<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://docs.bugcrowd.com/feed/changelogs/customer.xml" rel="self" type="application/atom+xml" /><link href="https://docs.bugcrowd.com/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-07-15T07:59:00+00:00</updated><id>https://docs.bugcrowd.com/feed/changelogs/customer.xml</id><title type="html">Bugcrowd Docs | Changelogs | Customer</title><subtitle>Bugcrowd user documentation</subtitle><entry><title type="html">Savant Vista Public Beta (1.0)</title><link href="https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta/" rel="alternate" type="text/html" title="Savant Vista Public Beta (1.0)" /><published>2026-07-14T00:00:00+00:00</published><updated>2026-07-14T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta/">&lt;p&gt;Savant Vista is now available in Public Beta for asset discovery and vulnerability scanning. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core concepts and product scope, step-by-step how-to guides for estate discovery, vulnerability baseline setup, and launching an autonomous test, and updated detailed reference articles reflecting the current platform UI, asset model, and scan behavior.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="asset-management" /><summary type="html">Savant Vista is now available in Public Beta for asset discovery and vulnerability scanning. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core concepts and product scope, step-by-step how-to guides for estate discovery, vulnerability baseline setup, and launching an autonomous test, and updated detailed reference articles reflecting the current platform UI, asset model, and scan behavior.</summary></entry><entry><title type="html">VRT Update (1.19.1)</title><link href="https://docs.bugcrowd.com/changelog/customers/vrt-update-119/" rel="alternate" type="text/html" title="VRT Update (1.19.1)" /><published>2026-07-08T00:00:00+00:00</published><updated>2026-07-08T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/vrt-update-119</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/vrt-update-119/">&lt;p&gt;Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been expanded to include Active Directory (AD) misconfigurations, Kerberos/SCCM abuse vectors, and server security misconfigurations (P1–P5). SSRF classifications have also been streamlined by replacing legacy categories with more granular SSRF metrics.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been expanded to include Active Directory (AD) misconfigurations, Kerberos/SCCM abuse vectors, and server security misconfigurations (P1–P5). SSRF classifications have also been streamlined by replacing legacy categories with more granular SSRF metrics.</summary></entry><entry><title type="html">IP Restrictions</title><link href="https://docs.bugcrowd.com/changelog/customers/ip-restrictions/" rel="alternate" type="text/html" title="IP Restrictions" /><published>2026-05-14T00:00:00+00:00</published><updated>2026-05-14T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/ip-restrictions</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/ip-restrictions/">&lt;p&gt;The IP Restrictions feature allows organization admins to restrict access to their organization based on IP address. By configuring an allowlist, you can ensure that only users connecting from approved IP addresses or CIDR ranges are able to access data within the organization.&lt;/p&gt;

&lt;p&gt;This setting is configured at the organization level and applies to all admin users associated with that organization.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">The IP Restrictions feature allows organization admins to restrict access to their organization based on IP address. By configuring an allowlist, you can ensure that only users connecting from approved IP addresses or CIDR ranges are able to access data within the organization.</summary></entry><entry><title type="html">VRT Scope Rules Added</title><link href="https://docs.bugcrowd.com/changelog/customers/vrt-scope-rules/" rel="alternate" type="text/html" title="VRT Scope Rules Added" /><published>2026-05-01T00:00:00+00:00</published><updated>2026-05-01T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/vrt-scope-rules</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/vrt-scope-rules/">&lt;p&gt;Engagement Briefs, the Submission form, and Security Inbox now support &lt;strong&gt;VRT Scope Rules&lt;/strong&gt;. These rules allow you to set reminders and out-of-scope exclusions for VRT items on all or some of your targets or target groups.&lt;/p&gt;

&lt;p&gt;VRT Scope Rules are intended to set expectations with researchers at or before time of submission. Used judiciously, should reduce noise and triage times across your engagements.&lt;/p&gt;

