# Put the program on your own domain

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Why bother

A program page at `security.yourcompany.com` is the address you can put in a policy, an email signature or a security.txt file. It is also the one researchers will trust.
## Setting it up

- Open **Custom domain** for the program and enter the hostname.
- Add the two DNS records shown — a CNAME and a TXT record.
- Press **Verify domain**. DNS can take up to an hour to spread.

## What is served there

Only the program page and its reporting flow. Nothing else on TotalCtrl is reachable on that hostname — not the sign-in page, not your workspace.

The domain belongs to one program, so an agency running a program per customer can give each its own address. Changing the hostname clears the verification, because the proof was for the old name.
## Branding

The page uses your Brand Kit. Pick which kit on the program’s Jira-free settings, or leave it to use the workspace default — a program with no branding configured still renders a finished page.

---

## Related Articles

- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Getting started with Bug Bounty](https://help.totalctrl.app/en-US/articles/bugbounty-getting-started-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)
- [Who can work a program](https://help.totalctrl.app/en-US/articles/bugbounty-access-1)
- [Internal notes and talking to a reporter](https://help.totalctrl.app/en-US/articles/bugbounty-comments-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)