VDP Scope

Searchable policies and automation rules for major bug bounty programs. Know what you can test before you submit.

When researching a vulnerability, you need to know: Can I use automated scanners on this program? Is a proof of concept required? What scope is in-bounds? Researchers often search "[program name] automation policy", "[program name] scope", or "can I use automated scanner on [target]" — but program policies are scattered across multiple platforms.

VDP Scope aggregates these rules in one searchable reference so you can verify submission requirements before spending time on research.

Loading programs...

Automation Policies & Requirements

Each program has specific rules about what testing methods are allowed. Some prohibit fully automated scanners and require manual vulnerability research. Others have strict proof of concept requirements. Search below to find automation policy, scope, and submission requirements for your target.