&lt;p&gt;For full details, see the &lt;a href=&quot;/customers/engagement-management/engagement-vrt-scope-rules/&quot;&gt;VRT Scope Rules&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="engagement-management" /><summary type="html">Engagement Briefs, the Submission form, and Security Inbox now support VRT Scope Rules. These rules allow you to set reminders and out-of-scope exclusions for VRT items on all or some of your targets or target groups.</summary></entry><entry><title type="html">CVSS v4.0 Support Added</title><link href="https://docs.bugcrowd.com/changelog/customers/cvss-v4/" rel="alternate" type="text/html" title="CVSS v4.0 Support Added" /><published>2026-04-29T00:00:00+00:00</published><updated>2026-04-29T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/cvss-v4</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/cvss-v4/">&lt;p&gt;The CVSS Calculator now supports CVSS 4.0 alongside CVSS 3.1. Program administrators can enable CVSS 4.0 under Program Settings &amp;gt; Submissions, after which all new submissions will default to the new version.
Switching versions does not automatically update existing submissions. These must be reviewed manually via the Security Inbox, or updated in bulk through the API.&lt;/p&gt;

&lt;p&gt;For full details, see the &lt;a href=&quot;https://docs.bugcrowd.com/customers/submission-management/cvss/&quot;&gt;CVSS documentation&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="submission-management" /><summary type="html">The CVSS Calculator now supports CVSS 4.0 alongside CVSS 3.1. Program administrators can enable CVSS 4.0 under Program Settings &amp;gt; Submissions, after which all new submissions will default to the new version. Switching versions does not automatically update existing submissions. These must be reviewed manually via the Security Inbox, or updated in bulk through the API.</summary></entry><entry><title type="html">VRT Update (1.18)</title><link href="https://docs.bugcrowd.com/changelog/customers/vrt-update-118/" rel="alternate" type="text/html" title="VRT Update (1.18)" /><published>2026-03-09T00:00:00+00:00</published><updated>2026-03-09T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/vrt-update-118</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/vrt-update-118/">&lt;p&gt;Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been enhanced to support mappings to auto-suggest CVSS vectors for opt-in customers.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been enhanced to support mappings to auto-suggest CVSS vectors for opt-in customers.</summary></entry><entry><title type="html">New Security Inbox- Speed, Automation, and AI</title><link href="https://docs.bugcrowd.com/changelog/customers/the-security-inbox/" rel="alternate" type="text/html" title="New Security Inbox- Speed, Automation, and AI" /><published>2026-02-02T00:00:00+00:00</published><updated>2026-02-02T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/the-security-inbox</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/the-security-inbox/">&lt;p&gt;We are excited to announce the launch of the new Security Inbox. Designed as a high-performance command center, it offers streamlined triage workflows, powerful customization features, and deeper platform efficiencies to accelerate your time to remediation.&lt;/p&gt;

&lt;h2 id=&quot;whats-new&quot;&gt;What’s New&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Saved Views &amp;amp; Pinning:&lt;/strong&gt; Design your perfect workflow. Create, share, and pin custom filter sets as tabs for one-click access to your most critical work queues.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Focused View Layout:&lt;/strong&gt; Maximize productivity with a split-screen interface. View full technical details side-by-side without losing your place (activities, brief, disclosures, etc.)&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;AI Triage Assistant:&lt;/strong&gt; Leverage our secure, in-platform AI operational assistant to summarize complex findings, suggest remediation steps, and even generate Nuclei retest templates using natural language.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Automated Integration Triggers:&lt;/strong&gt; Turn filters into actions. Link your Saved Views directly to Jira or other integrations to automate ticket creation based on your specific criteria.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;improved-capabilities&quot;&gt;Improved Capabilities&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Advanced Search &amp;amp; Filtering:&lt;/strong&gt; Find what you need in seconds. Search by Submission ID, Researcher, or Target with an enhanced filtering engine designed to help you focus on the vulnerabilities that matter most.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Modernized UI:&lt;/strong&gt; Experience a refreshed, scannable design across the entire Inbox, specifically engineered to reduce cognitive load during high-volume triage sessions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;ready-to-dive-in&quot;&gt;Ready to dive in?&lt;/h2&gt;

