Post-report documentation
When it comes to post-report documentation, be sure to follow the responsible disclosure guidelines set forth by the bug bounty program and not publicly disclose the vulnerability until the company has had time to resolve it.
Also, if possible, provide availability to help security teams better understand the vulnerability or conduct additional testing.
Remember that quality and clarity are critical in these reports. Make sure your report is well-structured, concise, and supported by concrete evidence so that it can be easily addressed by the company’s security teams.