Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
VR Public Managed Bug Bounty Engagement
3 more reviews needed for a grade
Write a review Claim this company profile

Work at VR Public Managed Bug Bounty Engagement? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.

We are a modern passenger, logistics and maintenance service company owned by the Finnish state which operates in Finland and Sweden. Please follow the rules detailed in this page to prevent unforeseen security problems to the clients of VR, their data or the business of the VR Group. Ratings/Rewards For the initial prioritization/rating of findings, this engagement will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Engagement Guidelines To gain the biggest bounty you need to be for example able to gain access to most or all client data or their personal details, or are able to misuse their payment methods. This will require a well-documented proof of concept code If the vulnerability reported does not create a risk or is not a security issue, we reserve the right to not award a bounty If the vulnerability is in a publicly available and widely used library, we may award a bounty which is smaller than usual If you report to us several vulnerabilities which turn to be different versions of the same root cause vulnerability, or the vulnerability is a smaller aspect of a bigger vulnerability, these reports can be combined for determining the bounty. Due to regulations, we interact with the original reporter only when discussing the reported vulnerabilities

Currency
USD
Submissions
Open
Launched
Oct 2025
Scope entries
1 Bugcrowd’s count

Scope

1 asset
AssetTypeEligibilityMax severity
www.vr.fi website ✓ bounty not set