Documents of the owner
For a company, an extract from the commercial register. For a sole proprietor, an extract from the register and an identity document. Programs of private persons are not accepted.
Authority to sign
The signatory is a member of the management body of the company or holds a power of attorney.
Proof of control over every asset
A DNS record or a file with a code we issue. Where that is impossible, the registration of the domain or the contract with the provider.
A person who answers
A contact who decides on rewards within 10 business days of receiving the report and tells us when a finding has been fixed.
An advance
A prepayment not smaller than the highest reward of the program with the commission. The reward and the commission for each valid report are debited from it, with an invoice for every debit. What has not been spent is returned when the program is closed.
Publish a program and name the reward
You pay for results: a reward for every confirmed vulnerability and our commission on it. A report that proves nothing costs you nothing.
01Requirements
What we need from you
The documents are what separates a program from an invitation to attack a system of somebody else.
02Steps
From the application to the first report
Application
You send the form on this page. A manager replies within 1 business day.
Verification
You send the documents and place the code we issue on every domain of the program.
Program
Together we write down the scope, the exclusions, the table of rewards and the rules.
Agreement and advance
You sign the agreement and pay the advance under a prepayment invoice.
Publication
The program is published, or opened to the researchers you have approved.
Reports
We examine every report within 5 business days of its receipt and pass on the confirmed ones, with the severity and the steps to reproduce.
03Costs
What you pay
Rewards
For confirmed vulnerabilities, within the table you have set. A reward of a program is not lower than €50.
Commission
20% of each reward, on top of it. It is invoiced together with the reward.
Nothing else
Verification, publication, the examination of reports and the payments to researchers are included.
04Program
What a program states
Scope
The domains, applications and interfaces that may be tested.
Exclusions
What may not be tested and which techniques are prohibited.
Table of rewards
The reward for a finding of low, medium, high and critical severity.
Rules
The rules of the platform and what you add to them: test accounts, hours, limits of load.
Safe harbour
Your commitment not to pursue the researchers who follow the rules.
Visibility
Public, for every registered researcher, or private, for the researchers you approve.
05Questions
What owners ask
What if nobody finds anything?
Then you pay nothing. The advance is returned in full when the program is closed.
Can we stop the program?
Yes. You can suspend or close the program at any time by a notice to us. Reports received before that are examined under the program, and you pay for those that are valid.
Who sees the reports?
The researcher who wrote the report, our specialists who examine it and the persons you name. Nobody else.
What if a report is not a vulnerability?
We answer it ourselves. You receive only the reports we have confirmed.
Is the website ready for a program?
If it has never been tested, start with the free website check or with a penetration test. A program is for what remains after them.
06Application
Publish a program
- Reply within 1 business day
- You pay only for confirmed vulnerabilities
- Commission 20%, nothing else
- The advance that is not spent is returned
Application received
Reference
Keep the reference: we name it in all further communication with you.
What happens next
- A manager reviews the application and replies within 1 business day.
- You confirm with documents that the system is yours, and we write down the program together.
- You sign the agreement and pay the advance. The program is published.
We never ask for payment, passwords or remote access in the first reply.