure>

4. Go to **Application Tab** on the sidebar.

<figure><img src="/files/DtFuio9dXHtcIrCXs6Xv" alt="" width="275"><figcaption></figcaption></figure>

4. Click on **Browse App Catalog** button

<figure><img src="/files/P6a0YyDLqPXYnQNHz4Qe" alt="" width="563"><figcaption></figcaption></figure>

4. Search for the **BugBase** application and click **Add Integration**
5. Select the options you'd like in your General Settings.
6. Click Next.
7. Make sure to get the required details from the **Sign-on Tab:**
   * **Sign-on URL**: Located on the Sign On tab > Sign on methods > SAML 2.0 > More details > Sign-on URL
   * **X509 Certificat**e: Located on the Sign On tab > Sign on methods > SAML 2.0 > More details > Signing Certificate
8. Click Done.
9. Assign the BugBase application to the people or groups that should have access to the application on the **Assignments tab.**

{% hint style="info" %}
User configured within Okta with an email address and an account for that user exists on BugBase should have same email address, and the [user should be a member of your organization in BugBase](/company-guide/company-settings/organisation#add-member).
{% endhint %}

10. [Open Bugbase](https://bugbase.in/login) in a new tab.
11. Follow the SAML setup instructions [here](/company-guide/company-settings/security-and-authentication/sso-with-saml).
    * Copy the Single-Sign On URL and the X.509 Certificate that you accessed in step 7 and paste them in the corresponding fields during setup.

## Notes

The following SAML attributes are supported:

| Name  | Value      |
| ----- | ---------- |
| email | user.email |

## SP-initiated SSO

1. Go to <https://bugbase.in/login>
2. Select **SSO**

<figure><img src="/files/LYAiuldUN3bUiXnMPmoM" alt="" width="375"><figcaption></figcaption></figure>

3. Enter your email, then click Login.

## Troubleshooting

{% hint style="info" %}
If you encounter any issues or problems. Please reach out to us at <queries@bugbase.in>.
{% endhint %}


# Google SSO setup via SAML

You can use your Google credentials to sign in to BugBase.

#### Configuring Single Sign-On through SAML using Google <a href="#configuring-single-sign-on-through-saml-using-okta" id="configuring-single-sign-on-through-saml-using-okta"></a>

### Pre-requisites <a href="#pre-requisites" id="pre-requisites"></a>

1. Be an administrator of that your Google Workspace Account.
2. All the Team members who will have access to sign in via SSO should have an Bugbase Account and should be a [member of your organization in BugBase](https://docs.bugbase.ai/company-guide/company-settings/organisation#add-member).

### Supported Features <a href="#supported-features" id="supported-features"></a>

The SAML integration currently supports the following features:

* SP-initiated SSO
* IdP-initiated SSO

### Configuration Steps <a href="#configuration-steps" id="configuration-steps"></a>

> To set up SSO via SAML for Google:

1. Login in to your **Google Workspace Admin Console**.
2. Navigate to **Apps -> Web and mobile apps** on the sidebar.

<div align="center"><figure><img src="/files/OQGQhqkm0rJZQN2ydD5T" alt="" width="170"><figcaption></figcaption></figure></div>

3. Click on **Add app and choose Add Custom SAML app**

<div align="center"><figure><img src="/files/zUV7lZgk0OloyWJmsJQr" alt="" width="375"><figcaption></figcaption></figure></div>

4. Add you app name, description and an app icon and click **continue**.

<div align="center"><figure><img src="/files/pEdXeUc0XUm2oGTaZZ3m" alt="" width="563"><figcaption></figcaption></figure></div>

5. On the next page, make sure to copy the **SSO URL** and **Certificate** and click **continue.**

<figure><img src="/files/Yg7ULiqgdCJ2M52pyhGs" alt="" width="563"><figcaption></figcaption></figure>

6. On the Service Provider Details page, add the following details:

   * ACS URL - `https://bugbase.ai/api/auth/sign-in/saml/callback`
   * Entity ID - `https://bugbase.ai/`
   * NAME ID Format - EMAIL

   <figure><img src="/files/k5vQMNg0EL84mKMUbMIP" alt="" width="563"><figcaption></figcaption></figure>
7. Click **Continue**.
8. On the next Attributes page. Add a Attribute mapping

| Google directory attributes | App attributes |
| --------------------------- | -------------- |
| Primary email               | email          |

<figure><img src="/files/1x9iWmq8rSkUd9ZWVqK0" alt=""><figcaption></figcaption></figure>

6. Click **Finish**.

### Adding User Access to Custom SAML app

<figure><img src="/files/PGHkKEiWoyjKAbJwT9ku" alt=""><figcaption></figcaption></figure>

1. Click on User access card to give access.
2. Ensure the service status is on, and add the group for which you want the service to be enabled.

<figure><img src="/files/EyewVdCdrILMIlSZRzpC" alt=""><figcaption></figcaption></figure>

3. Click Save.

{% hint style="info" %}
User configured within Okta with an email address and an account for that user exists on BugBase should have same email address, and the [user should be a member of your organization in BugBase](https://docs.bugbase.ai/company-guide/company-settings/organisation#add-member).
{% endhint %}

### Finishing the SAML Setup on BugBase:

1. [Open Bugbase](https://bugbase.in/login) in a new tab.
2. Follow the SAML setup instructions [here](https://docs.bugbase.ai/company-guide/company-settings/security-and-authentication/sso-with-saml).
   * Copy the SSO URL and the Certificate that you accessed in step 5 from [#configuring-single-sign-on-through-saml-using-okta](#configuring-single-sign-on-through-saml-using-okta "mention") and paste them in the corresponding fields during setup.

{% hint style="info" %}
If you encounter any issues or problems. Please reach out to us at <queries@bugbase.in>.
{% endhint %}

### SP-initiated SSO <a href="#sp-initiated-sso" id="sp-initiated-sso"></a>

1. Go to <https://bugbase.in/login>
2. Select **SSO**

<figure><img src="/files/3WeWGG31XCU6KIm2M2aG" alt="" width="375"><figcaption></figcaption></figure>

3. Enter your email, then click Login.


# Customization

At BugBase we provide customization options to make your workflows easy

BugBase provides robust customization options to enhance your bug bounty program's efficiency and usability. These features empower program managers to tailor the platform to their specific requirements, streamline bug report management, and foster better communication with researchers.

#### 1. **Custom Responses and Automated Reply Features**

With BugBase, you can set up **custom responses** to send personalized messages to researchers based on the status or type of their report. This ensures a professional and consistent communication experience.

Additionally, BugBase offers **automated reply features** to acknowledge bug report submissions instantly. This helps build trust with researchers by keeping them informed about their report's receipt and status without manual intervention.

***

#### 2. **Report Tags**

Effortlessly organize and manage reports using **Report Tags**, a feature designed for easy categorization and filtering of bug reports.

* **Create Tags:** Add meaningful tags to bug reports, such as "High Priority," "Critical," or "UI Bug."
* **Maximum Limit:** You can create and add up to **10 tags** per report.
* **Filter by Tags:** Quickly filter and search reports based on assigned tags, making it easy to prioritize and analyze submissions.

This feature ensures that your bug management process remains efficient, even as the volume of reports grows.


# Automations

Automations provide the ability to automate your processes in BugBase.

## Trigger Based Auto Responses

Automated Responses allows companies can set automated responses for various triggers, which will help them manage their communication more effectively. Automated Responses will save users’ time by automatically responding to their messages based on predefined triggers and events.

### Setup Quick Responses

> To Add Custom Quick Responses

1. Navigate to Your **Company Dashboard > Settings > Automations.**

<figure><img src="/files/cc5RGwrxSZhJWGBH9DOo" alt=""><figcaption></figcaption></figure>

2. Click on **Add New Action** button.

<figure><img src="/files/4ZK0OoeZkGgOrzWhqgrY" alt=""><figcaption></figcaption></figure>

3. Now add a title for the quick action and in the message section, enter the message you want to send to the Bug Reporter.

<figure><img src="/files/ntmpt4XBuKT2xWBvqRqV" alt=""><figcaption></figcaption></figure>

4. Now click on **Save .**

> Added Quick Actions will be visible in your Automations tab in settings.

### Setup Automated Response based on Trigger

> To Add Automated Response based on Trigger

1. Navigate to Your **Company Dashboard > Settings > Automations.**
2. Click on **Setup Auto Responses** button.

<figure><img src="/files/0wvOeVzZ64vYgKF0hx8f" alt=""><figcaption></figcaption></figure>

3. Now Select a Trigger, a action that you want to perform for the trigger and select the programs to want the action to happen.

<figure><img src="/files/i1UMnSdbVFiz7L6J7c8w" alt=""><figcaption></figcaption></figure>

4. Click on **Save** to apply the changes.

{% hint style="info" %}
The Automated response will automatically populate for the selected trigger in the selected programs.
{% endhint %}


# Report Tags

Effortlessly organize and manage reports using Report Tags, a feature designed for easy categorization and filtering of bug reports.

Companies can now add custom tags on Bug Reports for easier filtering, the feature includes:

* **Creation of Tags:** Add meaningful tags to bug reports, such as "High Priority," "Critical," or "UI Bug."
* **Maximum Limit:** You can create and add up to **10 tags** per report.
* **Filter by Tags:** Quickly filter and search reports based on assigned tags, making it easy to prioritize and analyze submissions.

This feature ensures that your bug management process remains efficient, even as the volume of reports grows.

### Add Report Tags

> Head over to [https://bugbase.ai/company/settings/](https://bugbase.ai/company/settings/report-tags)

1. Navigate to Your **Company Dashboard > Settings > Report Tags.**

<figure><img src="/files/gYz8uoIcfuuQBcxJbhVW" alt=""><figcaption></figcaption></figure>

2. Click on **Create New Tag** and enter a Tag name

<figure><img src="/files/OCApATB4iV4Y7esCuTey" alt=""><figcaption></figcaption></figure>

The tag should be successfully added to your Report Tags table

{% hint style="warning" %}
You can add only a maximum of 10 tags
{% endhint %}

### Adding tags to a Bug Report

Navigate to a bug report, you will see a dropdown ("Tags") where your added tags will be populated. Just select a Tag you want to choose - the report will automatically be tagged.

<figure><img src="/files/bfe7z23srM9yKQnpJv1X" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
You can use these tags for filtering reports based on tags on the Program Report section
{% endhint %}


# Manage Access

Invite users in your organization and give them roles to manage certain parts of your BugBase Company Account

{% hint style="warning" %}
This feature is available only to **Enterprise Tier Customers**
{% endhint %}

<figure><img src="/files/aK6bWdm1Vtkzgqy5HEnw" alt=""><figcaption><p>Manage Access Page</p></figcaption></figure>

The user who has created the company account is the **root user**. You additionally invite more users and assign them a role.

Learn more about Roles from the [Roles and Permissions](/company-guide/company-settings/roles-and-permissions) section

{% content-ref url="/pages/P2vBuX10GIKimkYf0ewg" %}
[Roles and Permissions](/company-guide/company-settings/roles-and-permissions)
{% endcontent-ref %}

Once the a program is chosen:

1. Select the user from the dropdown whom you want to invite to the program
2. Select the role from the predefined list of roles in your company account
3. You can also add a custom identifier for the user who is getting added

<figure><img src="/files/FSlHx9tLUcyXXzpUgX6k" alt=""><figcaption><p>Manage Invitees Pop up</p></figcaption></figure>


# Insights Dashboard

The insights dashboard provides a comprehensive program overview

<figure><img src="/files/W3NDyD1Jp6QX2i4WUuFw" alt=""><figcaption></figcaption></figure>

The Insight Dashboard provides a comprehensive overview of your bug bounty program, including:

* The top three performing programs and their statistics of the current month
* Number of resolved and unresolved bugs
* Detailed breakdown of critical reports, including:
  * Program name
  * Priority level
  * Risk analysis
* Pie charts to visualize:
  * Severity of vulnerabilities found (P1, P2, etc.)
  * Types of vulnerabilities reported (e.g. XSS, SQL injection, etc.)
* This feature allows the program manager to have a clear picture of the most critical vulnerabilities found in the program and types of vulnerabilities that are most commonly reported.
* Program manager can use this information to prioritize and address the most important issues in their bug bounty program.

### Exporting all the reported vulnerabilities into CSV

Clicking the button beside critical report insights named Export Vulnerabilities will give you a CSV listing all the reported vulnerabilities until the current date.

<figure><img src="/files/yDw6P3kQELN40f42S5nA" alt=""><figcaption></figcaption></figure>


# Campaigns

Start a Campaign for better outreach to bounty hunters!

