Rewards for vulnerabilities, paid officially

Owners of websites and services publish programs and name the reward. Researchers find vulnerabilities, report them through the platform and receive the reward from us. We verify the owner, examine every report and pay.

01How it works

Two sides, one set of rules

The platform stands between the owner and the researcher: it verifies the first, identifies the second and answers to both for the money.

For owners

You decide what may be tested and what a finding is worth.

  1. Application

    You name the website or the service, the rewards and the rules.

  2. Verification

    You confirm with documents that the system is yours and that you may sign for its owner.

  3. Agreement and advance

    You sign the agreement and pay an advance on account of the rewards and our commission.

  4. Program

    The program is published. Reports reach you examined, reproduced and rated.

  5. Reward

    You decide on the reward within your table. We pay the researcher, and our invoice covers the reward and our commission.

Publish a program

For researchers

You choose a program, follow its rules and are paid for what you find.

  1. Registration

    You register and accept the terms. Your identity is verified before the first payment.

  2. Program

    You choose a program and read its scope and its rules.

  3. Research

    You test what is in scope and stop at the proof.

  4. Report

    You report through the platform. We examine the report within 5 business days of its receipt.

  5. Reward

    The owner decides on the reward within 10 business days of receiving the report. We pay it within 10 business days of the decision.

Become a researcher

02Verification

A program is published only by the owner

Before a program appears, we check who publishes it. Without this a program would be an invitation to attack a system of somebody else.

  • The owner

    The owner is a company or an entrepreneur. A company provides an extract from the commercial register, which we compare with the register itself. A sole proprietor provides an extract from the register and an identity document.

  • The signatory

    The person who signs for a company is a member of its management body or holds a power of attorney.

  • Every asset

    Control over each domain is proved by a DNS record or by a file with a code we issue. Where that is impossible, by documents: the registration of the domain or the contract with the provider.

  • Third parties

    Where the system runs at a hosting or cloud provider, the rules of that provider for security testing are followed, and its consent is obtained where they require it.

03Rewards and commission

What a finding is worth and who pays whom

  • The owner sets the rewards

    A program has a table of rewards by severity: low, medium, high and critical. A reward of a program is not lower than €50.

  • One scale of severity

    We rate every confirmed finding on the CVSS 4.0 scale, so that the same finding is worth the same in every report.

  • The researcher receives the whole reward

    Our commission is 20% of each reward. The owner pays it on top of the reward.

  • Payment through the platform

    The owner pays an advance before the program starts. We pay the reward to the researcher within 10 business days of the decision and invoice the owner for the reward and our commission.

  • One reward for one vulnerability

    The first report of a vulnerability is rewarded. A later report of the same vulnerability is answered and not paid.

  • Taxes

    The reward is paid in full, by bank transfer, to a verified researcher or to their business. The researcher or their business pays the taxes on it where they are due.

04Rules

Rules of every program

A program may make them stricter. It never makes them looser.

  • Only what is in scope

    A researcher tests the assets the program names and nothing else. Where the rules are unclear, the researcher asks before testing.

  • Own accounts, own data

    Testing is done with accounts the researcher has created. Where access to the data of others becomes possible, the researcher stops at the proof and does not read, copy or keep it.

  • No harm

    No denial of service, no spam, no social engineering and no physical access, unless the program permits them in so many words.

  • Report to the platform only

    A finding is reported through the platform. It is not shared, sold or published.

  • Disclosure by consent

    A public write-up appears only after the fix and with the consent of the owner.

  • Safe harbour

    The owner authorises research within the rules and does not pursue the researchers who follow them.

05Limits

What the platform does not allow

  • A program for a system whose owner has not been verified
  • Testing of a system that no program covers
  • Payment demanded for a finding outside a program, or conditions for reporting it
  • Use of a vulnerability beyond what is needed to prove it
  • Access to the personal data of users, its copying or disclosure
  • Publication of a vulnerability that has not been fixed

06More for owners

Before a program and beside it

A program pays for what is hard to find. The rest is found faster by other means.

  • Free website check

    A first look from the outside. You pay for the report only when we find vulnerabilities.

  • Readiness assessment

    A penetration test before the launch, so that rewards are paid for what is hard to find.

  • Disclosure program

    A published policy and a working channel for reports, without rewards. The baseline for every product online.

  • Program management

    We write the policy, the scope and the table of rewards with you and run the program day by day.

07Unsolicited report

A stranger reported a vulnerability. What now?

It happens to every company with a product online. Most reports come from researchers acting in good faith. How you answer decides whether the next one reaches you or the public.

  1. Acknowledge receipt within a day or two. Do not threaten and do not promise payment.
  2. Ask for the technical detail needed to reproduce the issue, through a channel you control.
  3. Verify the claim on your side before any discussion of a reward.
  4. Fix the issue, then thank the reporter. A public acknowledgement costs nothing.
  5. Publish a program or a disclosure policy, so that the next report arrives through the front door.

08Questions

Bug bounty, asked plainly

Who can publish a program?

A company or an entrepreneur that owns a website or a service, or that its owner has authorised. Programs of private persons are not accepted. The program is published after the owner has been verified and the agreement has been signed.

What does a program cost?

The rewards you decide to pay and our commission of 20% on each of them. Publication, verification and the examination of reports are included.

Can a program be private?

Yes. A private program is open to the researchers you approve and is not shown in the list of programs.

Who decides whether a report is valid?

We examine, reproduce and rate every report. The owner decides on the reward within the table of the program. If the owner disagrees with the rating, we examine the report again, and that rating is final.

Does your own team take part in the programs?

No. We never report to the programs of our own platform. Our team hunts in the programs of other platforms and follows their rules.

Can a system be tested that has no program?

No. Without the authorisation of the owner it is not research, it is an offence. The platform accepts no reports about systems outside its programs.

Does bug bounty replace a penetration test?

No. Researchers choose what to look at, and nobody guarantees coverage. A penetration test covers the agreed scope systematically. A program on top of regular testing finds what either would miss alone.

Does safe harbour make research legal?

Safe harbour is a commitment of the owner not to pursue researchers who follow the rules. It does not change criminal law and does not bind third parties. That is why the rules are followed exactly and a record is kept of what was done.