Scope architecture
Keep each program, platform, policy URL, and eligible target connected.
Bug bounty operations, precisely scoped
The Scope turns scattered program pages, domains, wildcards, mobile apps, reports, and research notes into one clean operating system for security work. Know what is allowed, record what you tested, and keep every finding tied to the right target.
Built for researchers, analysts, viewers, and administrators.
Live scope overview
thescope.topAssets
66,861
In scope
57,962
Wildcards
5,933
Programs
1,743
*.example.comwildcardapi.example.comsubdomaincom.example.androidandroidOne source of truth
Top Scope keeps the target, program, workflow, and researcher context together so the next action is obvious.
Keep each program, platform, policy URL, and eligible target connected.
Draft, submit, and track vulnerability reports with the affected asset attached.
Route shared edits through approval while administrators retain abuse controls.
Filter and download TXT, CSV, or JSON data, or query a read-only API.
A bug bounty scope is the contract between a security program and a researcher. It identifies the systems that may be tested, the assets that must be avoided, the eligible vulnerability classes, and the operational rules around disclosure. When those details live across platform pages, bookmarks, screenshots, and local files, it is easy to test an outdated target or lose the context behind a report. Top Scope gives that information a consistent home. The Scope stores each program beside its platform, policy URL, status, reward information, tags, and organized asset inventory.
A useful bug bounty scope example might include *.example.com as a wildcard, api.example.com as a subdomain, a specific Android package, several public IP ranges, and an explicit out-of-scope support portal. Top Scope records every value with an asset type, scope state, severity ceiling, and bounty eligibility. The dashboard then calculates live totals for assets, in-scope targets, out-of-scope targets, wildcards, subdomains, APIs, mobile apps, and other useful categories. Researchers can see the boundary before testing instead of reconstructing it from memory.
Modern programs rarely contain only domains. A bug bounty scope GitHub entry may point to an organization, repository, or source-code target, while a bug bounty scope Android entry may identify an application package or store listing. The Scope also recognizes wildcard domains, subdomains, full URLs, IPv4 and IPv6 addresses, CIDR ranges, mobile targets, source assets, and custom values. Bulk entry makes large collections manageable, while platform and scope filters help narrow the program list. When a focused target list is needed, researchers can download unique TXT values, a context-rich CSV, or complete JSON records. Read-only API endpoints provide the same organized data for authorized automation.
Finding quality improves when evidence remains attached to the program and affected target. Top Scope includes a structured report workflow for the title, target, severity, status, executive summary, reproduction steps, impact, remediation advice, weakness or CWE, CVSS score, external report ID, external URL, and reward details. A researcher can keep a report as a draft, mark it submitted, and follow its progress without losing the scope reference. Personal notes capture endpoints, hypotheses, and follow-up work. A private per-user vault keeps temporary test accounts, API keys, and related credentials separated from other team members.
The Scope separates personal research data from shared program data. Administrators can add users, assign roles and permissions, restrict abusive accounts, and review requested program, asset, or report changes. Analysts and viewers can propose updates without silently rewriting the shared workspace. Each approval request shows the affected program and target, so an administrator can understand exactly what will change. Completed history can be removed selectively by its owner, while administrators can clean finished team history. Pending items remain protected until they are cancelled or reviewed. This approach keeps collaboration useful without giving every account unrestricted editing power.
A quick clarification
If you found this page after searching for “online ruler bug bounty scope finding template,” note that two different ideas have been combined. An online ruler camera, mm online ruler, accurate online ruler, or 12 inch online ruler measures physical or on-screen distance. Top Scope is an online security-workflow tool: it organizes the authorized boundaries of bug bounty programs and the findings produced while testing them.
Frequently asked questions
Top Scope is the public name for The Scope bug bounty operations platform. It gives security researchers and teams one online workspace for program records, in-scope and out-of-scope assets, vulnerability reports, personal notes, private vault items, approvals, exports, and read-only API access.
A spreadsheet stores rows, but Top Scope connects each target to its program, platform, eligibility, maximum severity, report workflow, approval history, and authorized user actions. Live totals, filters, deduplication, downloads, and APIs reduce the manual work required to keep a large collection usable.
Yes. Add GitHub organizations, repositories, and source-code targets to the relevant program. The platform preserves the program and platform context so a repository is not separated from its policy, scope state, or testing notes.
Android package names and mobile application listings can be stored as mobile assets. Each entry can be marked in scope or out of scope, assigned a maximum severity, and linked to the program that defines its testing rules.
Security work starts with the boundary
Use Top Scope to organize programs, validate the assets you can test, and keep findings connected to the rules that matter.
Sign in to The Scope