Developer
Get Support
Sign in
Get Support
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Last updated Jan 14, 2025

Making your Bug Bounty Program Public

Overview

To strengthen security and foster a collaborative environment, Atlassian will be requiring all Marketplace bug bounty programs to be public. Public programs offer greater accessibility for security researchers, streamline vulnerability reporting, and help ensure programs remain active and effective over time.

Why Go Public?

Opening your bug bounty program to the public delivers several key benefits:

  • Broader Researcher Access - Public programs are visible to all registered researchers, maximizing opportunities for vulnerability discovery and reward
  • Reliable Reporting Channels - Public visibility ensures researchers can easily find and report vulnerabilities through trusted channels
  • Sustained Program Activity - Public programs are less likely to become stagnant, as ongoing engagement is more likely in a public facing bug bounty program

Benefits of a Public Bug Bounty Program

Transitioning to a public program is free of charge and offers immediate benefits for your security posture.

Expanded Researcher Pool
Your program will attract a diverse range of security researchers, increasing the likelihood of uncovering critical vulnerabilities.

Increased Visibility
Public programs are listed on bugcrowd.com/engagements, a central hub for researchers seeking new challenges.

Diverse Skill Levels
Engage with researchers of varying experience. Bugcrowd's triage team supports newer participants to maintain submission quality.

Managed Submission Flow
Bugcrowd limits public launches to three per week, allowing triage teams to effectively manage incoming reports.

Enhanced Security Reputation
Public participation demonstrates a strong commitment to security, building trust with customers and the community.

Considerations and Challenges

Plan ahead for these common challenges to ensure a smooth transition to public.

ChallengeImpactMitigation Strategy
Submission OverloadTeams may be overwhelmed by report volumePrepare a contingency plan and ensure robust triage processes are in place

Prerequisites for Public Launch

Before making your bug bounty program public, ensure the following requirements are met:

RequirementDescriptionWhy is this important?
Gradual Researcher OnboardingHave 250 Researchers Minimum for at least 2 weeksPrevents overwhelming your triage process with sudden volume spikes
FundingMaintain at least $5,000 in your program accountEnsures you can promptly reward researchers for valid submissions
Vulnerability QueueNo more than three P1 (critical) vulnerabilities should be outstandingDemonstrates your ability to handle critical security issues promptly
Consider Increasing Rewards (Suggestion)At your discretion, you can increase rewards to improve incentives for researchersDemonstrates your program maturity
Queue HygieneEnsure there are no overdue items or policy violations in your queueShows program maturity and operational readiness
Accurate Scope and TargetsReview and confirm that all program scope and targets are up to datePrevents confusion and misdirected research efforts
Robust Review ProcessInternal team must have a scalable process for handling increased volumeCritical for managing the initial weeks post-launch effectively

The internal team responsible for triage must have a scalable process in place to handle increased submission volume, especially during the initial weeks post-launch.

How do you start the process of going public?

The transition process

1. Initial Request
Raise a ticket in the ECOHELP queue and Bugcrowd will work with you on a specific plan of how to get your program public facing.

2. Customized Timeline
Timelines and plans to get to public will vary based on how your program has performed in the past and how much ramp up may be required to get that program to public in a non-overwhelming way.

3. Scheduled Launch

  • Launch day: Wednesdays at 2PM EST
  • Limited launches: Only three programs launch per week
  • Advance scheduling: Launches are scheduled ahead of time with the Bugcrowd team
  • Program review: The program brief is reviewed prior to launch to ensure clarity and alignment with Atlassian standards

Policy enforcement and deadlines

Deadline for compliance: All Atlassian Marketplace bug bounty programs must be public by June 30th, 2026, and should be in Progress by March 1st, 2026. Programs that haven't started the public transition process could be paused and deactivated.

Compliance Requirements

No exceptions policy:
Unfortunately there are no exceptions and all Atlassian managed marketplace bug bounty programs must be public or actively working toward transitioning to a public program.

What this means for your program:
Your program must be Public or you must have raised an ECOHELP ticket to start the transition process.

Enforcement actions:
If you are not in the process of going public by the compliance deadline, Atlassian is entitled to pause and deactivate your bug bounty program.

Once the program is made public, you will not be able to transition it back to private again.

Getting help

For questions about transitioning your bug bounty program to public:

Rate this page: