# Welcome to the Bugv Docs Hub!

Welcome to the Bugv Documentation Hub! Here, you’ll find everything you need to dive into Bugv’s features, tools, and resources, all in one place. Let’s get started!

{% content-ref url="/pages/-MbLXok5XOhR1CFpeUHj" %}
[Researchers](/researchers/dashboard)
{% endcontent-ref %}

{% content-ref url="/pages/-MbLvCqpuTnDeuSXptyE" %}
[Customers](/customers/login)
{% endcontent-ref %}


# User Registration

As Bugv is a crowdsourced platform, anyone can register to participate. To register, please follow these steps:

1. Visit [https://bugv.io/signup/ ](<https://bugv.io/signup/ >)

![](/files/-MbLS5pcjLkApO9GaBuG)

2\. Select your account type and proceed with the signup process.&#x20;

3\. Register as a user, hacker, or researcher using the following link.

```bash
https://app.bugv.io/researcher/sign-up
```


# Customer Registration

If you’re looking to launch your own bug bounty program for your company, you’ll need to sign up as a customer on Bugv.

You can sign up as a customer by visiting the following link: [https://bugv.io/signup/ ](https://bugv.io/signup/)

![](/files/-MbLS5pcjLkApO9GaBuG)

Choose the option '**I am a Company**' if you wish to register as a company.

{% hint style="info" %}
At this time, we do not offer open or direct registration for customers. The customer registration process is manual, and we need to verify all details before onboarding clients.
{% endhint %}


# Platform Login

All users and customers can access their dashboards using the same login page.

```
https://app.bugv.io/sign-in
```

![Bugv Login page](/files/-MbLXcEEtLR8qOQLMxpN)


# Dashboard

After [logging](/login/login) in as a user or researcher, you'll arrive at your profile dashboard.

```
https://app.bugv.io/researcher/dashboard
```

![User dashboard snapshot](/files/-MbL_asLSA0wTjtYQJj4)

{% hint style="info" %}
At the moment, our dashboard cannot be made public, but this feature will be available in the future.
{% endhint %}


# Program

The program page lists all available and public programs offered on our platform.&#x20;

```
https://app.bugv.io/researcher/program
```

![](/files/-MbLfQgYltxj2dBbH-kA)


# My Submissions

This page displays all the vulnerability reports you submit to various programs.

```
https://app.bugv.io/researcher/my-report
```

![](/files/-MbLgtrsdrx8a4CTH45s)


# Severity of Reports

The severity of the report is classified according to the following categories:

<table data-header-hidden><thead><tr><th width="207">SEVERITY</th><th>DESCRIPTIONS</th></tr></thead><tbody><tr><td>SEVERITY</td><td>DESCRIPTIONS</td></tr><tr><td>CRITICAL                           </td><td>A report that poses a critical threat to the customer's assets.</td></tr><tr><td>HIGH</td><td>A report that has a significant impact on the customer's assets.</td></tr><tr><td>MODERATE</td><td>A report that has a moderate impact on the customer.</td></tr><tr><td>LOW</td><td>A report that has a minimal impact on the customer's assets.</td></tr><tr><td>INFORMATIONAL</td><td>A report that has no impact or poses an acceptable risk to the customer's assets.</td></tr></tbody></table>

{% hint style="info" %}
The final determination of the report's severity is also made by the customers.
{% endhint %}


# Report Status

Each report or submission has a unique status as it progresses through the report lifecycle. The following are the report statuses available on our platform.

![](/files/-MbLhNSRL8VBfPZeP5Yk)

### Report Status

<table data-header-hidden><thead><tr><th width="195">STATUS</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td>STATUS</td><td>DESCRIPTION</td></tr><tr><td>NEW                                                                   </td><td>When a vulnerability is reported, it is classified as NEW and has not yet been reviewed.</td></tr><tr><td>TRIAGED</td><td>This status is assigned to the report once it has been accepted.</td></tr><tr><td>DUPLICATE</td><td>If the report has already been submitted by another user, it is marked as Duplicate, indicating that it has been previously reported.</td></tr><tr><td>WON'T FIX</td><td>If the report has minimal impact and is deemed an acceptable risk, it is marked as Won't Fix.</td></tr><tr><td>NOT APPLICABLE</td><td>The report is marked as Invalid when it does not pose a security risk or impact.</td></tr><tr><td>UNRESOLVED</td><td>The report is marked as Accepted when it is considered acceptable and assigned to a developer for resolution.</td></tr><tr><td>RESOLVED</td><td>When the reported issue or bug is fixed, the report will be marked as Resolved.</td></tr></tbody></table>

