Publish a program and name the reward

You pay for results: a reward for every confirmed vulnerability and our commission on it. A report that proves nothing costs you nothing.

01Requirements

What we need from you

The documents are what separates a program from an invitation to attack a system of somebody else.

  • Documents of the owner

    For a company, an extract from the commercial register. For a sole proprietor, an extract from the register and an identity document. Programs of private persons are not accepted.

  • Authority to sign

    The signatory is a member of the management body of the company or holds a power of attorney.

  • Proof of control over every asset

    A DNS record or a file with a code we issue. Where that is impossible, the registration of the domain or the contract with the provider.

  • A person who answers

    A contact who decides on rewards within 10 business days of receiving the report and tells us when a finding has been fixed.

  • An advance

    A prepayment not smaller than the highest reward of the program with the commission. The reward and the commission for each valid report are debited from it, with an invoice for every debit. What has not been spent is returned when the program is closed.

02Steps

From the application to the first report

  1. Application

    You send the form on this page. A manager replies within 1 business day.

  2. Verification

    You send the documents and place the code we issue on every domain of the program.

  3. Program

    Together we write down the scope, the exclusions, the table of rewards and the rules.

  4. Agreement and advance

    You sign the agreement and pay the advance under a prepayment invoice.

  5. Publication

    The program is published, or opened to the researchers you have approved.

  6. Reports

    We examine every report within 5 business days of its receipt and pass on the confirmed ones, with the severity and the steps to reproduce.

03Costs

What you pay

  • Rewards

    For confirmed vulnerabilities, within the table you have set. A reward of a program is not lower than €50.

  • Commission

    20% of each reward, on top of it. It is invoiced together with the reward.

  • Nothing else

    Verification, publication, the examination of reports and the payments to researchers are included.

04Program

What a program states

  • Scope

    The domains, applications and interfaces that may be tested.

  • Exclusions

    What may not be tested and which techniques are prohibited.

  • Table of rewards

    The reward for a finding of low, medium, high and critical severity.

  • Rules

    The rules of the platform and what you add to them: test accounts, hours, limits of load.

  • Safe harbour

    Your commitment not to pursue the researchers who follow the rules.

  • Visibility

    Public, for every registered researcher, or private, for the researchers you approve.

05Questions

What owners ask

What if nobody finds anything?

Then you pay nothing. The advance is returned in full when the program is closed.

Can we stop the program?

Yes. You can suspend or close the program at any time by a notice to us. Reports received before that are examined under the program, and you pay for those that are valid.

Who sees the reports?

The researcher who wrote the report, our specialists who examine it and the persons you name. Nobody else.

What if a report is not a vulnerability?

We answer it ourselves. You receive only the reports we have confirmed.

Is the website ready for a program?

If it has never been tested, start with the free website check or with a penetration test. A program is for what remains after them.

06Application

Publish a program

  • Reply within 1 business day
  • You pay only for confirmed vulnerabilities
  • Commission 20%, nothing else
  • The advance that is not spent is returned

Publish a bug bounty program

Name the website or the service and the rewards. A manager replies within 1 business day and tells you which documents confirm that the system is yours.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
The program

Domain or URL of the website or of the main system to test, for example app.example.com.

Who sees the program

The reward for a finding of low severity, not lower than €50.

The reward for a finding of critical severity.

What may be tested, what may not, and what researchers must know. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. A secure channel is agreed after the first reply.

Automated abuse check