Q: What is BountyHQ?

BountyHQ is a public service, modeled after SecApps Scout, Devocore and Lookout, designed to aid bug hunting and vulnerability research. BountyHQ sole purpose is to advance information security research, enable bug bounty hunters, and ultimately make the Internet a better place.

Q: What can I do with BountyHQ?

Bug Bounty hunters benefit from our vast data. It is available for free and updated on a regular basis. Included, Bug Bounty Programs will benefit from our free scanning service to ensure that their assets are known and protected.

Q: How do I get started with BountyHQ?

It is very easy to get started. All related resources and help materials are available online and as part of the tool's built-in documentation.


How much does BountyHQ costs?

It does not cost anything. This is a service. We do it for the love of the community.


How many programs are included?

We include new programs on a regular basis. If your program of interest is not included yet, please get in touch and we will do everything we can to help.

How often do you scan?

This depends on the program itself. We can try to keep all of our data current. Please get in touch if the program of your interest is not scanned as frequently as you like. We might be able to help.

I represent a public bug bounty program and I would like to self-exclude?

Absolutely! We respect your decisions and we will take your public data as soon as you get in touch with us. We can be assured we mean no harm.

Q. How secure is my data in BountyHQ?

SecApps takes data security very seriously and this is why we have baked in hard security controls around your data. Your data has encryption at rest and in transit. Data is not persisted for longer than 3 months (90 days). This means that any data older than this period is automatically removed. This data is not archived so once removed it cannot be recovered.

Q. How long my data is retained by BountyHQ?

Your data is retained for up to 90 days from the time it is stored.

Q. What options do I have for encrypting data stored on BountyHQ?

Your data is automatically encrypted with the highest possible standard. SecApps does not need to access your data accept for executing your scouts and providing you access to read the data.

Q. Who can access my data?

You can access scout data from the Scout app from your Launchpad. In addition, you can export your data in multiple formats including CSV, JSON, XML and BSON. Your data will be available for up to 90 days from the time it is created.