<figure><img src="/files/Y2e0BbswqO4ekAcKuTPh" alt=""><figcaption><p>Campaigns page</p></figcaption></figure>

### What are Campaigns?

Campaigns are special promotional events during which participants receive increased rewards for submitting valid reports.

### Why would I want to create a Campaign?

Creating a campaign on a bug bounty platform offers several advantages to clients, particularly in terms of enhancing security and engaging the community:

1. **Focused Attention on Critical Areas**: A campaign can direct the attention of skilled researchers towards specific areas of your system or product. This is especially useful if you've recently updated your software, are preparing for a major launch, or need extra scrutiny on certain components.
2. **Increased Participation**: Higher bounties typically attract more participants, including top-tier researchers. This increased participation means more eyes examining your systems, which can lead to the discovery of vulnerabilities that might otherwise go unnoticed.
3. **Faster Discovery of Vulnerabilities**: With more researchers incentivized to participate, vulnerabilities are likely to be discovered and reported more quickly. This rapid identification allows you to address issues sooner, reducing the window of risk.
4. **Enhanced Security Posture**: By addressing vulnerabilities found during a campaign, you strengthen your overall security posture. This can enhance your reputation for taking security seriously, which is valuable for customer trust and business credibility.
5. **Community Engagement and Reputation Building**: Engaging with the bug bounty community through campaigns can help build a positive reputation among security researchers. This goodwill can lead to more thorough and dedicated testing in both current and future campaigns.
6. **Cost-Effectiveness**: While you pay more per vulnerability, you benefit from the concentrated effort within a specific timeframe. This focused approach can be more cost-effective compared to continuous, lower-intensity testing.
7. **Strategic Security Investments**: Campaigns allow you to allocate budget strategically during critical periods, ensuring that your investment in security aligns with business needs and cycles.
8. **Competitive Edge**: Demonstrating a proactive approach to security can give you a competitive edge, showing customers and partners that you prioritize protecting their data and privacy.

In summary, launching a campaign on a bug bounty platform is an effective way to quickly identify and address vulnerabilities, engage with the security community, and reinforce your commitment to security, all of which are crucial for maintaining the trust and safety of your clients and their users.

### Creating a Campaign

The create campaign section provides the user to create a new campaign according to your preferences with custom bounties and custom duration.

<figure><img src="/files/KoS74eW6l6jUPt3NVZZ1" alt=""><figcaption></figcaption></figure>

### Edit a Campaign

This page gives the user to modify the created campaign and customise it further.

<figure><img src="/files/fIIvQtDy2jESTUKVSeam" alt=""><figcaption></figcaption></figure>

\
Once the campaign details are filled up users can see the preview of the campaign they just created.

<figure><img src="/files/EiTdF5BxWrBCtkyy0KQO" alt=""><figcaption></figcaption></figure>


# Understanding Currencies Used in BugBase

BugBase employs three types of currencies to streamline and manage bounty rewards, transactions, and display preferences.

## **Banking Currency**

\
The **banking currency** is the primary currency used for all monetary transactions with BugBase.\
It is the currency used for:

* Funding the **bounty bin**.
* Paying security researchers.

#### **Key Details**:

* At the time of bounty assignment, the amount in public currency is converted to the banking currency **using the exchange rate applicable at that exact moment**.
* Payments to security researchers are completed in the banking currency.

{% hint style="info" %}

#### **Changing Banking Currency**

To change the banking currency, raise a request at **<queries@bugbase.ai>**.
{% endhint %}

## **Public Currency**

\
The **public currency** is the currency displayed to security researchers when bounties are assigned.\
It serves as the **default currency** for assigning rewards. All bounties and bonus are assigned in public currency.

#### **Usage**:

* Bounties are assigned in public currency and the amount is displayed to the security researcher in public currency.
* This currency ensures clarity for researchers about the rewards they are earning.

{% hint style="info" %}

#### **Changing Public Currency**

To change the public currency for your program, raise a request at **<queries@bugbase.ai>**.
{% endhint %}

## **Preferred Currency**

\
The **preferred currency** is used by program managers and organization members to view bounty and bounty bin related details on the dashboard.

\
All amounts in the dashboard, including bounties and balances in the **bounty bin**, are shown in the preferred currency.

#### **Key Details**:

* This is a **real-time conversion** of values from the banking currency to the preferred currency.
* It provides an approximate view of balances and bounties, but it **does not represent the exact transaction amount**.

#### **Changing Preferred Currency**:

To update your preferred currency:

1. Navigate to your **Company Dashboard**.
2. Go to **Settings > Profile**.
3. Change the preferred currency from the dropdown menu.


# Whitelist

Enabling, managing, and processing whitelist requests for in-scope assets.

The whitelist feature allows companies to authorize bounty hunters' credentials, such as phone numbers, emails, or both, on specific in-scope assets. Whitelisting is applied on a per-asset basis, ensuring targeted access control. Bounty hunters can request whitelisting through the programs they are part of, enabling seamless collaboration while maintaining security and compliance.

## Enable Whitelisting

To enable whitelisting for an asset, companies should follow these steps:

1. **Navigate to Assets**: Go to `/company/assets`.
2. **Edit an Asset**: Select the asset you want to edit.

   * Locate the **Require Whitelist** dropdown option.
   * Choose the appropriate whitelisting requirement, such as phone, email, or custom input from user, from the dropdown.
   * Incase of requirement of custom input from user, you can mention the custom field description below this will be shown to the researcher while requesting for whitelisting.

   <figure><img src="/files/j10Zg092iWtpsUIxVaC7" alt=""><figcaption></figcaption></figure>

## Managing Whitelist Requests

To manage whitelist requests after authorizing on the platform, follow these steps:

1. **Navigate to Whitelist Requests**: Go to `/company/assets/whitelist`.
2. **View Requests**: All users who have requested whitelisting will be listed here.
3. **Filter Requests**:
   * Use filters to view requests by specific assets or across all assets.
   * Further refine results by request status: **Requested**, **Approved**, or **Rejected**.
   * Additionally you can view custom field entered by researcher as well: ![](/files/dHmBEUkJDpNS3vY0lhfI)
4. **Approve or Reject Requests**:
   * Select one or multiple users.
   * Click on the **Approve** or **Reject** button to take action.

<figure><img src="/files/QTIJpTh4Se5Rdpb9FTlU" alt=""><figcaption></figcaption></figure>


# Bug Bounty Dashboard

Bug Bounty or VDP Dashboard allows program managers to view important information about the status of their bug bounty program, helping them to easily track and manage the program.

{% hint style="warning" %}
A **BugBounty or a Private Program** is available only to **Professional** and **Enterprise Tiers**
{% endhint %}

The Bug Bounty Dashboard is an essential tool for program managers to **effectively track** and manage their **Bug Bounty program**. It provides a comprehensive **view of all recent bugs** submitted to the program, including the **status**, **priority**, **proof of concept** and **impact** of each bug.

Additionally, the dashboard includes a variety of statistics such as program Bounty Assigned, Reports this month, **Total Reports, Closed Reports, New Reports, Resolved Reports, Duplicate Reports** and **Invalid Reports,** which allows program managers to easily monitor the progress and performance of their bug bounty program.

The dashboard also features a **leaderboard** of hackers who have hunted the various programs and gained reputation, giving program managers a clear picture of who is actively participating and contributing in securing various applications.

The program manager can **view** and **edit** the **program policy** directly from the dashboard, which makes it easy to make changes or updates as needed.

Monetary **bounty rewards** can be assigned to researchers and the **payouts** are **managed** by BugBase

### Quick Links

{% content-ref url="/pages/sR1CugWaHKHaAttkIuxg" %}
[Program Reports Section](/program-guide/bug-bounty-dashboard/program-reports-section)
{% endcontent-ref %}

{% content-ref url="/pages/N2IOsJjAZCfZAg2y6YA1" %}
[Program Policy](/program-guide/bug-bounty-dashboard/program-policy)
{% endcontent-ref %}

{% content-ref url="/pages/UQ5UsbkqAwyeCeOv6n2E" %}
[Payouts](/program-guide/bug-bounty-dashboard/payouts)
{% endcontent-ref %}

{% content-ref url="/pages/WWdk5BXLtd4vliFDWA0z" %}
[Settings](/program-guide/bug-bounty-dashboard/settings)
{% endcontent-ref %}


# Program Reports Section

The Reports section in BugBase acts as an inbox for all the reports submitted to the program.

This section contains these different features to help you manage your reports:

* Sort Reports by **Recent Activity**, **Submission Time**, **Severity** (Low to High & High to Low)
* Filter by **Read**/**Unread**
* Filter based on **Status** of reports [Report Status](/report-lifecycle/report-status)
* Filter based on **Status Labels** of reports [Report Status](/report-lifecycle/report-status#report-status-label)
* Filter reports by **Severity**
* Filter reports by **Tags** [Report Tags](/company-guide/company-settings/customization/report-tags)
* Hide **Pending Context Reports**
* Search for specific reports by keywords like **Report Title** and **Report ID**

<figure><img src="/files/qFNeAASTXgEm1gkkeU0m" alt=""><figcaption></figcaption></figure>

By clicking on any report in the Reports section, program managers can view the details of the report and take necessary actions. This includes reviewing the report, assigning it to a team member for further triage, updating the report's status, and providing feedback to the hacker who submitted the report. This feature allows program managers to quickly and easily view and manage reports, and take appropriate actions to address vulnerabilities.

Learn more about the Report Lifecyle here:

{% content-ref url="/pages/NecviZz76QqcavnkzXS2" %}
[Report Lifecycle](/report-lifecycle/bug-report)
{% endcontent-ref %}

## Report Tabs

Report tabs are designed to help you easily focus on the reports that matter most. Below is an overview of each tab and its description.

### All Reports

All reports reported to the programs are visible in this tab, relevant filters and sorts can be applied to look for the subset of the reports you wish to view

### New Reports

All the newly submitted reports (Report Status: **New**) are shown in this tab

### Pending Action

All reports that require action from the program's side are shown here - these reports will have the label **Pending Program Review**

### Unread Reports

All reports that have not been viewed yet (unread) are shown here

### Triaged Reports

All reports that are valid (Report Status: **Triaged**) are shown here


# Report Components

Reports are an essential part of a bug bounty program as they provide program managers with detailed information about a vulnerability, allowing them to understand the scope and impact of the issue, and take appropriate action to address it.

### Report Data

Reports typically consist of different components that provide a holistic view of the vulnerability, including:

* **Report Summary**: A brief overview of the vulnerability or issue reported, including a summary of the potential impact and severity of the issue.
* **Vulnerability Impact**: An assessment of the potential impact of the vulnerability on the affected system or application, including the potential risks or consequences.
* **Description**: A detailed explanation of the vulnerability or issue, including technical details of how it can be exploited, and the affected systems or applications.
* **Proof of Concept**: A demonstration of how the vulnerability can be exploited, such as proof-of-concept code or a video.

### Metadata Panel

The Metadata Panel is a feature located on the right side of the report in that provides program managers with **detailed information** about the **report** and the **reporter**. The information included in the Metadata Panel is essential for program managers to understand the scope and impact of the vulnerability and to take appropriate action to address it.

Some of the key information included in the Metadata Panel are:

* **Report ID**: A unique identifier for the report, which can be used to refer to the report in future communications.
* **Report Title**: A brief title that summarises the vulnerability or issue reported.
* **Vulnerability Category**: The category of the vulnerability, such as Cross-Site Scripting (XSS) or SQL Injection.
* **Priority**: The priority assigned to the vulnerability, which indicates the urgency of addressing the issue.
* **Vulnerable Endpoint**: The specific location or endpoint where the vulnerability occurs, such as a specific URL or API endpoint. **\[This is an optional field]**
* **Report Status**: The current status of the report, such as New, Triaged, Resolved, or Closed.
* **Report Assignee**: The individual or team responsible for evaluating and addressing the vulnerability.
* **Reporter**: Information about the reporter, such as their username and KYC (Know Your Customer) status.

<figure><img src="/files/X1PpwKSaoWv7YW9QFXfq" alt=""><figcaption></figcaption></figure>

### Conversation Timeline

The Report Timeline is a feature that provides a chronological view of all the activity that occurs in a report between the program managers and the hackers involved. It allows program managers to track the progress of the report and stay informed of any updates or changes.

