Bug Bounty Program Terms and Researcher Participation Agreement

Bug Bounty Program Terms and Researcher Participation Agreement

For Informational Purposes Only

A controlled reward-program agreement for eligible security research, with scoped authorization, severity and bounty rules, duplicate treatment, coordinated disclosure, payment compliance, and closure records.

Download Template (.docx)

Why You Need This

A vulnerability disclosure policy tells researchers how to report bugs. A bug bounty program tells them what they get paid for finding them. The two serve different purposes, and conflating them is a common startup mistake. This template gives you the contractual framework for a paid reward program: scoped authorization so researchers know exactly what systems they can test, a severity-based reward matrix so expectations are clear, duplicate-handling rules so you are not paying twice for the same finding, coordinated-disclosure controls so fixes ship before details go public, and payment compliance guardrails so your security team is not improvising cross-border payments from a spreadsheet.

What Is in the Package

The template covers the full lifecycle of a bug bounty engagement. It starts with program acceptance and eligibility — addressing age, jurisdiction, sanctions, employee exclusions, and identity requirements. It defines in-scope assets through a tiered registry that links each system to permitted testing methods and reward ranges. The conditional authorization provision establishes a safe harbor for compliant research without granting blanket immunity. Testing rules set boundaries on proof-of-concept depth, automated scanning rates, and prohibited methods. Report requirements specify what a submission must contain to be actionable. Severity determination uses CVSS plus business context, with documented overrides. The reward matrix ties payment ranges to severity tiers and asset criticality, with a reconsideration process for disputed decisions. Payment provisions address tax documentation, sanctions screening, team splits, and timing.

Key Provisions Explained

Reward Matrix and Funded Ranges

The template requires you to publish reward ranges by severity tier before launching the program — not to make ad hoc decisions after reports arrive. This is important because an apparent promise of payment can form a contract before your internal approvals are ready. The matrix ties Critical, High, Medium, and Low findings to dollar ranges, with documented authority to deviate for exceptional impact or quality. A program-wide budget cap and per-report maximum prevent open-ended financial exposure.

Duplicate and Collision Handling

The earliest complete, compliant report generally receives the reward — but “complete” matters as much as “earliest.” The template avoids a pure first-timestamp system that rewards incomplete reports and penalizes researchers who take time to document impact. Later reports can earn credit if they demonstrate a materially distinct root cause, exploit path, or impact not reasonably shown in the original submission. Related findings from the same root cause may be combined into a single bounty; unrelated findings should not be artificially bundled.

Payment Compliance

Paying security researchers across borders implicates tax withholding, sanctions screening, anti-fraud controls, and worker-classification rules. The template stages identity and tax documentation collection — you do not ask for a W-9 until a report is validated and potentially reward-eligible. Payment flows through your finance or platform provider, not through informal channels managed by your security team. Team submissions require a signed allocation instruction before payment splits.

Coordinated Disclosure

Researchers must keep nonpublic vulnerability details confidential until written disclosure approval or an agreed date. The company commits not to unreasonably withhold coordination and must consider active exploitation, user safety, and patch availability. This avoids both indefinite secrecy (which deters participation) and uncontrolled publication (which exposes users before a fix ships).

Reconsideration Process

A researcher can request one written reconsideration within 15 days, identifying the disputed scope, duplicate classification, severity, eligibility, or payment issue. A reviewer not solely responsible for the original decision issues a reasoned determination. This lightweight appeal mechanism materially improves consistency and researcher trust without creating a formal arbitration burden.

Included Schedules

Four schedules support the program terms: an Asset Scope and Tier Register linking each in-scope system to a reward tier and permitted methods; a Severity and Reward Matrix mapping CVSS-plus-context scores to funded payment ranges; a Report and Duplicate Decision Record documenting completeness, reproducibility, prior-case links, and appeal outcomes; and a Payment, Disclosure, and Closure Record tracking eligibility verification, tax and sanctions clearance, award amounts, and remediation status.

When to Use This Template

Use this after you already have a working vulnerability disclosure policy and remediation process. A bug bounty program without an underlying VDP is like offering commissions before you have a sales process — you will attract volume you cannot handle. This template is designed for companies ready to formalize paid security research: SaaS platforms, fintech companies, developer-tools businesses, IoT manufacturers, and any startup whose product surface is large enough that external researchers will find things your internal team misses.

Important Limitations

This is a drafting master. You must fund and approve reward ranges before launch, validate asset ownership and scope tiers, implement secure evidence handling and payment infrastructure, reconcile with your VDP and platform terms, and obtain security, finance, privacy, and legal approval. If you use a third-party bounty platform, reconcile the platform’s terms with these program terms and specify priority where they conflict.

Need help customizing this template for your business? Contact Montague Law to schedule a consultation and get this document reviewed by our team.

This template is provided by Montague Law for informational and educational purposes only and does not constitute legal advice. Consult a qualified attorney licensed in your jurisdiction before using any legal document.