**Severity of Reports**

Severity of the report has been classified on the following terms:&#x20;

<table data-header-hidden><thead><tr><th width="187">SEVERITY</th><th>DESCRIPTIONS</th></tr></thead><tbody><tr><td>SEVERITY</td><td>DESCRIPTIONS</td></tr><tr><td>CRITICAL                           </td><td>A report that poses a critical threat to the customer's assets.</td></tr><tr><td>HIGH</td><td>A report that has a significant impact on the customer's assets</td></tr><tr><td>MODERATE</td><td>A report that has a moderate impact on the customer.</td></tr><tr><td>LOW</td><td>A report that has a minimal impact on the customer's assets.</td></tr><tr><td>INFORMATIONAL</td><td>A report that has no impact or poses an acceptable risk to the customer's assets.</td></tr></tbody></table>

{% hint style="info" %}
The final determination of the report's severity is also made by the customers.
{% endhint %}


# Points Earned Through Bug Lifecycle

The report progresses through various stages of the bug lifecycle and earns specific points upon completing the lifecycle.

![](/files/-MbLkUKx301b0aRevQwt)

Here is the point system implemented on the platform.

| STATUS      | POINT EARNED |
| ----------- | ------------ |
| CRITICAL    | 50           |
| HIGH        | 30           |
| MODERATE    | 20           |
| LOW         | 10           |
| DUPLICATE   | 5            |
| INFORMATIVE | 0            |

{% hint style="info" %}
Currently, we do not offer points for Informative reports, but we may include points for them in the future.
{% endhint %}


# Payment Reports

This page provides a summary of all payments received for your reports.

```
https://app.bugv.io/researcher/payment
```

![](/files/-MbLs2O5HTPykc8rLUB0)

The payment page consists of two sections.

**Pending Payment**\
This section lists all pending payments that are yet to be transferred to your preferred payment methods from Bugv.

**Received Payment**\
This section lists all payments that have been successfully transferred to your preferred payment methods from Bugv.


# Payment Methods

As a security researcher, you can receive your payment through either of the two available methods:

1. [eSewa](https://esewa.com.np)
2. [PayPal](https://paypal.com)

```
https://app.bugv.io/researcher/profile/payment-option
```

![](/files/-MbLt32cNLRH2AyjopEz)


# Payment Information

All payments will be dispatched within 2-3 business days after the bounty has been awarded.

{% hint style="info" %}
The payment process may be delayed if the user has not been verified. Therefore, please verify your account for quicker payment.
{% endhint %}


# Leaderboard

The leaderboard displays a ranked list of users in descending order based on [points ](/researchers/my-report/points)earned, placing users with the highest points at the top.

```
https://app.bugv.io/researcher/leaderboard
```

![](/files/-MbLutCnPG2D64z-YY10)


# Customer Login

All user types share the same [Login](/login/login) on the platform. You can sign in using the link below:

<figure><img src="/files/IAsXPNnlR5CZwrjuzyq5" alt=""><figcaption></figcaption></figure>

```
https://app.bugv.io/sign-in
```


# Dashboard

Once you log in, you will be greeted with the organization's (customers') dashboard.

```
https://app.bugv.io/organization/dashboard
```

![Organization Dashboard](/files/-MbLwN-7giuYMfA779-L)

Here are the ingredients for the dashboard.