The Report Timeline shows the following activities:

* **Comments**: When program managers or researchers add a comment to the report.
* **State Changes**: When the state of the report changes, such as from "New" to "Triaged" or "Resolved".
* **Assignments**: When the report is assigned to a program manager or team member.
* **Reward Updates**: When a reward is assigned for a given report.
* **Severity Changes**: When the severity of the report changes, such as from **"P3"** to **"P1".**

The Report Timeline provides program managers with a clear view of all the activity that has occurred on the report and helps them to understand the progress of the report, as well as any changes that have been made.

<figure><img src="/files/MkR1XZmYVhJdjPtnthEU" alt=""><figcaption></figcaption></figure>


# Report Actions

The Reports section in Bugbase provides program managers with a centralized location to view and manage all reports submitted to the program. This feature allows program managers to take several actions on a report in order to efficiently manage them. You can:

* Add a comment
* Change report status
* Change report title
* Change priority
* Assign a report
* Report users
* Export report as PDF
* Connect to integrations

### Adding a comment

Program managers can add a comment to a report to provide feedback to the hacker who submitted the report or to discuss the report with other team members. Comments can be added to the report at any time and can be used to ask for more information, provide guidance, or express appreciation.

BugBase also allows program managers to use quick actions to reply to reports with per-defined responses for specific cases. This feature allows program managers to respond to reports quickly and efficiently, without the need to type out a response each time. You can even create your own custom quick actions for specific requirements.

<figure><img src="/files/GKRGIJqnFrjKnUFqWVTZ" alt=""><figcaption></figcaption></figure>

**Examples of quick actions include**:

* `Request for completing KYC`: This quick action can be used to let the hacker know that they need to complete their KYC to receive bounty payouts.
* `Request for Shipping Address`: This quick action can be used to request the hacker's shipping address when a physical reward is being sent.
* `Report under review`: This quick action can be used to inform the hacker that their report is under review by the program management team.

**Adding custom quick actions:**

1. Click the **`+`** icon at the right side of the quick actions section.

<figure><img src="/files/tCNorgdqzQHvg9RGonlb" alt=""><figcaption></figcaption></figure>

2. Enter `Title` and `Message` for your custom action and click on `Save`.
3. You can `Edit`/`Delete` your custom actions as well from the quick actions dropdown.

<figure><img src="/files/7iFtnVxukk02itT65h5n" alt=""><figcaption></figcaption></figure>

This feature saves time and effort for program managers, allowing them to respond to reports quickly and efficiently, while providing clear and consistent communication to hackers.

### Change Report Status

Program managers can change the state of a report to reflect its current status, such as "triaged", "resolved", "duplicate", "informational", "invalid", "spam", etc. This allows program managers to easily identify and prioritise reports based on their status.

#### To change report status:

1. Go to the top of the report page.
2. Click on the "Change Report Status" button.
3. Click on your desired status to change the status of the report.

<figure><img src="/files/EER7tfvehUuRfbU9kbgM" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
To learn more about report status view [report status page](/report-lifecycle/report-status)
{% endhint %}

### Update Report Title

Program administrators have the ability to update the title of a report if they find it necessary to better reflect the content or purpose of the report. This ensures clarity and improves communication among team members. To change the report title, click on the "Edit" button next to the report title, make the necessary changes, and save your updates.

<figure><img src="/files/ms9L6vO2opL4njxGdvih" alt=""><figcaption></figcaption></figure>

### Modify Report Severity

In addition to changing the status of a report, program managers can also change the priority of a report if they disagree with the priority set by the hacker. This feature allows program managers to quickly and easily adjust the priority level of a report to reflect its importance and urgency. Reports can be set to Critical, High, Medium, Low, Informational based on the severity of the vulnerability reported. This allows program managers to quickly identify and address critical vulnerabilities.

#### To change the severity of a report

1. Go to the top of the report page.
2. Click on the "Modify Report Severity" button.
3. Select the desired severity level from the options provided.

<figure><img src="/files/ZCrU1sap7sbSR8ZT12Md" alt=""><figcaption></figcaption></figure>

### Assign a Report

Program managers can assign a report to a specific team member for further triage and investigation. This allows program managers to delegate responsibility for investigating and addressing vulnerabilities to specific team members.

#### To assign a report

1. Go to the bottom of the report page and on the "Assignee" section.
2. Program manager can then select the team member from a list of program members to whom they wish to assign the report.
3. The assigned team member will then be responsible for evaluating the report and taking appropriate action on it.

<figure><img src="/files/7BNnsESmqmOVpKn1wKFM" alt=""><figcaption></figcaption></figure>

### Assign Rewards

Program managers can assign rewards to the hacker who submitted the report as a token of appreciation or reward for their contribution.

<figure><img src="/files/IhyeiTtWh6vnnI8hNTfu" alt=""><figcaption></figcaption></figure>

#### To set an reward

1. Go to the top of the report page and click on the "Assign Reward" button.
2. Enter the details of the reward, such as the type of reward and the amount.

<figure><img src="/files/Z6f4BQCn48H3YMtXbr9n" alt=""><figcaption></figcaption></figure>

### Report Users

Program managers can report users who violate the program's terms of service or abuse the platform. This allows program managers to take appropriate action against individuals who misuse the platform.

#### To report a user

1. Go to the top of the report page and click on the "Report User" button.
2. Provide a reason for the report, such as "violation of terms of service" or "abuse of platform".
3. This report will be reviewed by the platform team, and appropriate action will be taken.

<figure><img src="/files/ui13xOF3lMQXHKVIz1YR" alt=""><figcaption></figcaption></figure>

### Export Report as PDF

Another feature provided by the Reports section in BugBase is the ability to export a report as a PDF. This allows program managers to easily save a copy of a report for offline viewing or for sharing with others.

#### To export a report as a PDF,

1. Go to the top of the report page and click on the "Export Report as PDF" button.

This feature allows program managers to easily save a copy of a report for offline viewing or for sharing with others, such as stakeholders, team members, and other members of the organization. This feature makes it easy to share the report with others and to have a permanent record of the report.

### Connect to integrations:

Program managers can connect to integrations like Jira, Asana, Github and more. This allows program managers to integrate their bug bounty program with their existing workflows and processes, for example, by automatically creating tasks in project management tools for vulnerabilities that need to be fixed.


# Duplicating Reports

A duplicate report refers to a report that describes a vulnerability or issue that has already been reported and is being tracked by the program manager. This can occur when multiple hackers discover the same vulnerability and submit a report for it.

There are two ways to mark a report as duplicate in BugBase:

1. **Original Report ID**: When a program manager receives a report that is a duplicate, they can mark it as such by providing the original report ID. This allows program managers to easily link the duplicate report to the original report, making it easier to track and manage the issue.
2. **Issue Ticket Screenshot**: If the company is already aware of the issue, program managers can provide a screenshot of the issue ticket as proof that the issue was already known. This allows program managers to quickly verify that the issue has already been reported and is being tracked by the company.

<figure><img src="/files/B0YRUI6AT2aBkjozyqAv" alt=""><figcaption></figcaption></figure>

It is important to mark a report as duplicate as it helps program managers to avoid duplicate effort and prioritize the most important vulnerabilities.


# Assigning Swags

Assigning swags to hackers is a way for program managers to recognise and reward hackers for their contributions. Swags are physical items such as T-shirts, stickers, or other merchandise that can be awarded to hackers in addition to or instead of bounties.

In BugBase, program managers can award swags to hackers through the 'Assign Reward' feature. They can choose from a variety of swags that are available and assign it to the hacker.

#### To set an swag

1. Go to the top of the report page and click on the "Assign rewards" button.
2. Then select "Add Swag".
3. Enter the details of the swag, and click on save changes.

<figure><img src="/files/D8lVqwTJKwKgYaumk5lk" alt=""><figcaption></figcaption></figure>

Swags are a great way to recognise and appreciate the hackers who have helped to identify and report vulnerabilities. Assigning them in addition to or instead of bounties can provide a more holistic reward system for hackers.


# Assigning Bounties

Assigning bounties is a way for program managers to reward security researchers for their contributions in finding and reporting vulnerabilities. These bounties are monetary rewards given to security researchers for identifying and reporting valid vulnerabilities.

In BugBase, program managers can assign bounties to hackers through the **"Assign Reward"** feature. This feature allows managers to choose the bounty amount and assign it to the hacker. Program managers can set up different bounty amounts based on the type or severity of vulnerabilities.

### Steps to Assign a Bounty

1. **Navigate to the Report**:
   * Open the specific report page to which you want to assign the bounty.
2. **Click on "Assign Rewards"**:
   * At the top of the report page, click the **"Assign Rewards"** button.
3. **Select Reward Type**:
   * Choose either:
     * **Bounty Only**: Assign only a monetary reward.
     * **Bounty + Swag**: Assign a monetary reward along with swag to the security researcher.
4. **Enter Bounty Details**:
   * Enter the bounty amount manually or select from predefined bounty amounts.
5. **Save Changes**:
   * Click **"Save Changes"** to finalize and assign the bounty.

<figure><img src="/files/zHtsIFD6MzWSCKOyXYJc" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}

### Currency for Bounties

* Bounties are assigned in the **public currency** selected by the program admin for the program.
* At the time of assignment, the public currency is converted to the **banking currency**.

[Learn more about public currency, preferred currency, and banking currency here.](/company-guide/understanding-currencies-used-in-bugbase)
{% endhint %}

### Assigning Bonuses

Once a bounty is assigned to a report, **it cannot be modified**. However, program managers can assign a **bonus** to the security researcher as an additional reward.

#### To assign a bonus:

1. Click the **"Assign Rewards"** button again.
2. Select the option to assign a bonus.
3. Enter the bonus amount.
4. Click **"Save Changes"** to confirm.

<figure><img src="/files/7nHuQgPSt7xzsJiFDI1p" alt=""><figcaption></figcaption></figure>

### Collaborative Reports

When vulnerabilities are reported collaboratively by multiple hackers, BugBase automatically splits the bounty among the contributors. The split is based on the percentage of contribution decided by the hackers themselves.

### Best Practices for Awarding Bounties

1. **Follow Program Policy**:
   * Award bounties as per the program's guidelines. Ensure the report is valid and non-duplicate before assigning the bounty.
2. **Reward Significant Out-of-Scope Findings**:
   * Consider awarding bounties for out-of-scope vulnerabilities if they have a significant impact.
3. **Communicate Clearly**:
   * If the awarded bounty differs from the program policy or if a bounty is declined, provide clear explanations to hackers. This offers valuable feedback and encourages better submissions in the future.

### **Approval for Bounty Assignment:**

* Company Admins can configure bounty approval settings under **Company Dashboard > Settings > Access > People**.
* When bounty approval is required:
  * Bounties won’t be directly assigned.
  * The bounty assignment can either be accepted or declined by members who have the necessary permissions.

<figure><img src="/files/C8qD2fLqMPDTHZIfHIKJ" alt=""><figcaption></figcaption></figure>


# Assigning Thanks to Reporters

Acknowledge Efforts & Valuable Contributions of Bug Reporters by sending them a Thanks Message

This feature allows program owners to express their gratitude and appreciation to the reporters who have contributed to improving the security of their applications. In addition to assigning monetary rewards for valid bug reports, program owners now have the option to assign thanks to reporters as a way of acknowledging their efforts and valuable contributions.

{% hint style="info" %}
**Thanks** can only be assigned when marking the Report as **Resolved** or **Informational**
{% endhint %}

#### Conveying Thanks to a Reporter in a Particular Report

1. Navigate to a Report
2. Go to the **Top Action Bar** of the Report and click on the **"Change Report Status"** button.
3. When Marking a Report as Resolved or Informational, a Text Box will appear where you can add a **Thanks Message** to the Reporter acknowledging their efforts and valuable contributions in reporting the bug.
4. Enter the Thanks Message & Mark the Report as Resolved or Informational

<figure><img src="/files/6M2mWrvwAPIcRXfUCZoC" alt=""><figcaption><p>Assigning a Thanks Message</p></figcaption></figure>

Once the **Thanks has been Assigned,** it will show up in the Report Thread

<figure><img src="/files/1JKDhTWOsbyXd4PhbehS" alt=""><figcaption><p>Thanks Message on Report Thread</p></figcaption></figure>

{% hint style="info" %}
Assigning Thanks is **mandatory** when **No Reward (Bounty/Swag)** is assigned while marking a Bug Report as **Resolved**. In any other flow of changing report status it is an **optional** field (Incase of marking a report Informational)
{% endhint %}

### Why Assign Thanks?

BugBase is committed to fostering a collaborative and appreciative bug bounty community. The **"Assign Thanks"** feature aims to create a culture of recognition and gratitude within our platform, motivating reporters to continue their valuable contributions and encouraging program owners to express their appreciation. We believe that this feature will further enhance the bug hunting experience for all participants on BugBase.


