Frequently asked questions

Top Scope FAQ

Clear answers about organizing bug bounty scope, recording findings, controlling team changes, protecting personal research, and using The Scope’s exports and API.

What is Top Scope?

Top Scope is the public name for The Scope bug bounty operations platform. It gives security researchers and teams one online workspace for program records, in-scope and out-of-scope assets, vulnerability reports, personal notes, private vault items, approvals, exports, and read-only API access.

How is Top Scope different from a scope spreadsheet?

A spreadsheet stores rows, but Top Scope connects each target to its program, platform, eligibility, maximum severity, report workflow, approval history, and authorized user actions. Live totals, filters, deduplication, downloads, and APIs reduce the manual work required to keep a large collection usable.

Can I use Top Scope as a bug bounty scope GitHub tracker?

Yes. Add GitHub organizations, repositories, and source-code targets to the relevant program. The platform preserves the program and platform context so a repository is not separated from its policy, scope state, or testing notes.

How does bug bounty scope Android tracking work?

Android package names and mobile application listings can be stored as mobile assets. Each entry can be marked in scope or out of scope, assigned a maximum severity, and linked to the program that defines its testing rules.

Which scope asset types are supported?

Top Scope supports wildcard domains, domains, subdomains, URLs, IPv4 addresses, IPv6 addresses, CIDR ranges, mobile applications, source-code targets, and custom assets. Automatic type detection is available during bulk entry.

Can I separate in-scope and out-of-scope targets?

Yes. Every asset has an explicit scope state. Dashboard totals and program filters distinguish eligible targets from exclusions, making it easier to build focused testing lists without accidentally dropping the program context.

Does Top Scope include a bug bounty finding template?

The report workspace includes fields for the affected target, severity, weakness or CWE, executive summary, reproduction steps, impact, recommendation, external report link, reward, and workflow status. Each report stays connected to its program and affected asset.

How do analyst and viewer changes work?

Analysts and viewers can propose shared program, scope, and report changes, but those changes enter the approval queue instead of applying immediately. An administrator can inspect the affected program and target before approving or rejecting the request.

Can every user store private notes and secrets?

Active owners, administrators, analysts, and viewers can create personal notes and encrypted vault entries. Database queries are constrained to the signed-in user ID. Restricted users become read-only until an administrator restores access.

Can scope data be downloaded or queried through an API?

Yes. Authorized users can filter scope and download unique TXT targets, context-rich CSV records, or complete JSON data. Personal read-only API tokens provide program, asset, and report endpoints for approved automation.

How does Top Scope help prevent abuse?

Administrators can assign roles, override permissions, restrict an account to read-only access, disable sign-in, revoke tokens, and review all pending shared changes. Personal vault and note records remain isolated between users.

Is Top Scope an online ruler or camera measuring tool?

No. Searches such as online ruler camera, mm online ruler, accurate online ruler, and 12 inch online ruler describe tools for measuring physical dimensions. Top Scope measures security-program boundaries and organizes bug bounty assets; it does not measure objects or screen lengths.

Need the workflow?

Follow scope from program to finding.

The practical guide explains how to normalize targets, separate exclusions, export focused lists, and preserve report context.

Read the Guide