- September 29 — Improved: Report administration shows clearer controls, and analytics gained more detailed cost-control views.
- September 28 — Added: Report management shows linked duplicate reports alongside the pre-validation assessment.
- September 28 — Improved: The bonus workflow gained clearer handling when administrators review rewards.
- September 27 — Improved: Hall of Fame views show more researcher recognition details.
- September 25 — Added: Administrators can share bounty details by email and resend an administrator invitation.
- September 25 — Fixed: Stale-report reminders exclude known issues.
- September 22 — Fixed: Reward handling and analytics account for report-level known issues.
- September 21 — Added: The external admin API v1 supports programmatic organization workflows. Endpoint definitions are in the API reference tab.
- September 18 — Added: Program teams can submit known issues, and the platform gained an in-app notification system.
- September 18 — Added: The Linear integration synchronizes issues in both directions.
- September 18 — Improved: Administrators without super admin access can switch to all-report statistics where permitted.
- September 14 — Added: The organization bounty ledger brings reward activity into one view.
- September 12 — Added: A bounty program switch controls whether a program offers monetary rewards.
- September 9 — Added: Program teams can set researcher participation requirements.
- September 9 — Added: Individual users can suppress Slack notifications.
- September 8 — Added: Manage bounty tables in program settings, including table creation.
- September 8 — Added: An analytics role and expanded organization analytics provide more targeted access to reporting data.
- September 8 — Added: Embedded report forms can resize their hosting iframe.
- September 7 — Added: Manage scope directly and notify researchers when scope changes.
- September 7 — Improved: The GitHub integration can link multiple issues or security advisories to a report.
- September 6 — Added: Configure program test credentials and restart a paused program from its management view.
- September 3 — Added: Public researcher profiles and a public leaderboard make researcher activity discoverable.
- September 1 — Added: Filter advanced report views by target.
- August 31 — Added: Write a custom resolution message when closing a report.
- August 31 — Added: A Dropzone authorization API supports VDP onboarding and its extra-points flow.
- August 27 — Added: Create GitHub Security Advisories for accepted reports through the GitHub integration.
- August 27 — Improved: The Jira integration gained advanced field mappings.
- August 26 — Added: Invite super administrators through the team management flow.
- August 21 — Added: Copy a complete report when you need to share its details.
- August 21 — Improved: Report filters cover all severity and status values, and the scope table shows a tier column.
- August 21 — Added: Jira advanced configuration guidance and a program start action.
- August 15 — Added: Program owners can pause or stop a program.
- August 15 — Added: A public API exposes published Hacktivity entries.
- August 10 — Changed: Account authentication and user management began moving to Clerk.
- August 1 — Added: Jira gained two-way issue synchronization.
- July 26 — Added: Customize the branding of an embedded VDP form.
- July 26 — Added: Add custom fields to report submissions, including up to three program-specific questions.
- July 22 — Improved: The researcher identity verification flow gained a new version.
- July 20 — Improved: The leaderboard gained a redesigned experience.
- July 19 — Added: Researchers gained a My Profile view.
- July 18 — Improved: Report pre-validation provides more context before triage.
- July 16 — Fixed: Bounty totals include bonuses, and embedded-form reporters can view the associated program details.
- July 12 — Added: Publish eligible reports to Hacktivity and manage CVE requests.
- July 1 — Added: Move a report to a different program or target when it was submitted to the wrong place.
- June 30 — Added: Administrators can view reports across an organization.
- June 29 — Added: Reward controls restrict duplicate bounties.
- June 10 — Added: A new reports view helps teams work through incoming findings.
- June 10 — Added: Program teams can change VDP text and send email after a report’s program changes.
- June 6 — Fixed: Group authorization checks were tightened, and notifications no longer email users about their own actions.
- May 7 — Added: Upload credentials for program testing.
- April 28 — Added: Manage multiple layers of test credentials for a program.
- April 24 — Improved: Configure the GitHub integration across an organization, and review team summaries.
- April 23 — Added: Stale-report reminders and email preview help administrators manage follow-up.
- April 19 — Added: GitHub Security Advisory integration.
- April 17 — Added: Comments on linked GitHub issues and a GitHub-supported report pre-validation workflow.
- February 28 — Added: Researcher invitations show location and two-factor authentication information.
- January 9 — Added: Structured CVE and CWE data expanded report and team summary records.
- December 17 — Improved: Analytics calculate average bounty by severity.
- December 8 — Added: Expanded organization analytics and administrator join emails.
- November 28 — Improved: Report management shows CVSS information and the assigned team member.
- November 25 — Added: Assign reports to team members from the management view.
- November 2 — Improved: The main access-control rules were revised for organization workflows.
- September 26 — Added: Select filters and columns when exporting report data to CSV.
- September 22 — Added: Publish program announcements to researchers.
- September 16 — Added: Bonus rewards and program pause controls.
- September 5 — Added: Store program test credentials and assign VDP reporters.
- August 4 — Added: Business units help organize administrator access and program work.
- July 24 — Added: Set a bounty limit for a program.
- July 24 — Fixed: Performance improvements addressed timeouts in program details, management, analytics, and the catalog.
- July 8 — Added: Program report tables retain their selected view state.
- June 9 — Added: Administrator invitations, a new scope table, and updated settings views.
- June 9 — Improved: Report actions include Accepted risk, and getting-started guidance checks the administrator role.
- March 30 — Added: An email alias integration for program communications.
- March 17 — Added: Mark a finding as Accepted risk when your organization acknowledges it without immediate remediation.
- December 12 — Added: Back-office notifications for closed reports that receive a bounty.
- November 13 — Added: Invite administrators through a dedicated team workflow.
- November 6 — Added: Researcher notification sending and more analytics views.
- September 7 — Added: Review pending and declined administrator invitations.
- August 10 — Added: A public program catalog and ComplyCube identity verification.
- April 7 — Added: Program catalog discovery and expired-invitation analytics.
- April 7 — Fixed: Disabled targets no longer appear in the catalog.
- October 23 — Improved: CSV exports reflect the exporting administrator’s permissions.
- October 2 — Added: Invitation expiry is visible in administration.
- September 18 — Added: A dedicated pending reports view for incoming findings.
- September 16 — Fixed: Webhook access checks respect permissions.
- July 30 — Added: Private programs gained description content in discovery.
- July 22 — Added: A CVSS calculator in reporting and private programs in the public catalog.
- October 23 — Added: Two-factor authentication controls in account settings.
- October 22 — Added: Markdown preview for program management fields and easier navigation between analytics and program management.
- October 9 — Added: A dynamic notification bar for platform messages.
- June 9 — Added: Slack integration for report activity.
- June 8 — Added: Microsoft Teams integration for report activity.
- May 15 — Added: Secured certificates for programs.
- May 7 — Improved: Administrator triage gained a ban action and updated out-of-scope and informative severity handling.
- October 15 — Changed: A major platform redesign refreshed the application.
- October 12 — Added: File validation for uploaded evidence.
- July 29 — Improved: Reports gained structured attachment metadata.
- July 20 — Improved: The embedded VDP report form and its related services.
- June 23 — Improved: Markdown rendering gained sanitization for submitted content.
- June 16 — Added: Markdown preview in the reporting experience.
- June 1 — Added: Internal report comments.
- May 26 — Added: Dedicated storage and queue processing for report evidence.
- May 19 — Added: Verification updates, report status badges, and larger evidence uploads.