<table data-header-hidden><thead><tr><th width="225.5">INGREDIENTS</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>INGREDIENTS</strong></td><td><strong>DESCRIPTION</strong></td></tr><tr><td>Total Programs</td><td>Displays the total number of programs currently available in your organization.</td></tr><tr><td>Running Programs </td><td>Displays the total number of approved programs within your organization.</td></tr><tr><td>Unapproved Programs</td><td>Indicates the number of programs that have been rejected.</td></tr><tr><td>Overall Stats</td><td>Provides an overview of your organization's status regarding reports, payments, and points.</td></tr><tr><td>Total Submission</td><td>Indicates the total number of reports received for your program.</td></tr><tr><td>Total Bounty Paid</td><td>Displays the total bounty or monetary rewards you have paid out from the platform so far.</td></tr><tr><td>Total Points Distributed</td><td>Displays the total points you have awarded to various users for their reports.</td></tr><tr><td>Submission Stats</td><td>Provides an overview of the total number of submissions based on their report status.</td></tr></tbody></table>


# Reports


# Managing Reports

Once your bug bounty program is active, you will begin receiving vulnerability reports. You can view the submitted vulnerabilities through the 'Submissions' menu.&#x20;

```
https://app.bugv.io/organization/submission
```

![](/files/-Mb_nYSY2V29HsWOj83b)

![](/files/-Mb_ncbf_zg6mGYCAvds)

Let’s take an in-depth look at the report:

![](/files/-Mb_qkcudtNTwowXebXv)

1. Title of the report/vulnerability
2. Company to which the vulnerability was reported
3. Last updated date of the vulnerability report
4. [Severity](/researchers/my-report/report-severity) level of the report
5. Current [status](/researchers/my-report/report-status) of the report
6. Reward value awarded for this report
7. Total [points](/researchers/my-report/points) assigned to this report
8. Total number of comments or discussions related to the report


# Report Format

When you click on any report, it will open in the following page format.

![](/files/-Mb_wt_2gfeKvnxcHmVM)

This section provides the details of the report, including the specifics of the reported vulnerability. Here’s a detailed overview of the page format:

* **Target:** The domain or scope where the vulnerability was identified.
* **Vulnerability:** The exact URL of the vulnerable application.
* **Vulnerability Type:** The classification of the vulnerability.
* **Submitted By:** The username of the individual who submitted the vulnerability report.
* **Assigned To:** Indicates whether this vulnerability has been assigned to another team member.
* **Description:** A comprehensive description of the vulnerability.
* **Trace Dump/HTTP Request:** Contains the HTTP request related to the vulnerability.
* **Attachments:** Any attachments added by the reporter.
* **Review and Summary:** Displays all conversations related to the report.&#x20;


# Validating Report

In this section, we will validate the incoming reports, determining if the reported vulnerabilities are legitimate or simply false positives.

Upon opening any vulnerability report, it will be presented in the following report format:

![](/files/-Mba1ozxcN3hlNYHkQZk)

At the bottom, you will find the '**Action**' section, where we will validate all incoming reports.&#x20;

![](/files/-Mba25m6Y_3NQByfa_cS)

Here are the details of the **Actions** available.

Here’s a video tutorial on triaging and adding rewards to a report.

{% embed url="<https://youtu.be/qFLx7TpyI3w>" %}

**UPDATE STATUS**

&#x20;This action allows you to update the current status of [report](/researchers/my-report/report-status) submissions.

![](/files/-Mba39Row0oKiXznRkgJ)

SELECT STATUS:&#x20;

* **DUPLICATE:** Indicates that the vulnerability has already been reported.
* **NOT APPLICABLE:** Used when the vulnerability or report is deemed invalid or not applicable.
* **TRIAGED:** Signifies that the vulnerability is valid and has been accepted.
* **WON'T FIX:** Indicates that the vulnerability poses an acceptable risk and will not be addressed.

1. Additional statuses become available only once the report has been marked as '**TRIAGED**.'

![](/files/-Mba6f3yNqdQzTJS6f5R)

**CHANGE STATUS**

* **UNRESOLVED:** Indicates that the vulnerability has been accepted and assigned to a developer for resolution. At this stage, you can also add a reward for the report.
* **RESOLVED:** Once the vulnerability has been fixed, the status can be updated to Resolved.

