THE REVIEW PROTOCOL

Receipts over reputation.

Bad Bounties is an independent PhantomBugz project about researcher experiences and program accountability.

Every star has a review behind it.

Platform reviews score payout as advertised, customer service and support, and timeliness separately. Company reviews score payout / response time and honesty. Each category is out of five. A profile with no approved review is unrated.

Private first. Public after approval.

  1. Choose a profile or add a company. A new company name can appear immediately with no review or score.
  2. Submit your scores, optional category explanations, and written review. The complete submission enters the private staff queue.
  3. Staff approves, rejects, or requests changes. Neither stars nor text go public until the complete revision is approved.
  4. Edit your review when circumstances change. Your existing approved revision stays public until its replacement is approved; a revision is never an extra vote.

Review the experience, not the exploit.

Discuss payment, communication, timelines, honesty, and program conduct. Include dates, published reward terms, and nontechnical administrative context. Do not post PoCs, exploit code, reproduction steps, technical vulnerability details, or links to technical proofs. This also applies to private context and forum replies. File uploads are not accepted.

One record per reviewer and profile.

Reviews are limited by account and public network address. Shared networks can affect eligibility. Revisions update the same review record. A company’s conduct is separate from that of the platform hosting its program.

Discussion stays open.

Verified members may reply to company discussions, approved cases, and the General discussion thread. Replies have no star values and do not affect averages. New case topics require staff approval. Moderation evaluates genuine participation, relevance, duplicates, conflicts, and the community Rules. Approval should not depend on whether an experience is positive or negative.

Represent a program?

Create an account, verify your email, and reply in the relevant discussion with your context or resolution. Clearly state any affiliation. A claimed affiliation is not verified unless staff has checked it.

Private context is separate from public discussion.

The case intake form separates the proposed public summary from private administrative context. You and authorized staff can access the private submission. Only the reviewed public fields are copied to the forum after approval. Site administrators and service providers have operational access; read Privacy for data-handling details.

Reports and requests for review.

Use Contact to report content or request review of a decision. Explain the specific concern and relevant nontechnical context. A request does not guarantee an outcome or change existing restrictions.