A VDP gives researchers, users, and partners a safe, legitimate way to tell you about a security issue instead of staying quiet or disclosing it publicly. Without one, good-faith reporters have no clear — or legally safe — way to reach you.
A VDP has no guaranteed reward, no defined reward range, and doesn't require researcher KYC — it's essentially bug bounty without the payment layer. Bug bounty is built for active, incentivized testing; a VDP is built for broad, low-friction reporting from anyone who happens to find something.
Optional. A VDP has no reward by default, but any reward is fully discretionary — you can thank researchers however you like, and even offer a payment case by case, though it's never required.
No, it's optional. Since there's no payout, there's no financial or compliance reason to require it, though you can turn it on if you want more visibility into who's reporting.
Yes. A VDP and a bug bounty program run on the same platform with the same triage team, so moving from one to the other — or running both — doesn't mean starting over.
Increasingly, yes. Frameworks like the EU's NIS2 and Cyber Resilience Act now mandate coordinated vulnerability disclosure, and CISA BOD 20-01 requires it for US federal agencies. A documented VDP is a straightforward step toward meeting several of these at once.
Right now, VDPs are hosted on the HackenProof platform with a branded program page. An embeddable widget for your own site, submitting reports via API, is coming soon.