> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hckrt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Product changelog

> Notable Hackrate features, improvements, and fixes from the bugbounty-app history, 2021 to 2026.

This changelog records notable additions, improvements, and fixes to the Hackrate platform. It leaves out routine maintenance, copy edits, and small visual adjustments.

<Update label="September 2026">
  * **September 29 — Improved:** Report administration shows clearer controls, and [analytics](/companies/reports/analytics) gained more detailed cost-control views.
  * **September 28 — Added:** Report management shows linked duplicate reports alongside the pre-validation assessment.
  * **September 28 — Improved:** The bonus workflow gained clearer handling when administrators review rewards.
  * **September 27 — Improved:** Hall of Fame views show more researcher recognition details.
  * **September 25 — Added:** Administrators can share bounty details by email and resend an administrator invitation.
  * **September 25 — Fixed:** Stale-report reminders exclude [known issues](/companies/programs/known-issues).
  * **September 22 — Fixed:** Reward handling and analytics account for report-level known issues.
  * **September 21 — Added:** The [external admin API v1](/companies/integrations/external-api) supports programmatic organization workflows. Endpoint definitions are in the **API reference** tab.
  * **September 18 — Added:** Program teams can submit [known issues](/companies/programs/known-issues), and the platform gained an in-app notification system.
  * **September 18 — Added:** The [Linear integration](/companies/integrations/linear) synchronizes issues in both directions.
  * **September 18 — Improved:** Administrators without super admin access can switch to all-report statistics where permitted.
  * **September 14 — Added:** The [organization bounty ledger](/companies/reports/bounty-ledger) brings reward activity into one view.
  * **September 12 — Added:** A bounty program switch controls whether a program offers monetary rewards.
  * **September 9 — Added:** Program teams can set [researcher participation requirements](/companies/programs/researcher-requirements).
  * **September 9 — Added:** Individual users can suppress [Slack](/companies/integrations/slack) notifications.
  * **September 8 — Added:** Manage [bounty tables](/companies/reports/bounty-rewards) in program settings, including table creation.
  * **September 8 — Added:** An analytics role and expanded organization analytics provide more targeted access to reporting data.
  * **September 8 — Added:** Embedded report forms can resize their hosting iframe.
  * **September 7 — Added:** Manage [scope](/companies/programs/targets-scope) directly and notify researchers when scope changes.
  * **September 7 — Improved:** The [GitHub integration](/companies/integrations/github) can link multiple issues or security advisories to a report.
  * **September 6 — Added:** Configure program test credentials and restart a paused program from its management view.
  * **September 3 — Added:** Public researcher profiles and a public [leaderboard](/researchers/rewards/leaderboard) make researcher activity discoverable.
  * **September 1 — Added:** Filter advanced report views by target.
</Update>

<Update label="August 2026">
  * **August 31 — Added:** Write a custom resolution message when closing a report.
  * **August 31 — Added:** A Dropzone authorization API supports VDP onboarding and its extra-points flow.
  * **August 27 — Added:** Create GitHub Security Advisories for accepted reports through the [GitHub integration](/companies/integrations/github).
  * **August 27 — Improved:** The [Jira integration](/companies/integrations/jira) gained advanced field mappings.
  * **August 26 — Added:** Invite super administrators through the team management flow.
  * **August 21 — Added:** Copy a complete report when you need to share its details.
  * **August 21 — Improved:** Report filters cover all severity and status values, and the scope table shows a tier column.
  * **August 21 — Added:** Jira advanced configuration guidance and a program start action.
  * **August 15 — Added:** Program owners can pause or stop a program.
  * **August 15 — Added:** A public API exposes published [Hacktivity](/researchers/rewards/hacktivity) entries.
  * **August 10 — Changed:** Account authentication and user management began moving to Clerk.
  * **August 1 — Added:** [Jira](/companies/integrations/jira) gained two-way issue synchronization.
</Update>

<Update label="July 2026">
  * **July 26 — Added:** Customize the branding of an embedded [VDP form](/companies/programs/vulnerability-disclosure).
  * **July 26 — Added:** Add custom fields to report submissions, including up to three program-specific questions.
  * **July 22 — Improved:** The [researcher identity verification](/researchers/account/verification) flow gained a new version.
  * **July 20 — Improved:** The [leaderboard](/researchers/rewards/leaderboard) gained a redesigned experience.
  * **July 19 — Added:** Researchers gained a **My Profile** view.
  * **July 18 — Improved:** Report pre-validation provides more context before triage.
  * **July 16 — Fixed:** Bounty totals include bonuses, and embedded-form reporters can view the associated program details.
  * **July 12 — Added:** Publish eligible reports to [Hacktivity](/researchers/rewards/hacktivity) and manage CVE requests.
  * **July 1 — Added:** Move a report to a different program or target when it was submitted to the wrong place.
</Update>

<Update label="June 2026">
  * **June 30 — Added:** Administrators can view reports across an organization.
  * **June 29 — Added:** Reward controls restrict duplicate bounties.
  * **June 10 — Added:** A new [reports view](/companies/reports/overview) helps teams work through incoming findings.
  * **June 10 — Added:** Program teams can change VDP text and send email after a report's program changes.
  * **June 6 — Fixed:** Group authorization checks were tightened, and notifications no longer email users about their own actions.
</Update>

<Update label="May 2026">
  * **May 7 — Added:** Upload credentials for program testing.
</Update>

