Community
Review Guidelines
A good review helps another researcher decide where to spend their week. These guidelines keep BugRater honest, useful, and safe. Reviews that follow them get published faster; reviews that don't get sent back or removed.
Write from first-hand experience
Only review a program you actually worked. Base your rating on your own submissions and interactions — triage speed, payout fairness, communication, scope honesty, and whether you'd submit again. Secondhand rumors and "I heard that…" don't belong here.
Be specific and fair
Specifics help: median time to first response, how a duplicate or scope dispute was handled, how the payout compared to the advertised range. Both positive and negative reviews are welcome — the fast, fair programs deserve credit just as much as the slow ones deserve a heads-up. Rate the experience you had, not the mood you're in.
Never post sensitive details publicly
Protecting users comes first. Nothing below relaxes this. Do not post:
- Details of unpatched or unfixed vulnerabilities.
- Embargoed information or anything under a coordinated-disclosure timeline.
- The contents of a private report, or anything that would break an NDA or program terms.
- Anything that could help someone attack the program's users.
You can describe how a program handled a report without revealing what the report was.
You may tell us privately
The most useful thing on a program page is why reports get closed there — and the useful version of that needs detail you must never publish. So we ask for it privately instead. Each report row in the review form has a Tell us privately panel with three questions:
- Which component or feature? — a name, like checkout webhook.
- How did it work, in a sentence? — the technique, not the steps.
- What could an attacker actually do? — the impact, in plain words.
Never a proof of concept, never reproduction steps, never a payload. If someone could follow what you wrote, it is too much — trim it or leave it blank. The panel is optional, the consent box is off until you tick it, and you can withdraw everything you have given us at any time from your reviews, which erases the text.
What we do with it
One promise, and it is the whole design: it never appears as your report — only as a number in a distribution that at least three reports contributed to. Here is how that is held up.
- Encrypted at rest. All three answers are encrypted with AES-256-GCM before they are written. The key lives in the application's configuration, not in the database, and not in any table a query can reach — so a stolen database is ciphertext. GCM is authenticated, so a tampered value fails to decrypt rather than decrypting to something else.
- Access is limited, and here is exactly who has it. You, from your reviews, where you can read back every word you gave us. And site moderators, who can read it when they are handling a dispute about a report — mediating means reading. No one else: not the program, not other researchers, not anyone browsing the site. We are not going to tell you we can't read it. We can, deliberately, because that is what makes it useful when a program and a researcher disagree about what was filed.
- Published only as aggregates. A value is named on a program page once at least three reports from at least two different researchers share it — both floors, every time. Everything under either one is folded into an unnamed “too few to name” row: counted, so the totals add up, never named. One person filing five reports is still one person. A value that folds is not decrypted to produce the page at all — it is counted as an encrypted token and left closed.
- One facet at a time. We never cross-reference two private answers, or a private answer against a close reason. Each list can clear the floor on its own while their intersection is a single report — that is how anonymised data gets unpicked, so we don't build the intersection at all.
- Withdrawable. Withdraw it from your reviews and the text is erased — the encrypted value and the token that let it be counted both go, and the program's numbers drop it on the next page load.
- It never touches a program's grade. The grade is computed from reviews. This is reporting.
What encryption at rest does not do is defeat someone who has compromised the application itself: code that runs as us can use the key, the same way the site does when it shows you your own answers. That is the honest boundary, and it is the reason the aggregate floors above are enforced in the query rather than left to good intentions.
If it isn't fixed yet
Tick hold this back on that report. An embargoed row counts toward nothing — not the component list, not any total — until you come back and untick it. If you are unsure whether a fix has shipped, leave it ticked.
Your NDA and the program's terms still bind you
Us asking does not override them. We are a third party. If the program's terms, your NDA, or a platform's disclosure policy forbid sharing this with anyone outside the program, then they forbid sharing it with us — don't. Leaving the panel blank costs you nothing, and a review with no private detail is still a good review.
No doxxing
Critique the program and its process, not the people. Don't publish private information about anyone, and don't name and target individual triagers or employees. "The triage team was slow to respond" is fair; naming a specific person to attack them is not.
No astroturfing or retaliation
Companies may not rate their own programs, and no one may post fake positive reviews to inflate a grade. Likewise, don't post a retaliatory fake review to punish a program over an unrelated dispute. Both undermine the ratings everyone relies on.
What gets a review rejected
We decline reviews that aren't first-hand, disclose sensitive or embargoed details, break an NDA, name individuals, read as astroturfing or retaliation, or are abusive or spammy. Reviews from researchers who've verified a platform account carry more weight in a program's grade, so verifying your account makes your honest experience count for more.
Keep it constructive
The goal is to help researchers choose where to spend their time. Write the review you wish you'd read before you started — clear, specific, and fair.