#### MANAGING DUPLICATE&#x20;

Duplicate submissions are common within the program, which can make them challenging to manage. However, you can easily handle duplicates by using the 'Search Vulnerability' option under Duplicate.<br>

To Add a report as a duplicate:

**CHANGE STATUS > DUPLICATE**&#x20;

![](/files/-MbaJkp0P8pkIjAP02-8)

![](/files/-MbaL3mHLnSr5_4rg5AS)

## **CHANGE SEVERITY**

Each vulnerability report will include a [severity level](/researchers/my-report/report-severity) based on the reporter's assessment, but it may need adjustment according to the customer's standards. This action allows you to modify the current severity of the report submission.

![](/files/-Mba4klNRrOgJpPuL2dl)

**SELECT SEVERITY:**&#x20;

* **CRITICAL:** Indicates a vulnerability with a severe impact on the customer's assets or business.
* **HIGH:** Indicates a vulnerability with a significant impact on the customer's assets or business.
* **MODERATE:** Indicates a vulnerability with a moderate impact on the customer's assets or business.
* **LOW:** Indicates a vulnerability with a minimal impact on the customer's assets or business.
* **INFORMATIONAL:** Represents a vulnerability posing an acceptable risk to the customer.

## ASSIGN TO

If you have another team member in your organization to validate the incoming reports, you can assign those reports to them.

![](/files/-MbaHyl22UyHc3zqGDyN)

## UPDATE VULNERABILITY TYPE

If the reporter has submitted the vulnerability with an incorrect vulnerability type, you or the customer can adjust the vulnerability type using this action.

![](/files/-MbaHRLC0W50fuxDIAhS)

## UPDATE BUG TITLE

If the report title contains errors or differs slightly from the actual vulnerability, you or the customer can update or adjust the title using this action.&#x20;

![](/files/-MbaHca40r1NCUUGtZKo)

## NEED MORE INFO

If the report description lacks sufficient information to validate the submission, you can add a 'Need More Info' flag to the report. This flag indicates that you are requesting the reporter to provide additional details, which will facilitate the validation process for the submission.

![](/files/-MbaIbTHE0e47C-mS16B)

## LOCK

If the reporter submits spam reports with unnecessary comments, you can lock the report to prevent the reporter from making further comments.&#x20;

![](/files/-MbaIreynuro7YFKgfv3)

## ADD REWARD

Adding a reward to the report is straightforward; however, the [report status](/researchers/my-report/report-status) must be 'UNRESOLVED' to proceed with the reward addition.

**NEW  > TRIAGED > UNRESOLVED > ADD REWARD**

![](/files/-MbaC0sZ98s-4kc3bki0)

Since rewards are presented in ranges, you can adjust the reward amount based on the[ report's severity. ](/researchers/my-report/report-severity)

Enter your desired reward amount in the input field and click '**Submit**.' After submitting, you will need to switch to the payment gateway to complete the transaction.

![](/files/-MbaDDsCj32_Ia7I21Q5)

Currently, we only support payments through **eSewa** and **Fonepay**.

{% hint style="info" %}
We plan to add more payment methods in the future.
{% endhint %}

After completing your payment, you will be redirected to the payment confirmation page.

![](/files/-MbaDmmwRT_K-zkNK-MO)

You have now successfully completed the payment.


# Video Tutorial

Here’s a comprehensive video tutorial that walks you through the process of triaging vulnerability reports and adding bounties to them. This tutorial is ideal for those looking to refine their approach to managing vulnerability reports effectively and encourages responsible rewarding based on report quality and impact.

{% embed url="<https://youtu.be/qFLx7TpyI3w>" %}

Alternatively, you can refer to the manual steps for validating a [report.](/customers/reports/validating-report)


# Program

In this context, "program" refers to the customer applications or products, like PayPal, eSewa, Merojob, or Pasls, for which they intend to or have already launched a bug bounty program.

```
https://app.bugv.io/organization/program
```

![Program List of Organization](/files/-MbM-sS1aVIvaAc6zZyp)

Here are the details of the program dashboard:

* **Product Name:** This indicates the name of the product (program).
* **Type:** This denotes the type of program that has been assigned.
* **Date & Time:** This shows the date when the program was created.
* **Status:** This indicates the current status of the program.
* **Edit (Little Pencil):** This icon allows you to edit the program.