# Assigning Bonus Bounty

In BugBase, program managers have the option to assign bonus rewards to hackers in addition to the regular bounties. Bonus rewards are additional monetary rewards given to hackers for exceptional contributions or for going above and beyond in their reports.

When deciding to award a bonus, program managers should consider the following factors:

1. Quality of the report: Bonus rewards can be given to hackers who have submitted high-quality reports that are well-written, detailed, and include all the necessary information for the program manager to understand and reproduce the vulnerability.
2. Impact of the vulnerability: Bonus rewards can be given to hackers who have found vulnerabilities that have a significant impact on the organisation.
3. Cooperation and communication: Bonus rewards can be given to hackers who have cooperated well with the program managers and provided timely and detailed information throughout the reporting process.
4. Additional Research: Bonus rewards can be given to hackers who have done additional research and provided additional information about the vulnerability or potential exploitation scenarios.
5. Uncovering a Chain of Vulnerabilities: Bonus rewards can be given to hackers who have uncovered a chain of vulnerabilities or have found multiple vulnerabilities in the same target
6. Promotions: Promotions can be used to increase engagement with your program by offering hackers an additional incentive to participate. For example, you can offer bonus rewards for the first X number of valid reports submitted during a specified time frame, or for issues found within a specific product or feature.

It is important to note that bonus rewards are not mandatory and program managers have the discretion to award them as they see fit. It is a good way to recognise and incentivize exceptional contributions from hackers.

#### To set an bonus

{% hint style="warning" %}
You can only set bonus if there's already a bounty assigned to the report.
{% endhint %}

1. Go to the top of the report page and click on the "Assign rewards" button.
2. Enter the bonus amount and click on save changes.


# Automatic Response Generator using ChatGPT

The Automatic Response Generator is a new feature in our app that allows to generate automatic responses using ChatGPT.

### How to Use the Automatic Response Generator

You can generate automated replies using ChatGPT ,which enables you to quickly generate responses for frequently asked questions and customer inquiries without spending time crafting individual responses.

<figure><img src="/files/LT3knTczPZD4AUGD9dOZ" alt=""><figcaption></figcaption></figure>

1. Click on the **Generate Auto Response using chatGPT** button.

<figure><img src="/files/7eEuIe9NsQBfwsnEzODH" alt=""><figcaption></figcaption></figure>

2. A Modal will open.
3. Specify a prompt for the response you want to generate. This could be a question or a statement that you want the response to be related to.

<figure><img src="/files/vtyIGNDGy7JpbksJ0gjp" alt=""><figcaption></figcaption></figure>

4. Click on the **Generate Response** button. The app will then use ChatGPT to generate a response based on your prompt.

<figure><img src="/files/5g2LlYr3NwSmeM9sMR18" alt=""><figcaption></figcaption></figure>

5. Review the generated response. If you are satisfied with the response, you can edit and click on **Use this Response** button to copy the response to the message box.
6. If you want to alter the generated response, you can modify the prompt and click on the **Generate Response** button again. The app will then generate a new response based on the modified prompt.

<figure><img src="/files/Tt59KY5ghVpyrWhcqLks" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
You can make a maximum of 10 requests within a span of 24 hours.
{% endhint %}


# Program Policy

In the Policy section of Bugbase, program managers can view and edit the program policy page. This page contains key information about the program and the program's disclosure policy. The policy page includes the following components:

1. Disclosure policy: This section outlines the program's policy for disclosing vulnerabilities to the public. It includes information about when and how vulnerabilities will be disclosed, and the timeline for disclosing vulnerabilities.
2. Policy for in-scope assets: This section outlines the assets that are in scope for the program, and the types of vulnerabilities that will be rewarded.
3. Bounty reward structure: This section outlines the structure of the rewards offered by the program, including the minimum and maximum rewards for different types of vulnerabilities.
4. Rules of engagement: This section outlines the guidelines for how hackers should engage with the program, including the types of testing that are allowed and the types of activities that are prohibited.
5. In-scope and out-of-scope assets: This section lists the assets and technologies that are in-scope and out-of-scope for the program.

The program policy page provides important information for hackers and program managers alike, and it should be kept up-to-date with the latest information about the program. Program manager should make sure that the Policy page is updated with the latest information about the program and the program's disclosure policy, this will help hackers understand the program better and increase the quality of the reports.

On the top side of the program policy page, there are four tabs: Policy, Scope, Members, and Changelogs.

1. Policy: This tab contains the program's policy, which includes information such as the disclosure policy, reward eligibility criteria, policy for in-scope assets, bounty reward structure, and rules of engagement.
2. Scope: This tab contains all the scope groups, which define the assets that are in scope for the program.
3. Hall of Fame: This tab showcases the top security researchers in your program.
4. Announcements: This tab displays the program's announcements.
5. Changelogs: This tab contains a record of all the changes that have been made to the program's policy. This can be useful for tracking changes and understanding how the program has evolved over time.

#### Program Statistics

On the right side of the policy page, program statistics are also visible. These statistics include:

1. Total Reports Received: This shows the total number of reports that have been received by the program.
2. Assets in Scope: This shows the total number of assets that are currently in scope for the program.
3. Bounty Range: This shows the range of bounties that have been awarded for different types of vulnerabilities.
4. Hall of Fame: This tab contains a leaderboard of the top hackers who have hunted on the program.

These statistics provide a quick snapshot of the program's performance and can help program managers to understand how the program is doing and identify areas that need improvement.<br>

#### Post New Announcements

On the right side of the policy page, you will find a button "New Announcement." Click on it to post a new announcement:

1. Click on **New Announcement**.
2. Add the title and message.
3. Click **Save**.

<figure><img src="/files/1rma7lelqikzScFS9raR" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:** A notification email will be sent to all security researchers regarding the announcement.
{% endhint %}


# Editing Program Policy

In the Edit Program Policy section of BugBase, program managers can make detailed changes to the policy of their bug bounty program. The following are the options available to program managers in this section:

<figure><img src="/files/vICcvvKRFer13SpaXtvR" alt=""><figcaption><p>Edit Program</p></figcaption></figure>

### Updating the program logo

This option allows program managers to upload a new logo for their program. This logo will be displayed on the program page and in other areas of the platform.

### Program visibility

This option allows program managers to make their program visible or hidden on the Program Tab. Program Managers get to keep their programs private and only visible to selected hackers.

### Program Policy

Program managers can update various aspects of their program policy, bounty hunters view this policy before starting test in-scope assets and to learn more about your company.

Editing Policy:

<figure><img src="/files/9CvlmIUuYp7UkNehWzD3" alt=""><figcaption></figcaption></figure>

### Changing program details

* Program name: This option allows program managers to change the name of their program.
* Bug bounty budget: This option allows program managers to specify their bug bounty budget.
* Program website: This option allows program managers to specify the website of their program.
* Program tagline: This option allows program managers to specify a tagline for their program.
* Program introduction: This option allows program managers to provide an introduction to their program.

### Rules of engagement

This section outlines the guidelines for how hackers should engage with the program, including the types of testing that are allowed and the types of activities that are prohibited.

* Collaborator Allowance: This option allows program managers to specify whether they want to allow collaborations for this particular program. Collaboration can be a powerful tool to enhance the effectiveness of a bug bounty program.
* User Agent for tracking request: This option allows program managers to specify the user agent that will be used for tracking requests made to their assets.
* Automated Tooling: This option allows program managers to specify the maximum number of requests/second that will be allowed for automated tooling. This will help to prevent abuse of the program by hackers using automated tools.
* Request Header: This option allows program managers to specify the request headers that will be used for tracking requests made to their assets.

### Modifying scope groups

Program managers can add or edit in-scope and out-of-scope assets. This allows them to clearly define the assets that are in scope for the program and the types of vulnerabilities that will be rewarded, which can help hackers to better understand the program and increase the quality of the reports.

### Managing bounty tables

The Bounty Tables in Bugbase can also be used to set different bounties for different scopes and priority based vulnerabilities. This allows program managers to incentivize hackers to focus on specific areas of the application that are most critical to their organization. Program managers can create different bounty tables for different scopes and assign them a different priority level.

Additionally, program managers can set different bounties for different types of vulnerabilities within a scope or priority level. This allows for fair rewards for the severity and impact of the vulnerability.


# Best Practices For Designing Policy

A bug bounty policy is a document that outlines the rules, rewards, and expectations of a bug bounty program. It is typically created by an organization or company to encourage ethical hackers and security researchers to identify and report vulnerabilities in their software or web applications.

The policy typically includes information such as the scope of the program (what assets or systems are in-scope and out-of-scope), the types of vulnerabilities that are eligible for rewards, the rewards offered for different types of vulnerabilities, and the process for submitting and validating reports.

It also includes details like the rules of engagement, how and when rewards will be paid, and the process for disclosing vulnerabilities. Bug bounty policy is an important document as it sets the tone and rules for the bug bounty program and helps to attract and retain top hackers.

Here are some best practices for writing a good program policy for a bug bounty platform:

1. Be clear and concise: A good program policy should be clear and concise, making it easy for hackers to understand what is in scope, what is out of scope, and what rewards they can expect for different types of vulnerabilities.
2. Define scope clearly: Clearly define the scope of your program, including in-scope and out-of-scope assets and vulnerabilities. This will help hackers focus their efforts on the areas of the application that are most important to your organization.
3. Reward system: Clearly define your reward system, including the types of rewards offered, the criteria for earning rewards, and the process for submitting and validating reports.
4. Communication: Clearly communicate your program policy to all potential hackers, and make sure that they understand the rules and expectations.
5. Policy review: Regularly review and update your program policy to reflect changes in the threat landscape and the evolving needs of your organization.
6. Be fair and consistent: Be fair and consistent in your rewards and be transparent about the criteria for earning them.
7. Be transparent with hackers: Transparently communicate your decision-making process in regards to triaging, validating and rewarding hackers.
8. Be open to feedback and suggestions: Be open to feedback and suggestions from hackers to improve your program and policy.

By following these best practices, you can create a program policy that is clear, fair, and effective in incentivizing hackers to find and report vulnerabilities in your application.


# Best Practices For Bounty Tables

Bounty tables are an important tool for program managers in a bug bounty program as it allows them to define the rewards for different types of vulnerabilities and scopes. By using bounty tables, program managers can incentivize hackers to focus on specific types of vulnerabilities or areas of the application that are most critical to their organization. This helps to ensure that rewards are paid out fairly for the severity and impact of the vulnerability.

Here are some best practices to follow when using bounty tables:

1. Prioritize the most critical vulnerabilities: Prioritize the most critical vulnerabilities by assigning higher bounties to them. This will encourage hackers to focus on finding and reporting these types of vulnerabilities first.
2. Be transparent: Clearly communicate your bounty tables and rewards to hackers. Make sure that they understand the rewards they can earn and the criteria for earning them.
3. Regularly review and update: Review and update your bounty tables regularly. This will ensure that the rewards are in line with the current threat landscape and the evolving needs of your organization.
4. Assign bounties according to the scope: Assign different bounties to different scopes based on their priority and impact on the organization.
5. Communicate the changes: Keep your hackers informed about any changes made to the bounty table.

By following these best practices, program managers can ensure that their bug bounty program is effective in finding and fixing vulnerabilities, and that hackers are fairly rewarded for their efforts.


# Payouts

View and Track Payments and Rewards assigned to researchers at one place

{% hint style="warning" %}
For a **VDP Program** only swag rewards are visible in the payouts view
{% endhint %}

The **Payouts section** on BugBase allows program managers to view the history of bounties and swags that have been assigned to hackers and the payment status of these rewards.

<figure><img src="/files/jDi7HuYrVAZX6d0SzXDD" alt=""><figcaption><p>View all Assigned Rewards</p></figcaption></figure>

Program Managers can filter the history by date range, payment status (pending or complete), and type of reward (bounties or swag). This section provides a comprehensive overview of all the rewards that have been assigned and the status of their payment, which helps program managers to keep track of their budget and ensure that all rewards have been paid out in a timely manner.

Additionally, program managers can also download the data in the form of CSV for record keeping or for the purpose of accounting.


# Settings

The Settings page in BugBase allows program managers to manage various integrations and members.

1. **Integration**: In this section, program managers can connect their program with different tools such as Jira, Asana, Trello, etc. to integrate their bug bounty program with their existing workflows and processes. This allows for easy tracking and management of vulnerabilities that need to be fixed. Additionally, program managers can also add new integration or disconnect an existing one.
2. **Members**: In this section, program managers can see a list of all members that are part of the program and the reports that are assigned to them. It allows program managers to keep track of which members are handling which reports and make sure that the workload is distributed evenly among the team. They can also add new members or remove existing members as needed. This section also allows program managers to filter the members based on their roles and reports assigned to them.

