Comment by Aachen
I work in the field so it's hard to know what info you might be missing. To me it seems quite straightforward: you post to your website somewhere that you're happy to have people probe your technical security provided that they follow coordinated vulnerability disclosure (you'll want to flesh it out a tad more than this one sentence of course) and what kind of reward you're willing to hand out for what kind of bug and in which part of the scope. Any exclusions, such as that you won't pay out to young or old people or if you're born in the wrong country and got sanctioned or so, are also things you'll want to mention up front to prevent sour grapes afterwards
Perhaps I can answer a specific question or look for good pointers if you have a specific question about this?
Thanks! Any good examples?
Valve comes to mind: https://hackerone.com/valve?type=team