# Types of Program

These are the types of programs a customer can create on our platform.

<table data-header-hidden><thead><tr><th width="167">TYPE</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td>TYPE</td><td>DESCRIPTION</td></tr><tr><td>Public</td><td>This program is visible to everyone, including any logged-in users.</td></tr><tr><td>Private</td><td>This program is invite-only and is visible only to selected researchers.</td></tr><tr><td>Managed</td><td>The Bugv team will manage all incoming reports for the program.</td></tr><tr><td>UnManaged</td><td>The program owner is responsible for managing and validating all incoming reports themselves.</td></tr><tr><td>Reward &#x26; Point</td><td>This indicates that the program will offer monetary rewards and points for the reports. </td></tr><tr><td>Point Only</td><td>This indicates that the program will provide only points for the reports, with no monetary rewards offered.</td></tr></tbody></table>


# Program Status

When a program is created on our platform, it is assigned a specific status. Below are the available statuses:&#x20;

![](/files/-MbM62R096FrOIZNEvKj)

Here are the description and available status.&#x20;

<table data-header-hidden><thead><tr><th width="161">STATUS</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td>STATUS</td><td>DESCRIPTION</td></tr><tr><td>PENDING</td><td>The program is in a pending state as it has not yet been validated by the admin.</td></tr><tr><td>APPROVED</td><td>The program has been approved and is currently active on our platform.</td></tr><tr><td>REJECTED</td><td>The program has been rejected by the admin for not meeting the required standards.</td></tr><tr><td>PAUSED</td><td>The program is currently paused and will not be accepting any new submissions.</td></tr><tr><td>CLOSED</td><td>The program has been closed and is no longer active on the platform.</td></tr></tbody></table>


# Creating a Program

To launch your bug bounty program for your product or application, you need to create a program.

{% embed url="<https://youtu.be/yAW_srhmevg>" %}

Creating a program is simple. Just follow these steps:

1. Log in to your organization account, go to the "[Program](https://app.bugv.io/sign-in?returnUrl=%2Forganization%2Fprogram)" menu, and click the '+' icon in the top right corner of the page.

![](/files/-MbM7DBPRD2JWJKr4vRl)

2. Select your desired program type (Managed or Unmanaged).
3. If you choose "Managed," it will prompt you to select either a public or private program. Since we currently do not offer private programs, select "Public."

![](/files/-MbM7jwGYGRVyQloHQDX)

4. After selecting "Public Program," you will be prompted to choose between running a "Reward & Points" program or a "Points Only" program.

![](/files/-MbM86VJYzaZWVaqZE6b)

5. Once you select '[Reward & Point](/customers/program/type),' you can add the program details.

* **Program Name:** The name of your product/app, which will be publicly available to all users.
* **Tagline:** The product tagline, if you have one.
* **Description:** A description of your product that explains what it is all about.
* **Additional Description:** Any extra information you want to include.
* **Upload Logo:** Upload your product logo.

*For example, we will be creating a Program of '*[*eSewa*](https://esewa.com.np/)*' , here's how it is done.*

![](/files/-MbMBQmgBchQt1luq0R9)

6. After entering all the details, click on 'Continue' to access the target form.&#x20;

Here, you’ll need to specify the scope or testing URLs where you intend to conduct security testing, defining the areas for researchers to focus on during the assessment.

![](/files/-MbMCa5OuK1zqBc002N0)

You can add more targets by clicking the '+' icon in the top right corner. Currently, we support the following target types:

* Website
* API
* Android
* iOS

For Android and iOS, you can include the Play Store or App Store link.

7. After adding the targets, click on 'Continue' to proceed to the next step, where you will add the reward.

![](/files/-MbMDJGkuXTVMAxODFeI)

Here, you can define your own reward range based on the severity of the vulnerabilities.<br>

**Note:** The rewards must be listed in descending order.

8. After adding the rewards, click on 'Continue' to review your program. You can edit or make changes if needed.
9. Once you’re satisfied, click on 'Submit.' Your program will require approval before going LIVE, which typically takes 1-2 business days.
10. Your recently created program will appear on the [program](/customers/program) page with a [status ](/customers/program/status)of 'Pending.'