&lt;p&gt;To take full advantage of these new features and explore the updated workflows, please visit our &lt;a href=&quot;https://docs.bugcrowd.com/customers/security-inbox/the-security-inbox/&quot;&gt;Security Inbox Documentation.&lt;/a&gt;&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">We are excited to announce the launch of the new Security Inbox. Designed as a high-performance command center, it offers streamlined triage workflows, powerful customization features, and deeper platform efficiencies to accelerate your time to remediation.</summary></entry><entry><title type="html">Reward Cancellation Enhancement</title><link href="https://docs.bugcrowd.com/changelog/customers/rewards-page-update/" rel="alternate" type="text/html" title="Reward Cancellation Enhancement" /><published>2026-01-29T00:00:00+00:00</published><updated>2026-01-29T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/rewards-page-update</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/rewards-page-update/">&lt;h2 id=&quot;enhancement-8-hour-reward-cancellation-window&quot;&gt;Enhancement: 8-Hour Reward Cancellation Window&lt;/h2&gt;

&lt;p&gt;We’ve added more flexibility to your reward process. Customers now have a 8-hour window to cancel a reward after it has been issued, allowing you to quickly correct errors before payments are finalized.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Grace Period:&lt;/strong&gt; View a real-time countdown for “Processing” rewards.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Easy Voiding:&lt;/strong&gt; Cancel rewards directly from the Reward History table.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Transparency:&lt;/strong&gt; Select a reason for cancellation to keep researchers informed.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Instant Recovery:&lt;/strong&gt; Cancelled funds are immediately returned to your reward pool.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;After 8 hours, rewards are marked as &lt;strong&gt;Finalized&lt;/strong&gt; and processed for payment.&lt;/p&gt;

&lt;p&gt;For more details, view the updated &lt;a href=&quot;https://docs.bugcrowd.com/customers/quick-start/the-rewards-page/&quot;&gt;Rewards Page Documentation&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">Enhancement: 8-Hour Reward Cancellation Window</summary></entry><entry><title type="html">New Core AI Platform Capabilities</title><link href="https://docs.bugcrowd.com/changelog/customers/core-ai-platform/" rel="alternate" type="text/html" title="New Core AI Platform Capabilities" /><published>2025-12-10T00:00:00+00:00</published><updated>2025-12-10T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/core-ai-platform</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/core-ai-platform/">&lt;p&gt;We are excited to announce the launch of the new Bugcrowd AI capabilities designed to accelerate remediation, streamline triage, and provide deeper insights into your security posture—all while maintaining strict data privacy and control.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. AI Triage Assistant&lt;/strong&gt;&lt;br /&gt;
Transform triage from a static checklist into a dynamic conversation. The AI Triage Assistant is a secure, in-platform operational assistant embedded directly within the Submission Inbox. It empowers security teams to investigate vulnerabilities using natural language without leaving their primary workflow.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Conversational Investigation&lt;/strong&gt;: Ask questions to probe for details, such as “Explain this payload to me as if I were a junior developer” or “Model a potential attack chain for this flaw”.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Instant Efficiency&lt;/strong&gt;: Generate on-demand artifacts, including remediation guidance and valid Nuclei templates for retesting.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Context-Aware&lt;/strong&gt;: The assistant automatically references submission details, comments, and engagement metadata to ensure relevance and accuracy.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;2. AI Analytics&lt;/strong&gt;&lt;br /&gt;
Unlock deeper insights with natural language querying. AI Analytics empowers Organization Owners to analyze security program data through interactive dashboards and a new “Ask AI” interface.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Ask AI&lt;/strong&gt;: Query your program data using natural language (e.g., “What is our average ‘Days to Accept’ compared to last quarter?”) to get instant answers without generating complex reports.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Interactive Dashboards&lt;/strong&gt;: Visualize security posture with pre-defined reports where selecting data points highlights corresponding data across graphs.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Flexible Filtering&lt;/strong&gt;: Filter dashboards by date range, program name, or engagement type, and export data to CSV or PDF.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;3. AI Connect&lt;/strong&gt;&lt;br /&gt;
The secure “front door” for your internal AI tools. AI Connect is a dedicated Model Context Protocol (MCP) server that securely streams your program data to your internal AI applications.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Bring Your Own Agent&lt;/strong&gt;: Connect IDEs like Cursor or GitHub Copilot directly to your Bugcrowd program.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Real-Time Data&lt;/strong&gt;: Query submission data instantly via a secure Server-Sent Events (SSE) stream—no need to build complex data pipelines or exports.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Developer-Ready&lt;/strong&gt;: Enable your internal AI to merge vulnerability data with your codebases to generate context-aware remediation advice.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;security--data-privacy&quot;&gt;Security &amp;amp; Data Privacy&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Centralized governance for Generative AI.&lt;/strong&gt; We understand that data privacy is paramount. The &lt;strong&gt;Global Control of LLMs&lt;/strong&gt; allows Organization Owners to centrally manage the use of GenAI features across their organization. Organization Owners can Enable or Disable all LLM-powered features (like &lt;strong&gt;AI Triage Assistant&lt;/strong&gt; and &lt;strong&gt;Ask AI&lt;/strong&gt;) with a single action.&lt;/p&gt;

