{"programs": [{"slug": "velo-payments", "name": "Velo Payments", "org": "Velo Payments International Ltd.", "tagline": "Card acquiring, merchant tooling and payout rails. Sandbox credentials, or no report.", "url": "/programs/velo-payments/", "model": "Bounty", "status": "active", "managed": true, "tags": ["payments", "api", "web", "ios", "android"], "bounty_max": 50000, "bounty_label": "$500 – $50,000", "logo_text": "VP", "logo_color": "#0f766e", "text": "velo payments velo payments international ltd. card acquiring, merchant tooling and payout rails. sandbox credentials, or no report. bug bounty accepting reports payments api web ios android https://dashboard.velopay.example https://api.velopay.example/v4 https://checkout.velopay.example https://hooks.velopay.example https://payouts.velopay.example/v2 velo ios sdk velo android sdk https://api.velopay.example/v3 vault.velopay.example url api url api api ios android api network"}, {"slug": "stratamesh", "name": "Stratamesh", "org": "Stratamesh Technologies, Inc.", "tagline": "Multi-tenant Kubernetes: one control plane, eleven thousand tenants, one boundary that matters.", "url": "/programs/stratamesh/", "model": "Bounty", "status": "active", "managed": true, "tags": ["web", "api", "cloud", "kubernetes"], "bounty_max": 25000, "bounty_label": "$250 – $25,000", "logo_text": "SM", "logo_color": "#4f46e5", "text": "stratamesh stratamesh technologies, inc. multi-tenant kubernetes: one control plane, eleven thousand tenants, one boundary that matters. bug bounty accepting reports web api cloud kubernetes *.stratamesh.example https://api.stratamesh.example/v3 https://console.stratamesh.example registry.stratamesh.example *.stratamesh-edge.example strata terraform-provider-stratamesh ops2.stratamesh.example billing.stratamesh.example domain api url api domain executable source code url url"}, {"slug": "cadence-health", "name": "Cadence Health", "org": "Cadence Health Systems, PBC", "tagline": "Patient portal, clinician workspace and a FHIR R4 gateway. Synthetic records only, and we mean it literally.", "url": "/programs/cadence-health/", "model": "Bounty", "status": "active", "managed": true, "tags": ["healthcare", "web", "api", "android", "mobile"], "bounty_max": 18000, "bounty_label": "$250 – $18,000", "logo_text": "CH", "logo_color": "#dc2626", "text": "cadence health cadence health systems, pbc patient portal, clinician workspace and a fhir r4 gateway. synthetic records only, and we mean it literally. bug bounty accepting reports healthcare web api android mobile portal.cadencehealth.example fhir.cadencehealth.example care.cadencehealth.example id.cadencehealth.example api.cadencehealth.example rx.cadencehealth.example example.cadencehealth.patient direct.cadencehealth.example print.cadencehealth.example url api url domain api api android api url"}, {"slug": "arbor-ai", "name": "Arbor AI", "org": "Arbor Intelligence, Inc.", "tagline": "Inference, agent tool calling and retrieval. We pay for boundaries crossed, not for text we wish the model had not written.", "url": "/programs/arbor-ai/", "model": "Bounty", "status": "active", "managed": true, "tags": ["ai", "llm", "api", "cloud"], "bounty_max": 20000, "bounty_label": "$300 – $20,000", "logo_text": "AA", "logo_color": "#9333ea", "text": "arbor ai arbor intelligence, inc. inference, agent tool calling and retrieval. we pay for boundaries crossed, not for text we wish the model had not written. bug bounty accepting reports ai llm api cloud https://api.arbor-ai.example/v2 https://agents.arbor-ai.example/v1 arbor-lm-3 (hosted inference endpoint) arbor-embed-2 (hosted embedding model) https://gateway.arbor-ai.example https://console.arbor-ai.example weights.arbor-ai.example https://api.arbor-ai.example/v1 gallery.arbor-ai.example api api ai model ai model api url network api url"}, {"slug": "wayfare-mobility", "name": "Wayfare Mobility", "org": "Wayfare Mobility Systems GmbH", "tagline": "Connected-vehicle and fleet telematics. Bench hardware only, and never a vehicle that is in service.", "url": "/programs/wayfare-mobility/", "model": "Bounty", "status": "active", "managed": false, "tags": ["iot", "hardware", "mobile", "api", "network"], "bounty_max": 15000, "bounty_label": "$200 – $15,000", "logo_text": "WM", "logo_color": "#b45309", "text": "wayfare mobility wayfare mobility systems gmbh connected-vehicle and fleet telematics. bench hardware only, and never a vehicle that is in service. bug bounty accepting reports iot hardware mobile api network wayfare tcu-6 telematics control unit wayfare hu-4 infotainment head unit wayfare-os 4.x firmware bundles https://api.wayfare.example/fleet/v3 ota.wayfare.example wayfare drive (android) wayfare drive (ios) https://api.wayfare.example/fleet/v2 depot.wayfare.example