submission checklist
01
Active program scope

The platform you're targeting must have an active bug bounty program with the asset class in scope at submission time.

02
Public or invite-only

SoGood's program is open — no invite required. For invite-only programs, have your program acknowledgment ready.

03
Responsible disclosure

By submitting, you confirm use for authorized security research only and agree to follow the platform's disclosure policy.

04
Delivery

The signed zip is delivered to the email you provide. The manifest.json inside records your handle, scope, and the SHA-256 hash.

Request a workspace clone

Free for authorized security researchers.

Authorization is verified before any export begins.

Built with