Alternatives
Products that do what DISCLOSURE does
Liberating Security Research
- 1

- 2
List of Bug Bounty Programs and Responsible Disclosures
Nov 2025 · bugbountydirectory.com
- 3GB
2018 · github.com
- 4
- 5
- 6

- 7MU
Most feedback tools are built like people actually want to report bugs. They don’t. Unless you make it dead-simple, or better yet - a little fun. After shipping a few SaaS products, I noticed a pattern: Bugs? Yes. Bug reports? No. Not because users didn’t care but because reporting bugs is usually a terrible experience. Most tools want users to: * Fill out a long form * Enter their email * Describe a bug they barely understand * Maybe sign in or create an account * Then maybe submit it Let’s be real: no one’s doing that. Especially not someone just trying to use your product. So I built…
2025
- 8

- 9

- 10

- 11

- 12

- 13

- 14

- 15

- 16IB
I built this because I wanted my own directory of public companies running bug bounty programs — where I could see their infrastructure in one place and have a real idea of where to start poking holes. Neobotnet collects intel data from companies on HackerOne and Bugcrowd — subdomains, DNS records, web servers with status codes, indexed/crawled URLs, JS files, and exposed secrets/paths (still building this last part). The data is already there when you need it. No scans to run. Currently tracking 41 companies, 63,878 web servers, and 1.8M+ URLs. Long term I want to expand this to…
Mar 2026 · neobotnet.com
- 17

- 18

- 19

- 20NI
Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware
2022 · github.com
- 21BC
2018 · justi.cz
- 22RO
Finally open sourced an internal tool we've been using for managing secrets. It's similar to SOPS, but more opinionated, easier to configure/use correctly, and produces nicer git diffs. It also supports one-way encryption, so you don't have to know the private key to add secrets.
2023 · github.com
- 23FS
2023 · bountyfordevs.com
- 24

hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…
Jul 2026 · search.cerast-intelligence.com
Ranked by how close each launch is in meaning, then by votes. Refine with a description →