// Bug Bounty AI guide

Understanding bug bounty program scope

How to read a bug bounty program's scope so you test the right assets — in-scope vs out-of-scope, accepted vulnerability types, and the rules that keep your testing authorized.

Scope is the single most important part of any bug bounty program, because it is what makes your testing authorized. A finding on an out-of-scope asset is not a valid submission — and testing it may not be legal. Reading scope carefully is the first skill a hunter develops.

In-scope vs out-of-scope assets

Programs list the domains, applications, and sometimes IP ranges you may test, and usually an explicit out-of-scope list. Third-party services the organization uses are almost always out of scope even when they are reachable. When in doubt, treat it as out of scope.

Accepted and excluded vulnerability types

Most programs specify which issues they reward and which they consider out of scope (for example, self-XSS or missing best-practice headers with no demonstrated impact). Reporting an explicitly excluded issue wastes everyone's time.

Rules of engagement

  • Respect rate limits and any required test-identifying header.
  • Use only test accounts you created, not other users' data.
  • Never attempt denial of service, and stop at proof of concept — do not pivot deeper than needed to demonstrate impact.

Related guides

A bug bounty reconnaissance workflowA practical, repeatable reconnaissance workflow for authorized bug bounty targets — from confirming scope to mapping the attack surface and deciding where to look first.Writing a clear vulnerability reportWhat makes a vulnerability report easy to triage and act on — a precise title, real impact, reproducible steps, and concrete remediation, written for the person who has to fix it.

Terms used here

Bug bountyA program through which an organization invites security researchers to find and report vulnerabilities in its systems, usually in exchange for recognition or a monetary reward. Testing is authorized only within the program's published scope and rules.Responsible disclosureThe practice of reporting a discovered vulnerability privately to the affected organization and giving it reasonable time to fix the issue before any public discussion. Also called coordinated disclosure; it prioritizes protecting users over publicity.Attack surfaceThe full set of points where an attacker could attempt to interact with a system — every exposed domain, endpoint, service, and input. Mapping the attack surface is a core goal of reconnaissance because you can only assess what you know exists.