Arkose Labs

  • $100 – $2,000 per vulnerability
  • Partial safe harbor
  • Managed by Bugcrowd

Program stats

33 vulnerabilities rewarded

Validation within 2 days
75% of submissions are accepted or rejected within 2 days

$500 average payout (last 3 months)

Latest hall of famers

Recently joined this program


Please note: This program does not allow disclosure. You may not release information about vulnerabilities found in this program to the public.

Arkose Labs invites you to test and help secure our enforcement challenges and customer portals. We appreciate your efforts and hard work in making our web applications more secure and look forward to working with the researcher community to create a meaningful and successful bug bounty program. For researchers with repeat submissions that are reliable and in the spirit of responsible disclosure, Arkose Labs may invite you to a private program with higher rewards and closer interactions with our team.

As part of this public program;

  • Do not release or disclose any new or existing findings on social media or publicly available channels.
  • Avoid compromising the privacy and user experience of our customers
  • Avoid disrupting any corporate or production systems
  • Do not destroy data
  • Perform security research within the scope set out in this policy
  • Contact us immediately if user data is found during testing

If the terms in this policy are breached, then future rewards may be denied
Good luck!

This program follows the Bugcrowd VRT for standard ratings.

Scope and rewards

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email We will address your issue as soon as possible.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.