<Update label="April 2026">
  * **April 28 — Added:** Manage multiple layers of test credentials for a program.
  * **April 24 — Improved:** Configure the GitHub integration across an organization, and review team summaries.
  * **April 23 — Added:** Stale-report reminders and email preview help administrators manage follow-up.
  * **April 19 — Added:** GitHub Security Advisory integration.
  * **April 17 — Added:** Comments on linked GitHub issues and a GitHub-supported report pre-validation workflow.
</Update>

<Update label="February 2026">
  * **February 28 — Added:** Researcher invitations show location and two-factor authentication information.
</Update>

<Update label="January 2026">
  * **January 9 — Added:** Structured CVE and CWE data expanded report and team summary records.
</Update>

<Update label="December 2025">
  * **December 17 — Improved:** Analytics calculate average bounty by severity.
  * **December 8 — Added:** Expanded [organization analytics](/companies/reports/analytics) and administrator join emails.
</Update>

<Update label="November 2025">
  * **November 28 — Improved:** Report management shows CVSS information and the assigned team member.
  * **November 25 — Added:** Assign reports to team members from the management view.
  * **November 2 — Improved:** The main access-control rules were revised for organization workflows.
</Update>

<Update label="September 2025">
  * **September 26 — Added:** Select filters and columns when exporting report data to CSV.
  * **September 22 — Added:** Publish program announcements to researchers.
  * **September 16 — Added:** Bonus rewards and program pause controls.
  * **September 5 — Added:** Store program test credentials and assign VDP reporters.
</Update>

<Update label="August 2025">
  * **August 4 — Added:** [Business units](/companies/team/business-units) help organize administrator access and program work.
</Update>

<Update label="July 2025">
  * **July 24 — Added:** Set a bounty limit for a program.
  * **July 24 — Fixed:** Performance improvements addressed timeouts in program details, management, analytics, and the catalog.
  * **July 8 — Added:** Program report tables retain their selected view state.
</Update>

<Update label="June 2025">
  * **June 9 — Added:** Administrator invitations, a new scope table, and updated settings views.
  * **June 9 — Improved:** Report actions include **Accepted risk**, and getting-started guidance checks the administrator role.
</Update>

<Update label="March 2025">
  * **March 30 — Added:** An email alias integration for program communications.
  * **March 17 — Added:** Mark a finding as **Accepted risk** when your organization acknowledges it without immediate remediation.
</Update>

<Update label="December 2024">
  * **December 12 — Added:** Back-office notifications for closed reports that receive a bounty.
</Update>

<Update label="November 2024">
  * **November 13 — Added:** Invite administrators through a dedicated team workflow.
  * **November 6 — Added:** Researcher notification sending and more [analytics](/companies/reports/analytics) views.
</Update>

<Update label="September 2024">
  * **September 7 — Added:** Review pending and declined administrator invitations.
</Update>

<Update label="August 2024">
  * **August 10 — Added:** A public [program catalog](/researchers/programs/catalog) and ComplyCube [identity verification](/researchers/account/verification).
</Update>

<Update label="April 2024">
  * **April 7 — Added:** Program catalog discovery and expired-invitation analytics.
  * **April 7 — Fixed:** Disabled targets no longer appear in the catalog.
</Update>

<Update label="October 2023">
  * **October 23 — Improved:** CSV exports reflect the exporting administrator's permissions.
  * **October 2 — Added:** Invitation expiry is visible in administration.
</Update>

<Update label="September 2023">
  * **September 18 — Added:** A dedicated pending reports view for incoming findings.
  * **September 16 — Fixed:** Webhook access checks respect permissions.
</Update>

<Update label="July 2023">
  * **July 30 — Added:** Private programs gained description content in discovery.
  * **July 22 — Added:** A [CVSS calculator](/researchers/reports/severity-cvss) in reporting and [private programs](/researchers/programs/private-programs) in the public catalog.
</Update>

<Update label="October 2022">
  * **October 23 — Added:** Two-factor authentication controls in account settings.
  * **October 22 — Added:** Markdown preview for program management fields and easier navigation between analytics and program management.
  * **October 9 — Added:** A dynamic notification bar for platform messages.
</Update>

<Update label="June 2022">
  * **June 9 — Added:** [Slack](/companies/integrations/slack) integration for report activity.
  * **June 8 — Added:** Microsoft Teams integration for report activity.
</Update>

<Update label="May 2022">
  * **May 15 — Added:** Secured certificates for programs.
  * **May 7 — Improved:** Administrator triage gained a ban action and updated out-of-scope and informative severity handling.
</Update>

<Update label="October 2021">
  * **October 15 — Changed:** A major platform redesign refreshed the application.
  * **October 12 — Added:** File validation for uploaded evidence.
</Update>

<Update label="July 2021">
  * **July 29 — Improved:** Reports gained structured attachment metadata.
  * **July 20 — Improved:** The embedded VDP report form and its related services.
</Update>

<Update label="June 2021">
  * **June 23 — Improved:** Markdown rendering gained sanitization for submitted content.
  * **June 16 — Added:** Markdown preview in the reporting experience.
  * **June 1 — Added:** Internal report comments.
</Update>

<Update label="May 2021">
  * **May 26 — Added:** Dedicated storage and queue processing for report evidence.
  * **May 19 — Added:** Verification updates, report status badges, and larger evidence uploads.
</Update>
