MyBounty is an offline-first Android application designed for security researchers and bug bounty program managers to track, manage, and calculate bounty evaluations. Key Highlights Offline-First & Private: Built with a local SQLite/Room database so all vulnerability notes, CVSS scores, client details, and payout evaluations stay strictly on your device. Full Data Control: Easily purge or manage evaluation logs directly within the app or clear data via Android settings at any time.
What inspired you to build this?
I was inspired by a recurring concern in the bug bounty and security research community: researchers invest significant time, technical expertise, and effort into finding vulnerabilities, but the bounty they receive does not always feel proportional to the value of their work.
I noticed that bounty ranges have been reduced in many programs and that similar vulnerabilities can sometimes receive inconsistent rewards. This made me think about how researchers could have a more transparent way to understand and evaluate what a fair bounty might look like.
That idea led me to create MyBounty. I wanted to build a tool that supports fairness and transparency between security researchers and bug bounty program managers, while helping ensure that the effort involved in security research is properly recognized.
What problem were you trying to solve?
The primary problem I wanted to solve was the lack of a simple and accessible way to calculate a fair bounty for a security vulnerability.
Researchers need a way to understand whether an offered reward is reasonable, while program managers need a practical tool to help them determine an appropriate bounty based on factors such as vulnerability severity and impact.
MyBounty is designed to provide a structured approach to bounty calculation, helping reduce inconsistency and making reward discussions more transparent.
I also saw an opportunity to make this functionality available on mobile. Instead of relying only on web-based tools or manual calculations, I wanted researchers and program managers to have a dedicated mobile application they could use whenever they needed it.
What inspired you to build this?
The biggest motivation was my belief that security researchers deserve to have their hard work recognized and rewarded fairly.
A vulnerability report can represent hours or days of testing, analysis, creativity, and technical expertise. I wanted to create something that could help both researchers and program managers approach bounty decisions in a more consistent and transparent way.
MyBounty started from that idea: build a focused, easy-to-use mobile tool that can help bring more clarity to bounty calculations and encourage fairer conversations between researchers and programs.
How did your approach or process evolve while working on this launch?
Initially, my idea was to build a simple bounty calculator. As I worked on the concept, I wanted the calculation to be based on something objective rather than being just a subjective recommendation.
The approach evolved around using the bounty range provided by the program and mapping it against the CVSS 3.1 severity calculation. The idea is to take the program's defined minimum and maximum bounty range and provide a more structured way to determine an appropriate reward based on the vulnerability's CVSS 3.1 score.
This approach allows MyBounty to connect the program's own bounty policy with an established vulnerability severity framework. It gives researchers a clearer understanding of how a bounty can be calculated and gives program managers a practical tool to arrive at a more consistent reward.
I also wanted to make this process easily accessible on mobile, which led to developing MyBounty as a dedicated mobile application rather than keeping the concept limited to manual calculations or web-based tools.
The overall process evolved from simply building a calculator into creating a tool focused on consistency, transparency, and fair recognition of security research.