Skip to main content

New: Meet Apex, the agent that runs your security program while you sleep

New Cantina Features for Bounties & User Control

Cantina released updates including visible bounty rewards, redesigned bounty pages, user email changes, and enhanced client control features.

Hilary
bug bounties platform updates user management security research
New Cantina Features for Bounties & User Control

New Features

Rewards now visible for bug bounty findings

The platform enhanced visibility for bounty rewards, which now appear directly under each finding and in the findings list. This improvement gives researchers, clients, and triagers immediate insight into the value assigned to security contributions.

Redesigned bounty pages

Bug bounty pages have received a complete redesign with more comprehensive details. When logged in, users now see relevant bounty information positioned alongside findings for better context and workflow efficiency.

Screenshot of Uniswap’s public bug bounty page on Cantina, showing scope, contracts, and $15.5M total reward with bounty start details.

Change user email

One of the most requested features from security researchers is now live! Users can update their email address directly under Your Profile settings, giving them more control over account management.

Client Improvements

Invite anyone to a repository

Clients can now seamlessly add users from different teams or companies and manage their roles directly within the platform. This enhancement streamlines collaboration and simplifies user management across organizational boundaries.

Self-service bounty management

Clients now have the ability to modify their bounty program details without requiring support from the Cantina team. All management options are available under the Settings tab, with a comprehensive audit log ensuring complete traceability of changes. This provides clients with greater flexibility and accelerates the process of keeping bounty programs current.

Image of Cantina’s redesigned bug bounty settings page showing reward pot, severity levels, auditor instructions, and edit history.

Enhanced bug bounty workflow control

The platform expanded client capabilities to match those of triagers, including the ability to confirm or reject findings and manage labels. This empowers clients to take a more active role in their security programs.

What’s Next?

These updates came directly from user feedback. Have additional thoughts on these new features or more ideas for what’s next? Connect with the team on X.