Sign up as a company with your legal name, website and country, and set up two-factor authentication. Our team then checks that the organisation exists and that your email belongs to it — usually within two business days. Until then you can complete your profile and upload a logo, but you cannot publish programs or jobs.
Under Visibility in the program editor you choose between a public program, listed for everyone, and a private program, which only the researchers you invite can see. Set it before you submit the program for review.
Once a program is private, the Invitations section lets you invite researchers by username, with an optional message. They get a notification and decide whether to accept. Only members can read the program's scope and send reports. You can cancel a pending invitation or remove a member at any time. Their earlier reports stay with you. Private programs never appear in the public listings or on hacktivity.
The Report inbox lists new and open reports across your programs. On each report you can triage, accept, resolve, or close it as duplicate, informative or not applicable (with a reason the researcher reads). You can also re-score the severity, award a bounty, write internal notes only your team sees, and disclose closed reports on hacktivity. Every change notifies the researcher.
When you award or raise a bounty on an accepted report, RootBounty creates a payment for that amount. Our finance team pays the researcher and records the transfer reference. Company dashboard → Payments lists every bounty with its status and totals. You also get a notification when each one is paid.
Verified companies can publish job offers (Dashboard → Job offers). They appear on the jobs board and your company profile straight away; you can close, reopen or delete them at any time.