
I got tired of rebuilding the same reconnaissance on every target, watching good findings disappear into terminal scrollback, and starting from zero on every new program.
So I'm building BountyHub: one place where workflows run continuously, results land in structured datasets, and everything you learn stays with you. It's a one-person project from Serbia, being rebuilt from the ground up with the community shaping it.
It started with a frustration most hunters know: doing the same work over and over, and still not keeping any of it.
I kept rebuilding the same recon on every target, then losing the results in terminal scrollback.
BountyHub started as an experiment: one place for projects and automation. It confirmed that hunters wanted structure.
So it's being rebuilt from the ground up around continuous workflows, queryable datasets, self-hosted runners, bhlast for OOB, and agents with explicit capabilities.
The private beta is where real workflows from real researchers turn it into the platform we want to hunt with.
The mission is simple: make security research compound, and keep the human on the exploit.
Everything in BountyHub is built to work together. Discovery writes to datasets, datasets trigger workflows, and workflows run the tools you already trust.
Describe your process once in a real Starlark dialect, version it, and run it again on any target.
Every subdomain, port, and finding lands in a table you can query, diff, and trigger from.
A self-hosted Burp Collaborator alternative for DNS and HTTP callbacks, custom records, and file serving.
Run any tool on your own machines and keep proprietary scanners inside your infrastructure.
Add AI agents to triage results and chase leads, with only the context and tools you grant.
Store payloads in reusable groups and template them with variables so each target takes seconds.
Advanced tooling shouldn't be reserved for teams with a platform engineer. It should be accessible to every hacker with a process worth keeping.
Recon, collection, and bookkeeping should run without you.
You analyze and exploit. The platform handles the plumbing.
Your best workflow should run on every target you touch.
BountyHub is the convergence of the thrill of the hunt and the efficiency of centralization. It's the command center where your projects, workflows, and data come together, so every program you touch starts from everything you've already learned.
BountyHub runs on personal investment, so it stays aligned with users instead of investor demands.
Every feature and improvement is based on real workflows from security researchers.
Built with genuine passion for the security community, by someone who hunts with it.
Talking about a platform is easy. Shipping one is not. This is the first commit, and everything since has been built on top of it. No funding, no team, just a long-running project that keeps getting rebuilt and shipped.

The first commit. Everything since has been built on it.
Funded by me, not investors, so the roadmap answers to users.
It's on its next major version because it's worth getting right.
Every version has been shaped by feedback from real researchers.
Join the private beta and help shape the platform you'll hunt with.