This paper explores the economics of software vulnerabilities, evaluates three policy alternatives for vulnerability discovery and disclosure and argues that bug bounty programs, which leverage two-sided digital market platforms to connect organisations and ethical hackers, yield the highest effectiveness, legality and trustworthiness impacts.