{% content-ref url="/pages/qDuxxeDmbW8I2uNZAjY6" %}
[Integrations](/integrations/supported-integrations)
{% endcontent-ref %}


# Private Bug Bounty Dashboard

Private Bug Bounty Dashboard allows program managers to view important information about the status of their program, helping them to easily track and manage their program.

Engage with verified, skilled and elite ethical hackers in our **Apollo Community** for fast-paced pentests and see results in real-time

The **Private Bug Bounty** Dashboard is an essential tool for program managers to **effectively track** and manage their **Program**. It provides a comprehensive **view of all recent bugs** submitted to the program, including the **status**, **priority**, **proof of concept** and **impact** of each bug.

Additionally, the dashboard includes a variety of statistics such as program Bounty Assigned, Reports this month, **Total Reports, Closed Reports, New Reports, Resolved Reports, Duplicate Reports** and **Invalid Reports,** which allows program managers to easily monitor the progress and performance of their bug bounty program.

The dashboard also features a **leaderboard** of hackers who have hunted the various programs and gained reputation, giving program managers a clear picture of who is actively participating and contributing in securing various applications.

The program manager can **view** and **edit** the **program policy** directly from the dashboard, which makes it easy to make changes or updates as needed.

Monetary **bounty rewards** can be assigned to researchers and the **payouts** are **managed** by BugBase

### Quick Links

{% content-ref url="/pages/sR1CugWaHKHaAttkIuxg" %}
[Program Reports Section](/program-guide/bug-bounty-dashboard/program-reports-section)
{% endcontent-ref %}

{% content-ref url="/pages/N2IOsJjAZCfZAg2y6YA1" %}
[Program Policy](/program-guide/bug-bounty-dashboard/program-policy)
{% endcontent-ref %}

{% content-ref url="/pages/wXZubSGIPuWf4o5ALavr" %}
[Invite Hackers](/program-guide/private-bug-bounty-dashboard/invite-hackers)
{% endcontent-ref %}

{% content-ref url="/pages/WWdk5BXLtd4vliFDWA0z" %}
[Settings](/program-guide/bug-bounty-dashboard/settings)
{% endcontent-ref %}

{% content-ref url="/pages/UQ5UsbkqAwyeCeOv6n2E" %}
[Payouts](/program-guide/bug-bounty-dashboard/payouts)
{% endcontent-ref %}


# Invite Hackers

Only available on the Private Bug Bounty Programs

{% hint style="warning" %}
Invite Users Section is available only for **Private Bug Bounty Programs**
{% endhint %}

<figure><img src="/files/jK0uOb8vkepNKgECyGQo" alt=""><figcaption><p>Invite Dashboard</p></figcaption></figure>

## Sending Invitation to Join Private Program

All invited users can access the Program Policy and start submitting reports.

There are two ways to send Invitation to hackers:

### Generate Invite Link

Create invite links to invite researchers into your program. Links can be managed to limit access, and can be revoked at any time.

<figure><img src="/files/tiKlafb1XO1LqNNPzuoE" alt=""><figcaption></figcaption></figure>

#### **View Links**

Click on the **Generate Invite Link** Card and Modal will pop up with a list of existing links.

<figure><img src="/files/NCUqASZ3RRyIuchCS8Zj" alt=""><figcaption><p>Manage Links</p></figcaption></figure>

#### **Create New Link**

Click on **Create a new link** button, a panel on the right will pop up with default settings:

1. Number of Uses
2. Max Number of Uses
3. Expiration Date
4. Link Name

<figure><img src="/files/aOD9BuJCEazkILT0pITQ" alt=""><figcaption></figcaption></figure>

### Invite Researchers via email/username

<figure><img src="/files/XBByDwllKxdhkkTojL85" alt=""><figcaption></figcaption></figure>

Invite researchers to your program by **Email** or their **BugBase** username. They will receive instructions on joining your program.

#### Invite Users

Invitations can be sent to users using username or email.

Click on **Invite Researchers** Card, a modal will pop-up asking username or email to invite.

<figure><img src="/files/BSdNonHZswgrGPqUpA98" alt=""><figcaption></figcaption></figure>

The Invite can be accepted through notifications or via acceptance link through email.


# Manage Credentials

Only available on the Private Bug Bounty Programs

{% hint style="warning" %}
Manage Credentials Section is available only for **Private Bug Bounty Programs**
{% endhint %}

You can view all the program scopes associated credential vaults in the **Credentials Section**

<figure><img src="/files/lYENmzHtxbKSVkX5WJjw" alt=""><figcaption></figcaption></figure>

### Credential Requests

Incase any Credential Requests have been made by a Bug Hunter, the Credential Requests tab will populate with a list of requests.

Viewing a particular request will give you two options:

1. Auto Assign Credential
2. Manually Assign Credential

### Particular Vault Section

To view all the credentials and the status of assignment of a particular credential set, you can click on a particular Credential Vault in the **Program Vaults table**

<figure><img src="/files/lzf8rm5o8rxj0iPWlwTH" alt=""><figcaption></figcaption></figure>

### Assign/Unassign Credential Sets

Incase you wish to Manually Assign Credential Sets, navigate to a particular vault inside the Program Vaults sections.

From the Credentials Table, open any dropdown beside the credential set you wish to assign to a Bug Hunter. Once a User is selected for assignment, a popup like below should appear where the assignment preference to an asset needs to be chosen.

<figure><img src="/files/iWa00u9htsXsMLYFExX2" alt=""><figcaption></figcaption></figure>

Click on **Assign Credential** to successfully assign the credential.

To **Unassign** a particular credential set, click the **Remove Icon** beside the username of the assigned user.


# VDP Dashboard

VDP Dashboard allows program managers to view important information about the status of their program, helping them to easily track and manage their program.

The **VDP (Vulnerability Disclosure Program)** Dashboard is an essential tool for program managers to **effectively track** and manage their **Vulnerability Disclosure Program**. It provides a comprehensive **view of all recent bugs** submitted to the program, including the **status**, **priority**, **proof of concept** and **impact** of each bug.

Additionally, the dashboard includes a variety of statistics such as program Bounty Assigned, Reports this month, **Total Reports, Closed Reports, New Reports, Resolved Reports, Duplicate Reports** and **Invalid Reports,** which allows program managers to easily monitor the progress and performance of their bug bounty program.

The dashboard also features a **leaderboard** of hackers who have hunted the various programs and gained reputation, giving program managers a clear picture of who is actively participating and contributing in securing various applications.

The program manager can **view** and **edit** the **program policy** directly from the dashboard, which makes it easy to make changes or updates as needed.

### Quick Links

{% content-ref url="/pages/sR1CugWaHKHaAttkIuxg" %}
[Program Reports Section](/program-guide/bug-bounty-dashboard/program-reports-section)
{% endcontent-ref %}

{% content-ref url="/pages/N2IOsJjAZCfZAg2y6YA1" %}
[Program Policy](/program-guide/bug-bounty-dashboard/program-policy)
{% endcontent-ref %}

{% content-ref url="/pages/WWdk5BXLtd4vliFDWA0z" %}
[Settings](/program-guide/bug-bounty-dashboard/settings)
{% endcontent-ref %}

{% content-ref url="/pages/UQ5UsbkqAwyeCeOv6n2E" %}
[Payouts](/program-guide/bug-bounty-dashboard/payouts)
{% endcontent-ref %}


# Pentest Dashboard

The Pentest Dashboard on BugBase allows program managers to easily track and manage their ongoing pentests.

<figure><img src="/files/Jv2I4lO4zLWs48hqtHVx" alt=""><figcaption><p>Pentest Dashboard</p></figcaption></figure>

The dashboard provides a comprehensive overview of all pentest, including the ability to start a new pentest, view ongoing scans and access the pentest overview area.

### Create a new Pentest Program

To start a new pentest, create a **company account** and fill the onboarding steps to create a **Pentest Program**

{% content-ref url="/pages/9E9NQhwIg1plgHh2NFf5" %}
[Create a Company Account](/company-guide/create-a-company-account)
{% endcontent-ref %}

{% content-ref url="/pages/3UchUr1fprTJmkl37DPj" %}
[Create a Program](/company-guide/programs-dashboard/create-a-program)
{% endcontent-ref %}

> Once a pentest program is created, our security team will get in touch with you under 24 hours to get to know about your application that requires a pentest. Alternatively reach out to us at <admin@bugbase.in>

### Navigation in the Pentest Dashboard

The **View Pentest Scans** button takes you to the **Pentest Overview** area, where you can view *all vulnerabilities* found during the pentest, access the *pentest reports*, and get an overview of the pentest progress. In this area, you can view the vulnerabilities by *severity*, and filter them by category to better understand the scope and impact of the vulnerabilities found.

The pentest dashboard provides a clear and user-friendly interface for program managers to keep track of ongoing pentest, view pentest report and vulnerabilities and to access the pentest overview area. It is designed to provide program managers with all the tools and information needed to effectively manage and monitor their penetration tests, and make informed decisions based on the results.


# Pentest Overview

<figure><img src="/files/1WoUACFuqIocVxGaRq8G" alt=""><figcaption><p>Pentest Overview</p></figcaption></figure>

The Overview section of our pentest platform is an essential tool for program managers to view and manage the vulnerabilities found during the pentest. It provides a comprehensive view of all the vulnerabilities found during the test, including the number of resolved and unresolved vulnerabilities, as well as the number of vulnerabilities categorized by severity level (critical, high, medium, low, and none). This information is displayed in a clear and easy-to-read format, allowing program managers to quickly identify and track vulnerabilities, and make informed decisions on how to address them.

On the right side of the page, you will find a simple timeline that displays the progress of the pentest. This timeline allows program managers to track the progress of the test and understand how long it took to complete. Additionally, a download report button is provided, which allows program managers to download the full pentest report in pdf format.

The Overview section also includes information about the Bugbase VAPT expert who conducted the test, including their name and contact information. This is important as it allows program managers to contact the expert in case of any queries or clarifications regarding the test results.

To help program managers better understand the distribution of vulnerabilities found during the test, the Overview section also includes pie charts that show the distribution of vulnerabilities by severity level and by vulnerability type. These charts provide a visual representation of the data and make it easy for program managers to identify which types of vulnerabilities are most prevalent.

In addition to the vulnerability data, the overview section also provides information about the assets tested during the pentest. This includes a list of all the affected URI found during the test, which allows program managers to understand which assets were most vulnerable and prioritize their remediation efforts accordingly. An executive summary is also provided which gives a brief overview of the findings and the progress of the test.

All of this information and data is designed to help program managers effectively manage and mitigate the risks associated with the vulnerabilities found during the pentest. The detailed data and information provided in this section, along with the ability to download the full report and contact the VAPT expert, enables program managers to make informed decisions and take appropriate actions to address the vulnerabilities found during the test.


# Vulnerabilities Section

In the vulnerabilities section, program managers can view all vulnerabilities found during the pentest, organized by their status (**resolved** or **unresolved**) and issue type.

They can also view the **Affected URL** and **priority** of each vulnerability. Additionally, program managers can search for vulnerabilities using keywords to quickly find specific vulnerabilities. This section provides a comprehensive view of all vulnerabilities found during the pentest, allowing program managers to effectively manage and prioritize their security issues.

By clicking on any vulnerability report, program managers can view detailed information about the vulnerability, including the **affected URL**, **issue type**, **priority**, and any **additional comments** or **recommendations** provided by the pentester.

They can also take various actions on the vulnerability, such as marking it as resolved, assigning it to a specific team member for further investigation, or adding comments or notes.

This allows program managers to easily manage and track the progress of their vulnerabilities, and take necessary actions to address them.


# Pentest Report Components

Pentest reports provide a detailed overview of the vulnerabilities found during a penetration test. These reports typically include the following components:

1. Vulnerability Description: A clear and concise explanation of the vulnerability, including how it was discovered and the potential impact it could have on the system or network.
2. Vulnerability Impact: An assessment of the severity of the vulnerability, including the potential damage it could cause, the likelihood of exploitation, and the ease of remediation.
3. Remarks and Remediation: Recommendations for how to fix the vulnerability, including best practices and specific steps that should be taken to address the issue.
4. Proof of Concept: A demonstration of how the vulnerability can be exploited, including example code or screenshots that illustrate the issue.
5. Affected URL: The specific URL or asset that is affected by the vulnerability.
6. Priority: Indicating the severity of the vulnerability and the urgency of addressing the issue.
7. Issue Type: Categorizing the type of vulnerability, such as a cross-site scripting (XSS) or a SQL injection.

