# I found a bug — how do I report it?

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Two kinds of bug, two different places

Both are welcome, and they go to different teams.

- **A security bug** — something that could let somebody see data they should not, take over an account, or get past a permission check. Report it through the bug bounty program, where it reaches the security team, is tracked against a promised response time, and may earn a reward.
- **An ordinary bug** — a button that does nothing, a wrong total, a page that will not load. That is a support question: tell support what you expected and what happened instead.

## Reporting a security bug

- Open the program page — the workspace publishes one, often at an address like `security.thecompany.com`.
- Read the scope so you know what is in and out, and read the safe harbor terms.
- Press **Submit a report**, give your email, and open the link we send you. There is no account to create.
- Describe the issue, how to reproduce it, and what an attacker could do with it. Attach a screenshot or a short video if it helps.

You will get an email when the report is acknowledged, when it has been assessed, and when it is fixed. You can see your own reports at any time using the link you were sent.
## What happens next

Somebody reads it — a person, not a filter. The report is rated, and you are told the outcome with a reason, including when it is a duplicate or out of scope. If it is accepted it becomes tracked work, and you are told when it ships.

---

## Related Articles

- [Put the program on your own domain](https://help.totalctrl.app/en-US/articles/bugbounty-custom-domain-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)
- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Automate on reports: webhooks and the API](https://help.totalctrl.app/en-US/articles/bugbounty-api-and-webhooks-1)
- [Send reports to Issue Tracking or Jira](https://help.totalctrl.app/en-US/articles/bugbounty-trackers-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)