The Vercel Bug Bounty Program is now publicly available
By Steven Van ·
Vercel folds its private HackerOne program and its open-source bounty program into one public program covering the whole platform.
Vercel has merged its private HackerOne bug bounty program, running since 2022, with its open-source bug bounty program into a single public bug bounty program for Vercel.
The company says AI has sharply increased the volume of both valid and invalid vulnerability reports industry-wide. While some companies have responded by moving to private programs, Vercel says public reports were still surfacing real findings, so it built tooling to filter out noise and speed up triage and remediation ahead of the public launch.
- All products across the Vercel platform, plus its open-source projects, are now covered under the one program, with full scope listed on HackerOne.
- New vulnerability reports for Vercel's open-source projects should now go to the main Vercel program.
- Submissions already made through the previous OSS program do not need to be resubmitted; Vercel says it will still review them.
Vercel
The platform for frontend developers — deploy, preview, and scale web apps and AI agents with zero config.
View Vercel →