### Metadata

The metadata panel on the right side of the report provides detailed information about the report, including the report title, vulnerability ID, vulnerability type, priority, vulnerable endpoint, report status, and any external references.

This panel is designed to give you a clear understanding of the vulnerability and its impact, as well as any relevant information that may be needed to remediate the issue.

1. The report title and vulnerability ID are unique identifiers for the report, making it easy to track and manage the issue.
2. The vulnerability type, priority, and vulnerable endpoint provide information about the nature of the vulnerability and its impact on your systems.
3. The report status is used to track the progress of the issue, from initial discovery to resolution.
4. The external references section includes any additional information that may be relevant to the vulnerability, such as links to external resources or guidance on how to remediate the issue.

### Timeline

The report timeline is a detailed log of all the activities that have taken place in the report between the pentester and the program team. It includes updates such as comments added by the pentester or the program team, changes in the report status (e.g. from "new" to "resolved" or "ignored"), and retest requests made by the program team. This feature allows for easy tracking of the progress and resolution of each vulnerability reported.

Additionally, it provides a clear record of all the actions taken and communication exchanged related to a specific vulnerability. This helps in keeping track of all the vulnerabilities and their status, making it easy to keep track of progress and resolve vulnerabilities in a timely manner.


# Pentest Report Actions

In the pentest report action section, program managers have the ability to manage reports in an efficient manner by taking various actions on them. These actions include:

* Marking the status of a report as ignored or resolved
* Requesting a retest for a vulnerability
* Connecting the report to various integrations
* Adding comments and notes to the report
* Printing a specific vulnerability report

### Marking the Status of the Report

This allows program managers to update the status of a vulnerability report to indicate that it has been addressed or is not a valid issue.

#### To change the status of a report

1. Go to the metadata panel and click on the "Mark Vulnerability Status" button.
2. This will bring up a dropdown menu where you can select the desired status for the report, such as "Ignored" or "Resolved."

### Requesting a Retest

If a program manager is unsure about the validity of a report, they can request a retest to have the vulnerability re-evaluated.

#### To request a retest of a vulnerability

1. Go to the metadata panel and click on the "Request Retest" button.

### Connecting to Various Integrations

Program managers can connect their pentest reports to various integrations such as Jira, Asana and Github. This allows program managers to integrate their pentest program with their existing workflows and processes.

#### To connect to various integrations,

1. Go to the metadata panel and click on the "Connect to \* " button.

### Adding comments

Program managers can add comments to a report in order to provide feedback or additional information to the pentester who submitted the report.

### Printing Vulnerability Report

Program managers can print a report in order to have a physical copy for record keeping or for sharing with other team members.

#### To print a vulnerability report

1. Go to the metadata panel and click on the "Print Report" button.
2. This will open a printable version of the report that you can print or save as a PDF.


# Global Pentest Chat

The Global chat channel is a feature that allows program managers to communicate with the pentesting team in real-time. On the right side of the screen, you will find contact information for the lead pentester, as well as a chatbox that allows you to directly communicate with the team. Additionally, there is a timeline of the status of the pentesting, which includes information about whether it is ongoing or completed.

This allows program managers to stay updated on the progress of the pentest and address any concerns or questions they may have in a timely manner. The channel also serves as a communication hub for all the stakeholders of the pentest.


# Competition Dashboard

Host competitions to find out the best security talent from a pool of ethical hackers.

BugBase enables organizations to identify and hire the best security talent from a pool of ethical hackers. With our competitions, you can access a pool of ethical hackers and identify the best candidates for your organization. Whether you're looking to fill a specific role or simply to build a team of top-notch security experts, BugBase can help you find the right talent for your organization.


# Dashboard

Create, manage and track all your competitions with our user-friendly interface.

Using our Competition Dashboard, companies can effortlessly create new competitions and set custom rules and guidelines. The platform also allows for easy management of existing competitions, including the ability to search, view and edit entries.

<figure><img src="/files/PDVkHtwzrlhbkQsgI08m" alt=""><figcaption></figcaption></figure>


# Creating a Competition

Find the best security talent from a pool of ethical hackers. Create and manage competitions with ease.

## Basic Details

Fill the necessary information to create and launch your competition:

<figure><img src="/files/urUEDsbuLvLcl852jaDM" alt=""><figcaption></figcaption></figure>

Once you add Competition Name, Description, Start Date and Time, End Date and Time & Rewards information, you can start adding challenges.


# Adding Challenges

WIP

To add challenges to your competition, navigate to the competition dashboard and select the 'edit' button next to the relevant competition.

\<Image of Dashboard (highlight the edit button)>

To create a new challenge, provide the following information in the designated fields:

* Challenge Title
* Challenge Question
* Challenge Link
* Challenge Files (with a file size limit of 25 MB)
* Challenge Category
* Challenge Points
* Challenge Answer

<figure><img src="/files/ou6s523MyTNmDVoz12FB" alt=""><figcaption></figcaption></figure>

You also have the option to add hints for each challenge question, which can be useful for providing additional guidance or support to the competitors.

\<Image of Adding Hint>

To add multiple questions to a challenge, utilise the 'Add Challenge Question' button. This will create additional fields for inputting an additional question with the above mentioned fields.

\<Image of Adding Additional Question (If required)>

Before finalising your competition, you have the option to determine the visibility of your competition by selecting either "public" or "Not Visible" . Once you have made your selection, make sure to save your progress by clicking on the 'save' button.


# Manage Competitions

View insights and edit competition details

To manage your competitions, navigate to the competition dashboard and select the relevant competition. From there, you will have access to various management options such as viewing statistics, viewing the leaderboard, and managing users.


# Statistics

View all Competition Statistics in one place

Under the statistics tab, you will have access to various data related to the competition such as total attempts, correct attempts, and wrong attempts for each challenge. Additionally, you will be able to view the total number of users that have joined the competition.


# Leaderboard

Under the leaderboard tab, you will have access to the ranking and points of each user who is participating in the competition. The data is displayed in a tabular format and also as a graph for better visualisation of the progress of the competition.

\<Image of Leaderboard>

You also have the option to export the leaderboard data by clicking on the 'Export Leaderboard' button. This will send a copy of the leaderboard to your registered email for further analysis or record keeping.

\<SS of the email if possible>


# Manage Users

Under the Manage Users tab, you will have access to a list of all users who have joined the competition, along with their join date. You can also search for specific users using the search function provided. Furthermore, you have the ability to ban or unban any user from the competition if necessary.

\<Image of Manage Users>


# Bounty Hunter Dashboard

Logged in Successfully!

After logging in successfully, the personalised dashboard is the first thing that the hunter sees.

It consists of all the new **announcements**, **updates**, **bug reports** and **invitations** that the hunter is subscribed to in a feed format.

Whether it's a new program launch or a private program invite, the Feed has you covered with all the latest happenings in the platform and with you as a hunter.

### Feed

<figure><img src="/files/FXnIo4ErxO7zwr0Ly67G" alt=""><figcaption></figcaption></figure>

The feed categories colour coded so that you can easily differentiate between feed categories.

### Bounty Hunter Profile Card

This part shows you an overview of your profile including their global rank, no.of reports submitted, reputation, success rate etc.

<figure><img src="/files/SVgu4lQ599H0c3S2qZRV" alt=""><figcaption></figcaption></figure>


# Bounty Hunter Profile

The Bugbase Hacker Profile Page is a comprehensive dashboard for cybersecurity researchers  participating in bug bounty programs.

This profile page showcasing the hacker's skills, accomplishments, and contributions. It can be accessed at `/profile/<username>`, where `<username>` is the unique identifier for the hacker.

## Description

The profile page is divided into three main sections:

* [Overview](#overview-section)
* [Hacktivity](#hacktivity-section)
* [Badges](#badges-section)

## Definitions

* **Global Rank**: Your position on the global leaderboard, indicating your competitive standing among all hackers on Bugbase.
* **Reputation**: A measure of the reliability and impact of your findings. High reputation scores unlock privileges and reflect your expertise and contribution quality.
* **Thanks**: A section listing the programs for which you've submitted valid reports, highlighting your successful contributions.
* **Success Rate**: The ratio of valid reports to total submissions, indicating the quality and accuracy of your findings.
* **Hall of Fame**: Highlights the top programs you've contributed to, showcasing your significant impacts.
* **Hacktivity**: A timeline of your reputation fluctuations, providing insights into your activity and performance over time.
* **Badges**: Awards received for meeting specific criteria or achieving milestones, displayed on your profile to highlight your skills and accomplishments.

## Overview Section

The Overview page offers a snapshot of the hacker's profile, including:

* Hacker details (username, bio, etc.)
* Activity heatmap, visualizing participation frequency
* Global rank
* Hall of Fame, listing top contributions
* Competition stats, including CTFs (Capture The Flag) participation and rankings

<figure><img src="/files/mmdP4opUucr2Jp5qEKVU" alt=""><figcaption><p>Overview section</p></figcaption></figure>

## Hacktivity Section

This page displays a detailed timeline of the hacker's reputation gained or lost across different programs, offering insights into the hacker's activity and performance patterns.

<figure><img src="/files/CjPfKCItsurx7wviGySY" alt=""><figcaption><p>Hacktivity section</p></figcaption></figure>

## Badges Section

Here, hackers can view all the badges they have earned. Each badge includes:

* The name of the badge
* A short description of its significance
* The date it was achieved

<figure><img src="/files/C9zUdy7tna5nQXoQZyyU" alt=""><figcaption><p>Badges section</p></figcaption></figure>

The following table provides details on the types of badges available:

<table><thead><tr><th width="280">Name</th><th width="397">Description</th><th data-hidden>Icon</th></tr></thead><tbody><tr><td>Apex Hunter</td><td>Dominance as number 1 worldwide, celebrating unrivaled skills and leadership.</td><td><img src="https://files.bugbase.in/badges/rank1.svg" alt="Apex Hunter" data-size="line"></td></tr><tr><td>Guardian</td><td>Ranking 2nd on the global leaderboard, highlighting brave conquests and commitment to digital security.</td><td><img src="https://files.bugbase.in/badges/rank2.svg" alt="Guardian" data-size="line"></td></tr><tr><td>Warrior</td><td>Recognized for the 3rd rank on the leaderboard, acknowledging dedication to fighting bugs and enhancing cybersecurity.</td><td><img src="https://files.bugbase.in/badges/rank3.svg" alt="Warrior" data-size="line"></td></tr><tr><td>Explorer</td><td>Honors a seven-day streak of engagement, celebrating persistent brilliance and dedication in the digital world.</td><td><img src="https://files.bugbase.in/badges/7daystreak.svg" alt="Explorer" data-size="line"></td></tr><tr><td>Immortal</td><td>Celebrates a year of unmatched hacking dedication, showcasing ceaseless passion and skill in cybersecurity.</td><td><img src="https://files.bugbase.in/badges/1yearstreak.svg" alt="Immortal" data-size="line"></td></tr></tbody></table>


# Programs Directory

List of all Active Programs on BugBase

## Subsections

The Programs Directory is sub divided into three categories all of which present bug bounty programs to the hackers. The sections are as follows:

* Public Programs
* Private Programs
* Programs Not Listed on BugBase
* Saved Programs

### Public Programs

<figure><img src="/files/cM7M8o7OPRtpwl1i5TGE" alt=""><figcaption><p>Public VDP/BugBounty Programs</p></figcaption></figure>

This section provides the hackers with a plethora of bug bounty programs which are hosted by various organizations.

The organization name is accompanied by their Launch date, bounty range and labels which provide some additional information to the hacker so that they can pick a program that they like.

Program Policy, Scope Restrictions and other statistics of the programs can be viewed by clicking on the program.

### Private Programs

<figure><img src="/files/wczcnPmWclHb5D8CYgpj" alt=""><figcaption><p>Private Bug Bounty Programs</p></figcaption></figure>

This section show the hacker what private programs they have access to and similar Launch Date, bounty range and labels are present which again, provide additional information to the hacker about the program.

Just like the public programs, the program policy, scope restrictions and other statistics of the programs can be viewed by clicking on the program.

### Programs not listed on BugBase

<figure><img src="/files/xDWq7RQha4q0k5vqejOR" alt=""><figcaption><p>Submitting Reports to a program that doesn't exist on BugBase</p></figcaption></figure>

This section allows a hacker to submit a report for a bug bounty program which is not listed on BugBase.

