Redline New Evaluation screen: report fields for title, vulnerability type, asset, steps to reproduce, proof of concept, and impact, alongside a CVSS v3.1 calculator.

The New Evaluation workspace: draft or paste a report, then run it through the evaluator.

// WHAT IT DOES

Catch what a triager would, first.

  • Completeness checklist. Flags missing repro steps, proof, impact, and affected assets before you submit.
  • Evidence-versus-speculation read. Tells you where your writeup asserts impact it has not actually shown.
  • Tone check. Catches phrasing that reads as exaggerated or unprofessional to a triager.
  • Full CVSS v3.1 calculator. Live vector and score with a plain-English breakdown of each metric.
  • HackerOne severity mapping. Translates the score into the platform's severity bands.
  • Bugcrowd VRT estimate. A priority estimate to sanity-check against the program's published VRT.
  • Local history and Markdown export. Saved evaluations stay on your machine; export a clean report in one click.

// PRIVACY

Your reports never leave your machine.

  • No account, no sign-in, and no cloud sync. Your reports and inputs stay on your device.
  • No analytics or usage tracking. Apart from an optional check for new versions, nothing you enter is transmitted.
  • History is stored locally, under your control.

Redline is a drafting aid, not a substitute for your own judgment. Severity estimates should always be confirmed against the program's own published VRT before submitting. For use only with bug bounty programs and engagements you are personally authorized to test.