Skip to content
TRIAGERS
Strategy · 9 min read · TRIAGERS™ Team

How to Set Bug Bounty Reward Amounts (and Defend Them)

How to anchor bounty amounts to business impact, why underpaying criticals backfires, bonus practices that work, and how to raise your table without chaos.

The critical payout is the most scrutinized number in your entire program policy. Researchers read it before they read your scope, they compare it against every alternative use of their evening, and they will absolutely quote it back to you in a dispute. Most programs set it by copying whatever a comparable company publishes, which is how you end up with a payments platform paying the same $3,000 for account takeover as a recipe app, and then wondering why nobody serious hunts there.

This is how to set the numbers so they hold up, and how to defend them when they're challenged.

Anchor the table to business impact, not market vanity

The wrong way to build a bounty table is to browse public programs, find your "peers," and position yourself slightly above the median so the launch post looks respectable. That anchors your prices to other people's guesses about other people's risk.

The right anchor is a question your security team can actually answer: what does this class of bug cost us if an attacker finds it first? Full account takeover means something different on a bank than on a newsletter tool, even at identical CVSS. Work severity tier by severity tier:

  • What incident does this bug become? A critical on your payment flow becomes fraud losses, regulatory notification, and a disclosure to your largest customers. Price a meaningful fraction of that, because the researcher is selling you the option to skip it.
  • What does the alternative discovery channel cost? A boutique pentest runs $1,500 to $2,500 per tester-day and might surface one high per week. If a researcher hands you a working pre-auth RCE, they compressed weeks of billable hunting into one report. Paying $1,000 for it prices their work below the intern rate at the firm you already retain.
  • What is your data actually worth? PII, financial records, and health data carry statutory exposure per record. If a single IDOR can enumerate 400,000 customer records, a $500 bounty is a rounding error against the incident it prevents.

Rough shapes we see work in practice, by company profile:

Severity Early stage Established High-stakes (fintech, infra, health)
Critical $2,500–5,000 $10,000–20,000 $50,000+
High $1,000–2,500 $4,000–8,000 $15,000–25,000
Medium $250–500 $1,000–2,500 $3,000–6,000
Low $50–150 $200–500 $500–1,500

The absolute numbers matter less than the ratios. A table where critical pays only 3x medium tells researchers to farm mediums with a scanner. A healthy table pays criticals 20x to 50x what lows pay, because that spread is what funds the weeks of unpaid dead ends that finding a critical requires.

Underpaying criticals costs more than it saves

Criticals are rare: on most programs they're 2 to 5 percent of valid reports. That rarity means doubling your critical payout barely moves annual spend, while halving it changes who hunts your program entirely.

Run the arithmetic on a mid-size program: 300 valid reports a year, eight of them critical. Raising the critical bounty from $5,000 to $15,000 costs $80,000 a year. One critical that an attacker finds first, because the researchers capable of finding it were hunting somewhere that pays $15,000, costs you an incident response engagement, breach counsel, customer notification, and a quarter of executive attention. IBM's breach-cost reports put the median well north of $4 million; even discounting heavily for your size, the $80,000 is insurance priced at pennies.

The subtler cost is portfolio allocation. Top researchers run their time like a fund: expected payout times probability of success divided by friction. A cheap critical tier doesn't make them submit for less money, it makes them not start. You never see the reports you priced out of existence, which is why underpaying feels free right up until your program cost math includes a breach.

Pay on triage, not on fix

When you pay is part of what you pay. A $10,000 bounty delivered 120 days after submission, because policy says "on remediation," is worth less to a researcher than $8,000 within a week of validation, and they price accordingly.

Paying on fix ties researcher income to your engineering backlog, which they can neither see nor influence. Pay the full amount when triage validates the report. If finance insists on holding something back, split it: 80 percent on triage, 20 percent on fix verification. We cover why this single policy dominates most retention levers in the researcher relations guide.

Bonuses: where discretion earns its keep

A fixed table plus discretionary bonuses beats a complicated table. Keep the base table simple enough to fit in a screenshot, then reserve 10 to 15 percent of annual bounty budget for top-ups, awarded for specific behaviors you want more of:

  • Full chains. A researcher who takes SSRF to cloud metadata to account takeover, in one report with the complete path, saved you three tickets and showed you real blast radius. Pay the chain at the severity of its endpoint, then add 25 to 50 percent for the depth. If you pay chains as their most severe single link, researchers learn to split findings into separate submissions, and your queue gets worse.
  • Novel bug classes. The first report of a vulnerability class you've never seen on your stack is worth more than its CVSS, because it seeds your secure-coding guidance and your variant analysis. A flat "first of class" bonus ($1,000 to $2,500 on an established program) is cheap for what it teaches you.
  • Exceptional reports. Clean PoC, impact analysis, suggested fix, tested regression cases: top up 20 to 30 percent and say why in the comment. You're publicly pricing the report quality you want, and other researchers read disclosed reports.