BugBase makes an effort to allow hackers to submit the reports to other bug bounty programs as well.

### Saved Programs

<figure><img src="/files/twbwPYldZq4w9CNUZme2" alt=""><figcaption></figcaption></figure>

This section allow hackers to access programs they have previously saved. This section provides a convenient and organized way for hackers to access and manage the programs they use most frequently, without having to search. Information like Launch Date, bounty range and labels are present which again, provide additional information to the hacker about the program.

This allows for quick and efficient follow-up on resolved bugs, and helps to keep track of all reported issues.


# Program Policy Page

View Policy, Scope Groups, Credentials, Hall of Fame and Changelogs

<figure><img src="/files/f4j4r7Gv9LPHEBDauD0N" alt=""><figcaption></figcaption></figure>

This page contains key information about the program and the program's disclosure policy. The policy page includes the following components:

1. Disclosure policy: This section outlines the program's policy for disclosing vulnerabilities to the public. It includes information about when and how vulnerabilities will be disclosed, and the timeline for disclosing vulnerabilities.
2. Policy for in-scope assets: This section outlines the assets that are in scope for the program, and the types of vulnerabilities that will be rewarded.
3. Bounty reward structure: This section outlines the structure of the rewards offered by the program, including the minimum and maximum rewards for different types of vulnerabilities.
4. Rules of engagement: This section outlines the guidelines for how bounty hunters should engage with the program, including the types of testing that are allowed and the types of activities that are prohibited.
5. In-scope and out-of-scope assets: This section lists the assets and technologies that are in-scope and out-of-scope for the program.

The program policy page provides important information for bounty hunters and program managers alike, and it should be kept up-to-date with the latest information about the program. Program manager should make sure that the Policy page is updated with the latest information about the program and the program's disclosure policy, this will help bounty hunters understand the program better and increase the quality of the reports.

On the top side of the program policy page, there are **six tabs**:

1. **Policy:** This tab contains the program's policy, which includes information such as the disclosure policy, reward eligibility criteria, policy for in-scope assets, bounty reward structure, and rules of engagement.
2. **Scope:** This tab contains all the scope groups, which define the assets that are in scope for the program.
3. **Members:** This tab contains a list of all the members who manage this program. Program managers can add or remove members as needed.
4. **Credentials & VPN:**
   1. [VPN Access](/bounty-hunter-guide/programs-directory/vpn-access)
   2. [Credentials](/bounty-hunter-guide/programs-directory/credentials)
   3. [Whitelist](/bounty-hunter-guide/programs-directory/whitelist)
5. **Hall of Fame**: This tab contains a leaderboard of the top bounty hunters who have hunted on the program.
6. **Changelogs:** This tab contains a record of all the changes that have been made to the program's policy. This can be useful for tracking changes and understanding how the program has evolved over time.

#### Program Statistics

Program statistics are displayed on the right side of the policy page, offering a quick overview of the program's performance. These include:

1. **Total Reports Received**: Displays the cumulative number of reports submitted to the program.
2. **Assets in Scope**: Indicates the total number of assets currently included in the program's scope.
3. **Bounty Range**: Highlights the range of bounties awarded for various vulnerability types.
4. **Average First Response Time**: Shows the average time taken to acknowledge a submitted report
5. **Average Report Resolution Time**: Reflects the average time it takes to resolve a report after submission.
6. **Average Report Triage Time**: Indicates the average time taken to evaluate and triage report.
7. **Last Report Triaged**: Displays the time elapsed since the last report was triaged by the program.


# Credentials

Credentials are essential for gaining access to the program's assets and conducting any necessary testing.

Certain programs may only allow authorized access to their assets through special credentials, which can be obtained through the credentials tab in program policy page. Without these credentials, it may not be possible to conduct any hacking activities on the program's assets.

## Program Credentials

The credentials tab on a program's policy page displays all the assets for which credentials have been set up. By accessing this tab, you can view a comprehensive list of the program's assets that require credentials for authorized access.

<figure><img src="/files/pgNnimU0DQFQlfEK9g81" alt=""><figcaption><p>Credentials Tab</p></figcaption></figure>

## Getting Access to the Credentials

In the credentials tab of the program policy page, you have the option to either view or claim credentials, depending on the type of credentials that the program has set up.

Upon clicking the claim button, the credentials will be automatically assigned to you. However, for request credentials, you will need to submit a request, and the program will manually assign the credentials. You will be notified once the credentials have been assigned to you.

Upon assignment, you can view the credentials in the credentials tab, along with any relevant instructions for their use. This information will be available to you so that you can properly utilize the credentials to gain authorized access to the program's assets during testing.

<figure><img src="/files/ZedU9sTzT0RUzrX8rVOC" alt=""><figcaption></figcaption></figure>

## Reporting Issues with Credentials

If you encounter a problem while viewing a credential, you can report the issue by clicking on the "Report Issue" button in the credential details. This will open a modal for reporting the credential issue, where you can describe the problem you're experiencing.

Please use the "Issue Description" field to provide details and then click on "Submit Report." The program team will be notified via email.

<figure><img src="/files/KiPUqMvj0hkNoqZDblyU" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Please remember that these credentials are confidential and should not be shared with anyone outside. Additionally, use these credentials solely for testing purposes related to the particular program and asset.
{% endhint %}


# VPN Access

VPN is essential to access the specified assets in the program. It's important to note that these assets cannot be accessed without connecting to a VPN.

<figure><img src="/files/Xd9o9pgZMWA4Z3Q75UYZ" alt=""><figcaption></figcaption></figure>

## Program VPN servers

### 1. Viewing VPNs

1. Go to the program policy page and choose the **Credentials & VPN** tab.
2. You will see a list of VPN servers that the company has created.
3. Click on "View Server Configuration" to see the VPN configuration details.

<figure><img src="/files/p0z2SnM8qZ42QlfZstA5" alt=""><figcaption></figcaption></figure>

## 2. **Downloading VPN Configuration**

1. To obtain the OpenVPN configuration file, click on **"Download Configuration File"** button.

<figure><img src="/files/A1EwCJvOBA3g7qOoRBnR" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Learn[ how to connect to VPN using the config file here.](#connecting-to-vpn-using-the-config-file)
{% endhint %}

## 3. **Understanding VPN Configuration Details**

1. **Server Name:** This is the name given to the VPN server.
2. **Server Status:** Indicates whether the VPN server is currently running, stopped, or in the process of deploying.
3. **Rate Limit:** This refers to the maximum number of requests per minute allowed through the VPN, ensuring fair usage and server stability.
4. **Countries:** Lists the countries from which you are allowed to access the VPN.
5. **Accessible Assets:** Shows the specific domains (assets) you are permitted to test. Each domain includes:

   * **Asset:** The specific domain or asset you have access to.
   * **Active Time Period:** The time range during which the asset is available for testing.\ <mark style="color:red;">**NOTE: All time range is in UTC timezone.**</mark>
   * **Blacklist Routes:** Any API routes or paths that are off-limits, even when connected to the VPN.<br>

   <figure><img src="/files/jx4D2fVFQu0T5SV3CEsI" alt=""><figcaption></figcaption></figure>

## Connecting to VPN using the config file

Once you have .ovpn file downloaded ( config file ). Follow the below steps:

1. Add the domains/in-scope targets of the program to your /etc/hosts file
   1. Example: *docs.google.com* and *bugbase.in* are the domains/in-scope targets in the VPN configuration. Check [here for the accessible assets](#id-3.-understanding-vpn-configuration-details).
   2. Lookup the DNS resolution of the target domains.<br>

      <figure><img src="https://lh7-us.googleusercontent.com/m4H_HUrSexvS8WZdxTPF3-kCobrUcSswbMMaEhlETRReQNTtnPcfpKubtgZfczaEgDntJ4p-5ppFiakw-1bx-RRAbwOoIKiSWbUU4Ia-Wof_eF5SrjlkCOn96xsepoL6uf9hCcsZ23qVpAAjAI60tR8" alt=""><figcaption></figcaption></figure>

      <figure><img src="https://lh7-us.googleusercontent.com/2q9dSouTrsQiV0UdhOkkvmIa9RE4wh-XXYABxSWLWANLkpNBrEaGGQoAQllF27KBSGUZQiVva1uG6hpxNzY9w2KJbn4eCAzOjGFCeilDsOb_Wzypo89tCYmPNj31fBofqDspsLFOFjZxX4W9GgNnvko" alt=""><figcaption></figcaption></figure>
   3. Add the Addresses to the /etc/hosts for your linux systems or the corresponding local resolution files for Windows and MacOS.<br>

      <figure><img src="https://lh7-us.googleusercontent.com/xqnodjs48p9kmo2JrO_0SbDNwQtf0N2YWxvmLPUovvSUlZCWh3YTyhYIJWapksaAcqu6GwQjhqNNDgwBPyDKFxDZT3Yf74I0g55mjlWN0iqwsPi94BKOead5QoL5ef0_Nmex90Ab3TPVQmmWmJ8WXJ8" alt=""><figcaption></figcaption></figure>
   4. Connect to VPN Server using the .ovpn file with sudo permissions.
   5. Confirm a valid connection by checking the newly assigned IP on the tun interface.
      * \`ip a\` - Linux User
      * \`ipconfig\` - Windows User
      * \`ifconfig\` - MACOS
   6. Confirm additions of the domains/targets to the routing table
      * Linux users can use the `route` command to do this
      * MacOS Users can use \``netstat -rn`\` command to do the same
      * Windows users can use \``route print`\`
   7. In case the target domains are not live or do not have a valid IP address on Lookup, the IP will be separately mentioned in the Program description

{% hint style="info" %}
Please wait approximately 2-5 minutes before starting testing to ensure a smooth experience.
{% endhint %}


# Whitelist

A step-by-step guide for hackers to request whitelisting for assets requiring credentials.

## Requesting Whitelisting for Assets

To request whitelisting for assets requiring authorisation, follow these steps:

1. **Navigate to Program Page**
2. **Access the Credentials & VPN Tab**: Select the **Credentials & VPN** tab.
3. **Locate the Whitelist Section**: Scroll down to the **Whitelist** section to view assets requiring whitelisting.
4. **Request Whitelisting**:
   * Individually request whitelisting for each asset.
   * A prompt will display the specific requirements, indicating whether phone, email, or both are needed.

<figure><img src="/files/sRd1B1viSPyeRuLKVctt" alt=""><figcaption></figcaption></figure>

**Additional Notes**:

* If a phone number is required, ensure it is set up in the **User Settings** page before requesting whitelisting.
* For email requirements, the default BugBase alias will be used: **{username}@teambugbase.com**
* Requirements may vary by asset.


# Collaborate

Allowing and managing collaboration amongst bounty hunters within private programs.

### Toggling Collaboration on Private Programs

1. **Navigate to Profile Settings**
2. T**oggle collaboration** to enable or disable other users from contacting you for collaboration opportunities.

> Collaboration is enabled for all users by default

<figure><img src="/files/kTUTLzY8U1Yl3tG2phhI" alt=""><figcaption></figcaption></figure>

### Contacting users for collaboration

1. **Navigate to Private Program Dashboard**
2. **Collaboration Tab**
   1. Username - Click to view the user profile
   2. Send mail - Contact the bounty hunter via their BugBase email alias

<figure><img src="/files/7GhhPN39XdNHhcQ1AjEZ" alt=""><figcaption></figcaption></figure>


# Bounty Hunter Reports Section

View all reports categorised at one place to focus on what matters the most

<figure><img src="/files/21RKu9kkJ5KEfbcOL7QI" alt=""><figcaption></figcaption></figure>

The reports dashboard divides all the reports submitted(or collaborated on) by a bug hunter into neat sections:

* All Reports
* New Reports
* Triaged Reports
* Pending Action
* Unread
* Draft Reports
* Unlisted Reports

{% hint style="success" %}
All these sections are accompanied with Filters which allow bounty hunter to easily access whichever report they want.
{% endhint %}

### All Reports

This section lists all the reports that have been reported by the bounty hunter.

{% hint style="info" %}
The all reports tab does not include draft reports
{% endhint %}

### New Reports

This tab lists all the reports that have been submitted to a program and not yet triaged. It allows bounty hunters to keep a track of the new reports, their status and access them if they want to.

### Triaged Reports

This tab lists all the triaged reports. Any further communication with the program representatives can be done by accessing the bug report.

### Pending Action

This tab lists all the reports that require more context, program managers can label the report as **More Context Required** all the reports having this label will show up here.

### Unread

This tab lists all the reports that have not been read yet by the bounty hunter, viewing the report marks the report as read.

