Program Intelligence
Store the platform, policy URL, status, visibility, rewards, tags, and working context for every bug bounty program.
Product capabilities
Top Scope combines program intake, asset architecture, reporting, private research, controlled collaboration, and export-ready data. Each feature is designed around one idea: a security target is useful only when its authorization and program context remain attached.
Store the platform, policy URL, status, visibility, rewards, tags, and working context for every bug bounty program.
Classify wildcard, domain, subdomain, URL, IP, CIDR, mobile, source-code, and custom assets as in scope or out of scope.
Search large collections and narrow programs or targets by platform, scope state, asset type, and related program.
Download clean TXT target lists, context-rich CSV records, or complete JSON data using the filters currently selected.
Connect each vulnerability report to its program and affected target, then track severity, status, evidence, and reward details.
Let every active user keep private hypotheses, endpoints, test ideas, and program-specific research notes.
Give every active user isolated storage for test accounts, API keys, passwords, tokens, and other temporary secrets.
Route analyst and viewer changes through administrator review while retaining restriction, disable, and permission controls.
Issue personal tokens for authorized program, asset, and report queries without allowing token-based mutations.
Personal by design
Owners, administrators, analysts, and viewers can maintain their own notes and vault entries. Those records are filtered by user ID, and vault values are encrypted at rest with a user-derived key. Restricting an account immediately removes mutation access without exposing one user’s records to another.
Shared with control
Non-admin users can propose new programs, scope assets, report updates, and deletions. Top Scope records the affected program and exact target, then waits for an administrator to approve or reject the request. Finished request history can be cleaned selectively without deleting pending work.
Learn how program rules become normalized assets, focused exports, and connected findings.