Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

govtech-vulnerability-disclosure-programme-policy

YesWeHackView on YesWeHack
RawAI Enhanced
2
In Scope
1
Out of Scope
In-Scope Assets (2)
AssetCategoryBountyQuick Links
*.gov.sgOTHERNo-
Domains where GovTech is the registrarOTHERNo-
Out-of-Scope Assets (1)
AssetCategoryBounty
All domains or subdomains not listed in the above list of 'Scopes'OTHERNo
Scope Changes (6)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addeddomains where govtech is the registrarOTHERIn Scope19:09
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope19:09
Added*.gov.sgWILDCARDIn Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope00:52
Added*.gov.sgWILDCARDIn Scope00:52
Addeddomains where govtech is the registrarOTHERIn Scope00:52