# Writing your policy, and what goes where

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

A program has two setup pages and they answer different questions. The one people get stuck on is **Policy**, because it is prose and a blank box is not a question anybody can answer. There is a draft to start from — see below.
## Which page does what

- **Policy** — how somebody is allowed to test, and whether they are protected for doing it. Rules of engagement, the kinds of finding you will not accept, your safe harbor promise, how disclosure works.
- **Scope and rewards** — what is testable and what it pays. A group per kind of asset, the targets inside it, and a reward range per priority. This is a table, not prose.

Keep asset names and money out of the policy text. Both already appear on the public page from the scope table, and a second copy in prose goes stale on its own — the published page then contradicts itself.
## Start from a draft

While the policy is empty, the Policy page offers **Insert draft policy**. It writes a complete first version covering rules of engagement, common findings that are not eligible, safe harbor and disclosure. Read it through and edit it — it is a starting point, not legal advice, and the safe harbor paragraph in particular is one your own lawyer should see. The button disappears once there is a policy, and it will not overwrite one.
## The Summary field

One line, published in two places: under the program name at the top of the public page, and as the description a search engine or a chat app shows when somebody shares the link. Write it as a sentence somebody outside your company would understand.
## Do not repeat your response times

Acknowledge within, Assess within and the disclosure window are fields further down the same page. They are published on the program page and every report is measured against them — that is where the queue gets "past a promised time" from. Writing the same numbers into the policy text means changing one and not the other.
## You can see how it reads

**View public page** is in the top bar of the Policy page and of Overview. The policy is formatted rich text — headings, lists, links — and it renders on the public page the way it looks in the editor.

---

## Related Articles

- [Put the program on your own domain](https://help.totalctrl.app/en-US/articles/bugbounty-custom-domain-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)
- [Getting started with Bug Bounty](https://help.totalctrl.app/en-US/articles/bugbounty-getting-started-1)
- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Automate on reports: webhooks and the API](https://help.totalctrl.app/en-US/articles/bugbounty-api-and-webhooks-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)