The Vercel Bug Bounty Program is now publicly available
In 2022, we launched a private bug bounty program through HackerOne. Over the last several years, we've worked with HackerOne's VIP program to refine our process, targets, and scope, onboarding thousands of their best researchers and hardening security across our platform.
We've translated those learnings into several public bounty programs:
Today, we are combining our private and OSS bounty programs into a single, public Vercel bug bounty program.
Copy link to headingWhy now
AI has fundamentally changed the nature of bug bounty programs, exponentially increasing the number of reports, both valid and invalid. Some companies are responding by moving to private programs.
At Vercel, we’ve found that public reports are still surfacing real, valuable findings. AI enables a much wider range of researchers to discover vulnerabilities, and we believe in evaluating reports on their own merit, so making our entire program public was the logical choice.
In preparation for the public launch, our security engineering team has streamlined our process and built tooling to filter out noise and expedite remediation. We have improved every step, from triaging reports to shipping and verifying fixes.
Our team and processes have been battle tested through our private program and several large public programs in the recent past. We are ready to open a comprehensive program to the public and have the best researchers out there responsibly explore every part of the platform.
Copy link to headingWhat is covered
All products across the Vercel platform and our open-source projects are now part of our unified public program. Read the Scope page on HackerOne for full details on what is covered.
Consolidation makes sense for our processes, but we also received feedback from the research community that having multiple programs made disclosure confusing because there were multiple places to submit reports. A single program simplifies reporting across our platform and open-source projects.
New findings in our open-source projects should be reported to the main Vercel program, but if you already have submissions to the previous OSS program, you don't need to copy them over. We will still review every submission that was made through that program.
Copy link to headingHow to participate
If you’re a security researcher, visit our HackerOne program page for details, bounties, and guidelines.
To file a report, submit your findings through HackerOne with clear reproduction steps. Our security team reviews every submission and works with researchers via the disclosure process. We're committed to fast response times and transparent communication.
We appreciate the researchers who take the time to dig into our code and report issues responsibly. We would also like to thank all the researchers who have been working in our private program. You have helped build the foundation for this public program, and nothing will change for you. We look forward to your future submissions.
Learn more about security at Vercel.
Copy link to headingJoin our security team
If this kind of work excites you, we are hiring. Apply to join the Vercel security team.
Contributors
