Bug Bounty / Vulnerability Disclosure Stack
Bug bounty/disclosure program pages with WebPage + Offer, FAQs, and breadcrumb navigation.
When to use this stack
- Bug bounty program landing pages
- Vulnerability disclosure policy pages with reward terms
- Pages where FAQs clarify scope and reporting timelines
What is included
Defines the disclosure page and its summary.
Expresses the bounty or disclosure offer terms.
Answers scope, timeline, and safe harbor questions.
Provides navigation context for the bounty page.
Properties across the bundle
Nested properties keep their parent path, such as offers.priceCurrency. Only publish values that match visible page content.
Required properties
- availability
- description
- itemListElement[].name
- mainEntity[].@type=Question
- mainEntity[].acceptedAnswer.text
- name
- price
- priceCurrency
- url
Recommended properties
- dateModified
- description
- eligibleRegion
- inLanguage
- itemListElement[].item
- mainEntity[].acceptedAnswer.text
- mainEntity[].author.name
- mainEntity[].name
- priceValidUntil
Combined JSON-LD
Paste this as one script tag, then replace every example value with data from the live page.
[
{
"@context": "https://schema.org",
"@type": "WebPage",
"@id": "https://www.example.com/security/bug-bounty#page",
"name": "Bug Bounty Program",
"description": "Report security vulnerabilities and earn rewards under our disclosure policy.",
"url": "https://www.example.com/security/bug-bounty",
"inLanguage": "en-US",
"dateModified": "2025-08-18"
},
{
"@context": "https://schema.org",
"@type": "Offer",
"@id": "https://www.example.com/security/bug-bounty#offer",
"name": "Security Bug Bounty",
"description": "Rewards for eligible vulnerabilities based on severity and impact.",
"price": "0.00",
"priceCurrency": "USD",
"availability": "https://schema.org/InStock",
"eligibleRegion": "Worldwide",
"url": "https://www.example.com/security/bug-bounty#submit"
},
{
"@context": "https://schema.org",
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "What is in scope?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Production web apps, APIs, and mobile apps listed in the scope section are eligible."
}
},
{
"@type": "Question",
"name": "How quickly do you respond?",
"acceptedAnswer": {
"@type": "Answer",
"text": "We acknowledge reports within 3 business days and provide updates weekly."
}
},
{
"@type": "Question",
"name": "Do you provide safe harbor?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Yes. Researchers following the policy are protected from legal action."
}
}
]
},
{
"@context": "https://schema.org",
"@type": "BreadcrumbList",
"itemListElement": [
{ "@type": "ListItem", "position": 1, "name": "Home", "item": "https://www.example.com" },
{ "@type": "ListItem", "position": 2, "name": "Security", "item": "https://www.example.com/security" },
{ "@type": "ListItem", "position": 3, "name": "Bug Bounty", "item": "https://www.example.com/security/bug-bounty" }
]
}
]Implement and verify
- 01
Start with the live page
Confirm titles, prices, availability, policies, and visible FAQ content before generating markup.
- 02
Add one JSON-LD script
Use the combined example as a template in the document head or before the closing body tag.
- 03
Complete regional details
Fill shipping destinations and timing for every region the page actually serves.
- 04
Link the return policy
Use a stable MerchantReturnPolicy URL and keep its terms synchronized with the page.
- 05
Match visible answers
Add only FAQs that users can read on the same page, with identical answers.
- 06
Validate after changes
Run Rich Results Test after implementation and whenever price, availability, or policy data changes.
Common errors and fixes
- Missing currency or availability
Use ISO currency codes and complete schema.org availability URLs in Offer data.
- Incomplete shipping details
Include shippingDestination.addressCountry and deliveryTime.transitTime with units.
- Return policy is not connected
Reference MerchantReturnPolicy from the Offer and provide a stable public policy URL.
- FAQ answers differ from the page
Keep structured FAQ answers identical to visible answers.
Stack FAQs
Should I list reward tiers?
If reward tiers are published, add a separate Offer entry or include tiers in the Offer description.
Can I link to a third-party platform?
Yes. Keep the main policy on your domain and link to the submission platform in the Offer URL.