Two rules keep bonuses defensible. Announce the categories in your policy so bonuses read as a system rather than a mood. And never use a bonus to quietly correct a severity you scored wrong: if the bug was a high, rate it a high and pay the high, because a medium-plus-bonus creates a paper trail that says your own table doesn't bind you.

Handling "other programs pay more"

Every program hears this, and the response depends on whether it's true.

Often it's an apples-to-oranges comparison: the researcher is quoting another program's theoretical maximum against your table midpoint, or a mobile OS vendor's exploit pricing against your SaaS program. Respond with the actual comparison: "That program's $50,000 tier is for persistent zero-click compromise of a platform with two billion devices. Our critical tier reflects impact on our asset base, and this report was paid at the top of it." Specific beats defensive.

Sometimes it's true, and that's market data, not an insult. If researchers with options keep telling you the same thing, and your top-ten submitters are going quiet, your table has drifted below clearing price. The mistake is fixing it per-report: matching one researcher's ask off-table teaches everyone that your prices are opening bids, and you'll renegotiate every critical forever. Hold the line on the individual report, pay exactly what the table says, and then change the table for everyone if the signal is real.

What never works is "our budget is limited." It may be true, but the researcher's alternative isn't your budget, it's another program, and budget arguments confirm that hunting you is charity.

When and how to raise the table

Watch for four signals:

  1. Your best researchers' submission gaps are widening. Time-since-last-report for your historical top ten is the earliest indicator, the same one that flags general researcher churn.
  2. Valid-report volume falls while scope grows. A growing attack surface with shrinking findings means attention went elsewhere, and price is the likeliest lever.
  3. Your pentests find things your bounty should have. If a two-week engagement surfaces three highs on assets that have been in scope for a year, your table wasn't buying the depth you assumed it was.
  4. Direct competitors publish a bigger table. Researchers hunting your sector see both.

When you raise, raise loudly. A bounty increase announced with a blog post and a platform update reliably produces a submission spike within days, which is the entire point: you're buying attention, so collect it. Consider making the increase retroactive for reports currently in the queue; it costs little and converts an announcement into goodwill with the exact researchers already engaged.

Raising for a specific scope area works as a temporary promotion: doubled bounties on the new acquisition's assets for 60 days redirects your existing researcher pool without permanently repricing everything. Lowering a table is occasionally legitimate (a scope area matured, or launch pricing was deliberately hot), but grandfather every in-flight report at the old rate and say plainly why, or the cut will be read as bad faith and cost more than it saves.

Communicating reward decisions without burning researchers

Most reward disputes are process failures wearing a pricing costume. The decisions that burn researchers share a pattern: the number arrived without reasoning, contradicted a previous decision, or moved after the fact.

  • Show the mapping, every time. "Rated High per our published table, CVSS 8.1, paid $6,000 at the top of the High band for report quality" survives scrutiny. A bare "$6,000" invites a negotiation you didn't need to have.
  • Consistency is the defense. The same bug class on the same asset must pay the same this quarter as last, across different triagers. That takes a shared rubric and a searchable decision log, the same machinery that keeps severity assignment honest, because reward disputes are usually severity disputes with a dollar sign attached.
  • Decide severity before looking at the invoice. If your severity calls cluster just under tier boundaries, researchers will chart it. Have the person rating the bug not be the person defending the budget.
  • When you underpaid, pay the difference without ceremony. A researcher who successfully argues impact and receives the top-up plus a thank-you tells that story for years. A researcher who wins the argument and receives silence tells a different one.
  • Never punish the appeal. Arguing a reward through proper channels is engagement. Programs that respond to polite pushback with slower responses select for researchers who don't care enough to argue, and those aren't the ones you want.

The table you can defend is the one built on impact math, applied identically to everyone, and adjusted in public. Anything else is a standing invitation to negotiate every report.


If reward disputes are eating your team's week, the underlying problem is usually inconsistent triage: severity drives money, and severity calls made by whoever was free that day won't hold up. TRIAGERS™ provides dedicated triage teams that apply your rubric the same way on every report, priced per report. Get in touch if your bounty decisions need a steadier hand behind them.

Keep reading
The Triage Brief

New articles, straight to your inbox.

Practical triage writing, published a few times a month. Unsubscribe anytime.

Or grab the RSS feed.

Drowning in unread reports?

Lease an expert triage team that validates, reproduces and rates every submission, so your engineers only see signal.

Get a triage team