Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Where credit is recorded in public

138 releases

Vendors name researchers in their own advisories and release notes. Verifiable ground truth that needs no platform's permission. Find your line and claim it: it is yours immediately, and it is durable standing on your profile even for vendors that run no bounty platform at all. Every credit carries a BugRater ID you can quote, CVE or not.