Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Safety Bug Bounty
Safety Bug Bounty Bugcrowd $250–$7,500
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Safety Bug Bounty? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.

We’re pleased to announce that we are launching a new Bug Bounty Program for select safety and abuse issues. As AI technology rapidly evolves, so do the potential ways it can be misused. We believe it’s essential to recognize and reward responsible disclosures involving critical safety and abuse scenarios. Program Rules In addition to the existing OpenAI Security Bug Bounty rules, the following rules apply: Qualifying issues must represent a design or implementation issue in an active OpenAI product that can be abused by an attacker to cause material harm. Reports must be addressable via a clear set of recommended steps or mitigations. The goal of this program is to reward for bug fixes and we cannot reward requests for general product improvements. Qualifying issues must be consistently reproducible. Researchers should provide enough steps and evidence to reproduce the issue reliably under typical conditions. We may accept partial or probabilistic exploits if the result is still high impact, but the burden of proof is on the researcher to demonstrate it is not a one-off fluke. We only reward for issues that have not already been submitted to us. Any accounts used as victims must be test accounts owned by the researcher. Any testing that affects accounts, assets, or services owned by others is strictly prohibited. Vulnerability testing must not risk damage or compromise to any real-world accounts. For example, prompt injection text should not be hosted on public surfaces discoverable by real users or their agents. Final reward decisions and amounts are up to OpenAI discretion, especially when applied to safety issues.

Currency
USD
Submissions
Open
Scope entries
5 Bugcrowd’s count

Scope

5 assets
AssetTypeEligibilityMax severity
*.openai.com other ✓ bounty not set
Agentic Tools other ✓ bounty not set
openai.com website ✓ bounty not set
Other other ✓ bounty not set
OpenAI models other out not set