hardware hardware executable api network android ios api url"}, {"slug": "giving-hust", "name": "HUST Giving", "org": "Hanoi University of Science and Technology", "tagline": "Donation and fundraising portal. Tested under written authorisation from the university.", "url": "/programs/giving-hust/", "model": "Bounty", "status": "active", "managed": true, "tags": ["web", "api", "payments"], "bounty_max": 10000, "bounty_label": "$50 – $10,000", "logo_text": "GH", "logo_color": "#8a1538", "text": "hust giving hanoi university of science and technology donation and fundraising portal. tested under written authorisation from the university. bug bounty accepting reports web api payments giving.hust.edu.vn giving.hust.edu.vn/* (donation flow) giving.hust.edu.vn (payment callback / ipn handlers) giving.hust.edu.vn (administrative interface) giving.hust.edu.vn (public api endpoints) giving.hust.edu.vn (file upload, if reachable) domain url api url api url"}, {"slug": "hustack", "name": "HUSTack", "org": "School of ICT – Hanoi University of Science and Technology", "tagline": "Online programming judge for algorithms, data structures and competitive programming. Test the sandbox and submission isolation.", "url": "/programs/hustack/", "model": "VDP", "status": "active", "managed": true, "tags": ["web", "api", "sandbox", "code-execution"], "bounty_max": 0, "bounty_label": "No cash reward", "logo_text": "HS", "logo_color": "#d32f2f", "text": "hustack school of ict – hanoi university of science and technology online programming judge for algorithms, data structures and competitive programming. test the sandbox and submission isolation. vulnerability disclosure accepting reports web api sandbox code-execution hustack.soict.ai hustack.soict.ai (submission / code execution sandbox) hustack.soict.ai (api endpoints) hustack.soict.ai (submission viewing / idor) domain api api url"}, {"slug": "ironvale", "name": "Ironvale Foundation", "org": "Ironvale Foundation, a registered nonprofit association", "tagline": "Volunteers keeping ironvale-tls, ivpkg and the Anvil build tool alive. Clone it and break it.", "url": "/programs/ironvale/", "model": "VDP", "status": "active", "managed": false, "tags": ["open-source", "network", "desktop", "cloud"], "bounty_max": 0, "bounty_label": "No cash reward", "logo_text": "IF", "logo_color": "#2563eb", "text": "ironvale foundation ironvale foundation, a registered nonprofit association volunteers keeping ironvale-tls, ivpkg and the anvil build tool alive. clone it and break it. vulnerability disclosure accepting reports open-source network desktop cloud git.ironvale.example/ironvale/ironvale-tls git.ironvale.example/ironvale/ivpkg registry.ironvale.example release.ironvale.example git.ironvale.example/ironvale/anvil git.ironvale.example/ironvale/ironvale-tls-sys git.ironvale.example ironvale-tls 2.6 maintenance branch source code source code api domain source code source code domain source code"}, {"slug": "meridian-civic", "name": "Meridian Civic Systems", "org": "Meridian Civic Systems Authority", "tagline": "Shared permitting, transit fares and open data for the nineteen municipalities that own us.", "url": "/programs/meridian-civic/", "model": "VDP", "status": "active", "managed": true, "tags": ["government", "web", "api", "cloud"], "bounty_max": 0, "bounty_label": "No cash reward", "logo_text": "MC", "logo_color": "#0e6a80", "text": "meridian civic systems meridian civic systems authority shared permitting, transit fares and open data for the nineteen municipalities that own us. vulnerability disclosure accepting reports government web api cloud permits.meridiancivic.example id.meridiancivic.example api.meridiancivic.example fares.meridiancivic.example inspections.meridiancivic.example notify.meridiancivic.example data.meridiancivic.example legacy.meridiancivic.example url domain api url url api url url"}, {"slug": "driftline", "name": "Driftline Games", "org": "Driftline Games Ltd.", "tagline": "Tidebreak: a team shooter with a player-run economy. Client, matchmaking, market, anti-cheat.", "url": "/programs/driftline/", "model": "Bounty", "status": "paused", "managed": false, "tags": ["gaming", "web", "api", "desktop"], "bounty_max": 12000, "bounty_label": "$100 – $12,000", "logo_text": "DG", "logo_color": "#db2777", "text": "driftline games driftline games ltd. tidebreak: a team shooter with a player-run economy. client, matchmaking, market, anti-cheat. bug bounty paused gaming web api desktop tidebreak client, windows and linux retail builds market.driftline.example mm.driftline.example account.driftline.example api.driftline.example ridgeback anti-cheat driver legacy-api.driftline.example creators.driftline.example executable api api url api executable api url"}]}