### Draft Reports

This tab lists all the reports for the bounty hunter which are not yet submitted but have been initialised and worked on upon.

This allows bounty hunters to fine tune their reports over a period of time before submitting it to the program.

### Closed Reports

This section lists all the reports which have been closed in one of the following ways:

* Resolved and Closed
* Duplicate and Closed
* Invalid and Closed
* Spam and Closed

A bounty hunter can still access the report and the conversation in case they want to by clicking on the report. However after 14 days of a report moving into the closed stage (Resolved/Duplicate/Invalid or Informational), the chat section and further report actions are disabled.


# Submitting Reports

A good report starts with a warm and cozy greeting

<figure><img src="/files/KaMPyZCQSIZBkGJGMo0c" alt=""><figcaption><p>Submit Report Page</p></figcaption></figure>

Once the hacker has found a valid bug, they can then proceed to submit a bug report by navigating to the program page and clicking on "Submit Report"

## Best Practice

Before submitting a report it is considered best practice to do the following steps to improve the quality of bug reports:

* Ensure that the bug is in-scope
* Ensure that the bug does not violate the program policy laid out in the Rules of Engagements
* Go through the bug report and ensure its clear, reproducible and properly formatted

### Selecting Scope

The program may have listed multiple in-scope items out of which the hacker has to select the one which the bug falls under.

Additionally, the hacker can add an in-scope item in case a wildcard was provided in the scope restrictions of the program.

{% hint style="info" %}
A hacker can add "docs.bugbase.in" as an item to the scope in case "\*.bugbase.in" was mentioned in the rules of engagement as the scope
{% endhint %}

### Vulnerable Endpoint / Affected URL (Optional)

This allows the hacker to further specify if a particular endpoint is vulnerable. Mentioning this can sometimes speed-up the triaging process by a bit.

### Selecting Vulnerability Type

The hacker has to select a Vulnerability Type from a dropdown menu which has a lot of Vulnerability types grouped by OWASP Top Ten Categories.

Selecting the correct vulnerability type allows the triager to see the bug in a particular context and improves impact of the bug report.

### Selecting Severity

The Severity can be selected in one of the two ways:

* Severity Picker
* CVSS Calculator

Whereas Severity Picker is very simple in design and a one-click process to set severity to a vulnerability, the CVSS Calculator breaks down the risk posed by the vulnerability and may be better able to define the overall severity of the vulnerability.

## The Report

#### Title

The title should define the bug in a few words. Phrases like "Remote command Execution" and "Unauthenticated Local File Inclusion" are welcome.

It can be used to expand upon the selected Vulnerability Type in a few words.

#### Summary

The Summary should describe the bug in a few sentences. The characteristics of the bug like complexity, user interaction, privileges required and a brief of the impact can be provided to improve the quality of the bug report.

#### Proof of concept

<figure><img src="/files/2GXLcGG629BciuwEi4ig" alt=""><figcaption></figcaption></figure>

BugBase provides a Bug Submission Template by default for every report. It can be modified by the hackers to suit their needs. It is suggested that this format be followed for all bug reports.

{% hint style="success" %}
The more seasoned hackers can most definitely use their own format provided it is professionally written and covers all the information needed to address the bug
{% endhint %}

#### Attachments

A good bug report is accompanied with screenshots or a video POC if it requires chaining of exploits/bugs. Adding attachments is optional but advised so as to assist the triaging team in reproducing the bug without issues.

#### Vulnerability Impact

The Impact section talks about the risk posed by the bug and the situations that could happen if the bug was exploited by a malicious hacker. It can also talk about how the bug can act a base for other possible bugs. *The impact section is not meant for further description of the bug*.

#### Reviewing Report

<figure><img src="/files/E0e82qOpTX0V0nUV3mHd" alt=""><figcaption></figcaption></figure>

Once the hacker has successfully filled all the sections of the bug report completely, a small pane shows them how the report looks like on the whole and would appear like once submitted.

Best Practice suggests going through the report thoroughly to see if something was missed or any other error is present.

If the hacker is not satisfied with their report and wants to amend their report at another time, the report can be saved as a draft and accessed later.

<figure><img src="/files/hl8D36aI1IRlLV0Ase6c" alt=""><figcaption></figcaption></figure>

#### Submitting the report

<figure><img src="/files/VsTUIRNrbFcz7yUqDKep" alt=""><figcaption></figcaption></figure>

Once the Hacker is satisfied with their bug report, they can submit the report by clicking on submit. Now the report will be sent to the program and will await the triage process.

<figure><img src="/files/szWKXc7YcLhTKzTJ45Z9" alt=""><figcaption></figcaption></figure>


# Interaction with Program Representees

Once a report has been submitted, the hacker gains access to a chat window while viewing the report.

<figure><img src="/files/3t0y5sAIZ5s5xHgFdlOD" alt=""><figcaption></figcaption></figure>

Here, the hacker can converse with the Program Representatives to provide any additional information or discuss about the bug.

Any communication with the program representatives has to be done via this chat window. This may include but is not limited to

* requests for more context
* requests for photo/video POC
* provision of more context
* provision of photo/video POC

{% hint style="info" %}
All the collaborators of the bug report can chat with the program representatives on the same chat window.
{% endhint %}


# Collaboration

Splitting bounties and working as a team!

This feature allows hackers to add other hackers as a collaborator on the bug report. This may be due to the reason that they both(or even more than two) collectively found the bug.

The hackers can easily add another hacker to a bug report after submitting it by navigating to the report and using the "Add invitee" button at the bottom of the chat window.

<figure><img src="/files/ccfk374GbdyudQFDW7nm" alt=""><figcaption></figcaption></figure>

To add a hacker as a collaborator, their BugBase username along with the bounty split percentage should be provided in the dialog box

<figure><img src="/files/EjGFtIeFKRKLC0dF90Lx" alt=""><figcaption></figcaption></figure>

The split percentage is mutually decided by the hackers and can be changed anytime before the bounty has been assigned.

{% hint style="warning" %}
The invited hacker has to accept the invite to the report from their notifications dashboard before getting access to the report and chat window.
{% endhint %}


# Response Generation through ChatGPT on Report Chat

The Response Generation is a new feature in our app that allows to generate responses using ChatGPT.

### How to Use the Response Generator

You can now generate replies using **ChatGPT** on any Bug Report on BugBase,which enables you to generate clear AI driven responses for frequently asked questions and customer inquiries without spending time crafting individual responses.

This **Generate Response with ChatGPT** feature can be found on any Bug Report.

<figure><img src="/files/LT3knTczPZD4AUGD9dOZ" alt=""><figcaption></figcaption></figure>

1. Click on the **Generate Response with ChatGPT** button.

<figure><img src="/files/7eEuIe9NsQBfwsnEzODH" alt=""><figcaption></figcaption></figure>

2. A popup will appear asking for a Prompt using which a response will be generate.
3. Specify a prompt for the response you want to generate. This could be a question or a statement that you want the response to be related to. This response will be generated keeping the previous chat messages in consideration.

<figure><img src="/files/vtyIGNDGy7JpbksJ0gjp" alt=""><figcaption></figcaption></figure>

4. Click on the **Generate Response** button. The app will then use ChatGPT to generate a response based on your prompt.

<figure><img src="/files/5g2LlYr3NwSmeM9sMR18" alt=""><figcaption></figcaption></figure>

5. Review the generated response. If you are satisfied with the response, you can edit and click on **Use this Response** button to copy the response to the message box.
6. If you want to alter the generated response, you can modify the prompt and click on the **Generate Response** button again. The app will then generate a new response based on the modified prompt.

<figure><img src="/files/Tt59KY5ghVpyrWhcqLks" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Note:** You can make a maximum of **10 requests** within a span of **24 hours**.
{% endhint %}


# Competitions

PwnTheWorld

<figure><img src="/files/A8LvLWcRRaqOSa5U5BHs" alt=""><figcaption></figcaption></figure>

The competitions dashboard displays the information about ongoing competitions hosted on BugBase.

These competitions are usually CTF/jeopardy type events which let the hackers show their elite skills off in a controlled environment.

Each competitions accompanies a separate leaderboard which shows the hackers with the highest points.

### All Competitions

This sections shows all the ongoing competitions. The hacker can resume with their progress on a joined competition by clicking on continue or join a new on by clicking join.

The competition banner is also accompanied by the details which tell the hacker more about the competition.

### My Competitions

This Section lists all the competitions that a hacker has joined. They can quickly navigate through them and start solving the CTF challenges.

### Rewards

The rewards won via competitions are communicated to the hacker via email or discord.


# Discord Community

GG!

<figure><img src="/files/OnbNMFXhV05yQHJEs1TJ" alt=""><figcaption></figcaption></figure>

Our discord is a lively community and you can hop on anytime to have a chat with a fellow hacker or one of our own security team.

## Support

The BugBase Discord has a ticketing system which allows hackers to raise any concerns or solve any of their issues with the platform or a program.

It is highly advised for all hackers to join the discord server to be able to get quick support.

## Competition Support

Any issues with any of the challenges of **BugTrials** and a general discussion or solutions(**After the competition has ended**) of challenges are very common at the BugBase Discord server and allow hackers to learn something new from each challenge.

## Community

Interact with the hackers around the World and make new hackers friends at the server.

{% hint style="success" %}
<https://discord.com/invite/UpyG8f9MCk> hosts the invitation link for the BugBase discord server
{% endhint %}


# Leaderboard

Elite Hacker leaderboard

<figure><img src="/files/60myRR75CGtho9zFI7aZ" alt=""><figcaption></figcaption></figure>

The Leaderboard shows BugBase's most active and "reputed" users

The Leaderboard lists the top ten hackers who have helped make the web a safer place.

Concise statistics of the hackers are also provided and their profile page can be easily visited by clicking on them.

{% hint style="success" %}
The Leaderboard's main aim is to add competitiveness to bug bounty hunting and motivates the hackers to become the best of them all.
{% endhint %}


# Multi-Factor Authentication

Secure your account with Multi-Factor authentication

Multi-factor authentication (MFA) is a security system that requires users to provide multiple forms of authentication in order to access a system, application, or service. This adds an extra layer of security, making it more difficult for unauthorised users to gain access to sensitive information

You can set up Multi-Factor authentication in one of the two ways. Firstly, using any **Authenticator** app capable of generating **Time-based One-Time Password (TOTP)** authentication codes. You can use Google Authenticator or Duo Mobile or any other compatible application to generate the codes. Secondly, You can enable OTP based login via Registered Email Address. Everytime you try to login a OTP will be sent to your registered email and you have to verify it.

### Setup

> To enable Multi-Factor Authentication:

1. Navigate to Your **Hacker Dashboard > Settings > Security.**
2. Choose any one of the Authentication type and Enable it.

<figure><img src="/files/zNp3w5fIRMZ3J4ZAxwQL" alt=""><figcaption></figcaption></figure>

### MFA via Authenticator App

1. Toggle **Enable multi factor authentication via authenticator app**.
2. A modal would pop up on your screen, click on the **Setup** button to initiate MFA process.

<figure><img src="/files/qh4raY6czMXu8RHdu8Kw" alt=""><figcaption></figcaption></figure>

3. You will see a `QR code` and also a `Secret key` on the screen.

<figure><img src="/files/Oev7AFq8noTYIlcV3VzU" alt=""><figcaption></figcaption></figure>

4. You can either scan the `QR code` or enter the `Secret Key` and manually save it on your Authenticator app. Now you would be able to see the`BugBase (username)` account in your app.
5. Click **`Continue`** once you have added your account in the Authenticator app.
6. Enter the 6-digit code from the Authenticator app and click on `Verify`.

<figure><img src="/files/XsA7x1kfIZEORj94v944" alt=""><figcaption></figcaption></figure>

7. After successful verification, you will be logged out from your account and you will be asked to enter the 6-digit OTP every time you are logging in.

<figure><img src="/files/XHPhlcJrRRaHTjO31OVt" alt=""><figcaption></figcaption></figure>

### MFA via Email OTP

1. Toggle **Enable multi factor authentication via email**.
2. A modal would pop up on your screen, click on the **Setup** button to initiate MFA process.

<figure><img src="/files/g52EeCoxnlhAJMNsN2jw" alt=""><figcaption></figcaption></figure>

3. A One-Time Password will be sent to your registered email and Enter the OTP to complete the verification process.

<figure><img src="/files/Nk0LI9SevAdvl0qhnfAG" alt=""><figcaption></figcaption></figure>

> You can disable multi-factor authentication as well from **`Settings`** > **`Security`**.




---

[Next Page](/llms-full.txt/1)

