So I built patchli.st. The idea is simple: indie founders list their products, set bounties they can afford ($50-500 range), and security researchers submit vulnerabilities. You only pay when someone finds something real.
Free to list. No platform fees on the founder side. Researchers get paid directly when bugs are verified.
Looking for feedback. Is this something you'd use? What's missing?