# Bug Bounty

Take security bug reports from outside your company: publish a vulnerability disclosure program, receive reports from researchers, and work them in a queue that measures the response times you promised.

[← TotalCtrl Help Center](https://help.totalctrl.app/en-US/)

## Articles

- [Put the program on your own domain](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-custom-domain-1)
- [Response times and the disclosure window](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-sla-1)
- [Scope groups and reward tables](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-scope-and-rewards-1)
- [Automate on reports: webhooks and the API](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-api-and-webhooks-1)
- [Send reports to Issue Tracking or Jira](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-trackers-1)
- [Getting started with Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-getting-started-1)
- [Who can work a program](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-access-1)
- [Internal notes and talking to a reporter](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-comments-1)
- [Triage: states, priority and duplicates](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-triage-1)
- [Writing your policy, and what goes where](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-policy)
- [I found a bug — how do I report it?](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-found-a-bug)
- [What is stored, and what is never sent](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/articles/bugbounty-data-handling-1)