Product capabilities

Bug bounty scope tools that stay connected.

Top Scope combines program intake, asset architecture, reporting, private research, controlled collaboration, and export-ready data. Each feature is designed around one idea: a security target is useful only when its authorization and program context remain attached.

Program Intelligence

Store the platform, policy URL, status, visibility, rewards, tags, and working context for every bug bounty program.

Scope Architecture

Classify wildcard, domain, subdomain, URL, IP, CIDR, mobile, source-code, and custom assets as in scope or out of scope.

Fast Filtering

Search large collections and narrow programs or targets by platform, scope state, asset type, and related program.

Useful Exports

Download clean TXT target lists, context-rich CSV records, or complete JSON data using the filters currently selected.

Finding Workflow

Connect each vulnerability report to its program and affected target, then track severity, status, evidence, and reward details.

Personal Notes

Let every active user keep private hypotheses, endpoints, test ideas, and program-specific research notes.

Encrypted Vault

Give every active user isolated storage for test accounts, API keys, passwords, tokens, and other temporary secrets.

Approval Control

Route analyst and viewer changes through administrator review while retaining restriction, disable, and permission controls.

Read-only API

Issue personal tokens for authorized program, asset, and report queries without allowing token-based mutations.

Personal by design

Notes and secrets belong to the signed-in user.

Owners, administrators, analysts, and viewers can maintain their own notes and vault entries. Those records are filtered by user ID, and vault values are encrypted at rest with a user-derived key. Restricting an account immediately removes mutation access without exposing one user’s records to another.

Shared with control

Program changes remain reviewable.

Non-admin users can propose new programs, scope assets, report updates, and deletions. Top Scope records the affected program and exact target, then waits for an administrator to approve or reject the request. Finished request history can be cleaned selectively without deleting pending work.

See the complete scope workflow.

Learn how program rules become normalized assets, focused exports, and connected findings.