Schema stack

    Bug Bounty / Vulnerability Disclosure Stack

    Bug bounty/disclosure program pages with WebPage + Offer, FAQs, and breadcrumb navigation.

    Included schema
    Web Page
    Offer
    Frequently Asked Questions
    Breadcrumb
    Fit

    When to use this stack

    • Bug bounty program landing pages
    • Vulnerability disclosure policy pages with reward terms
    • Pages where FAQs clarify scope and reporting timelines
    Composition

    What is included

    Data contract

    Properties across the bundle

    Nested properties keep their parent path, such as offers.priceCurrency. Only publish values that match visible page content.

    Required properties

    • availability
    • description
    • itemListElement[].name
    • mainEntity[].@type=Question
    • mainEntity[].acceptedAnswer.text
    • name
    • price
    • priceCurrency
    • url

    Recommended properties

    • dateModified
    • description
    • eligibleRegion
    • inLanguage
    • itemListElement[].item
    • mainEntity[].acceptedAnswer.text
    • mainEntity[].author.name
    • mainEntity[].name
    • priceValidUntil
    Copy-ready example

    Combined JSON-LD

    Paste this as one script tag, then replace every example value with data from the live page.

    [
      {
        "@context": "https://schema.org",
        "@type": "WebPage",
        "@id": "https://www.example.com/security/bug-bounty#page",
        "name": "Bug Bounty Program",
        "description": "Report security vulnerabilities and earn rewards under our disclosure policy.",
        "url": "https://www.example.com/security/bug-bounty",
        "inLanguage": "en-US",
        "dateModified": "2025-08-18"
      },
      {
        "@context": "https://schema.org",
        "@type": "Offer",
        "@id": "https://www.example.com/security/bug-bounty#offer",
        "name": "Security Bug Bounty",
        "description": "Rewards for eligible vulnerabilities based on severity and impact.",
        "price": "0.00",
        "priceCurrency": "USD",
        "availability": "https://schema.org/InStock",
        "eligibleRegion": "Worldwide",
        "url": "https://www.example.com/security/bug-bounty#submit"
      },
      {
        "@context": "https://schema.org",
        "@type": "FAQPage",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "What is in scope?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Production web apps, APIs, and mobile apps listed in the scope section are eligible."
            }
          },
          {
            "@type": "Question",
            "name": "How quickly do you respond?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "We acknowledge reports within 3 business days and provide updates weekly."
            }
          },
          {
            "@type": "Question",
            "name": "Do you provide safe harbor?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Yes. Researchers following the policy are protected from legal action."
            }
          }
        ]
      },
      {
        "@context": "https://schema.org",
        "@type": "BreadcrumbList",
        "itemListElement": [
          { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://www.example.com" },
          { "@type": "ListItem", "position": 2, "name": "Security", "item": "https://www.example.com/security" },
          { "@type": "ListItem", "position": 3, "name": "Bug Bounty", "item": "https://www.example.com/security/bug-bounty" }
        ]
      }
    ]
    Workflow

    Implement and verify

    1. 01

      Start with the live page

      Confirm titles, prices, availability, policies, and visible FAQ content before generating markup.

    2. 02

      Add one JSON-LD script

      Use the combined example as a template in the document head or before the closing body tag.

    3. 03

      Complete regional details

      Fill shipping destinations and timing for every region the page actually serves.

    4. 04

      Link the return policy

      Use a stable MerchantReturnPolicy URL and keep its terms synchronized with the page.

    5. 05

      Match visible answers

      Add only FAQs that users can read on the same page, with identical answers.

    6. 06

      Validate after changes

      Run Rich Results Test after implementation and whenever price, availability, or policy data changes.

    Quality check

    Common errors and fixes

    • Missing currency or availability

      Use ISO currency codes and complete schema.org availability URLs in Offer data.

    • Incomplete shipping details

      Include shippingDestination.addressCountry and deliveryTime.transitTime with units.

    • Return policy is not connected

      Reference MerchantReturnPolicy from the Offer and provide a stable public policy URL.

    • FAQ answers differ from the page

      Keep structured FAQ answers identical to visible answers.

    Questions

    Stack FAQs

    Should I list reward tiers?

    If reward tiers are published, add a separate Offer entry or include tiers in the Offer description.

    Can I link to a third-party platform?

    Yes. Keep the main policy on your domain and link to the submission platform in the Offer URL.

    Primary sources

    References