&lt;p&gt;The Bugcrowd AI Capabilities is built on a &lt;strong&gt;“Zero Training Policy.”&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;No Training&lt;/strong&gt;: Your data is never used to train third-party models.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Inference Only&lt;/strong&gt;: Data is used solely to generate the feature’s immediate output and is not retained.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Secure Infrastructure&lt;/strong&gt;: All LLMs are hosted securely within Bugcrowd’s infrastructure.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;for-more-information-and-documentation&quot;&gt;For More Information and Documentation:&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://docs.bugcrowd.com/customers/ai-capabilities/ai-analytics/&quot;&gt;&lt;strong&gt;AI Analytics: Ask AI&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://docs.bugcrowd.com/customers/reporting-organization/organization-analytics/&quot;&gt;&lt;strong&gt;Organization Analytics&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://docs.bugcrowd.com/customers/ai-capabilities/ai-triage-assistant/&quot;&gt;&lt;strong&gt;AI Triage Assistant&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://docs.bugcrowd.com/customers/ai-capabilities/ai-connect/&quot;&gt;&lt;strong&gt;AI Connect&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://docs.bugcrowd.com/customers/ai-capabilities/global-controls-of-llm/&quot;&gt;&lt;strong&gt;Global Control of LLMs&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content><author><name></name></author><category term="customer" /><summary type="html">We are excited to announce the launch of the new Bugcrowd AI capabilities designed to accelerate remediation, streamline triage, and provide deeper insights into your security posture—all while maintaining strict data privacy and control.</summary></entry><entry><title type="html">Request a Response Enhancements</title><link href="https://docs.bugcrowd.com/changelog/customers/request-a-response/" rel="alternate" type="text/html" title="Request a Response Enhancements" /><published>2025-11-17T00:00:00+00:00</published><updated>2025-11-17T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/request-a-response</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/request-a-response/">&lt;p&gt;We have enhanced the Request a Response feature to foster stronger collaboration between customers and researchers, ensuring more timely and effective submission resolution.&lt;/p&gt;

&lt;h2 id=&quot;whats-new&quot;&gt;What’s New&lt;/h2&gt;

&lt;h3 id=&quot;1-automatic-expiration&quot;&gt;1. Automatic Expiration&lt;/h3&gt;

&lt;p&gt;Any open RaR will &lt;strong&gt;automatically expire after 10 business days&lt;/strong&gt; if no response is provided by the party that the request was directed to.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;To prevent expiration and maintain Researcher engagement, please ensure your team responds to or triages submissions with an active RaR within this 10-business-day window.&lt;/li&gt;
  &lt;li&gt;The expiration event is recorded in the submission’s &lt;strong&gt;Activity Log&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;2-increased-researcher-quota&quot;&gt;2. Increased Researcher Quota&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Researchers can now have &lt;strong&gt;2 open RaR&lt;/strong&gt; at any given time (previously the limit was 1).&lt;/li&gt;
  &lt;li&gt;This allows for more collaboration and may result in a slight increase in RaR activity on your submissions.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;For more details on how to use this functionality, see&lt;/em&gt; &lt;a href=&quot;https://docs.bugcrowd.com/customers/submission-management/responding-to-a-request-response/&quot;&gt;&lt;strong&gt;Responding to a Request a Response&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">We have enhanced the Request a Response feature to foster stronger collaboration between customers and researchers, ensuring more timely and effective submission resolution.</summary></entry></feed>