Find vulnerabilities and be paid for them, officially

Programs of verified owners, written permission to test and a reward paid by bank transfer with documents. The whole reward is yours: the commission is paid by the owner.

01Conditions

Who can take part

  • An adult

    You are at least 18 years old.

  • Identified

    Before the first payment we verify your identity. Your name is not passed to the owner of a program without your consent, unless you act outside the rules or the law requires it.

  • Free of sanctions

    Payments are refused to persons under sanctions binding in the European Union, and to accounts subject to them.

  • Independent

    You do not work for the owner of the program and have not worked on the system you report about.

02Steps

From registration to the reward

  1. Registration

    You send the form on this page and accept the terms. We reply within 1 business day.

  2. Program

    You choose a program and read its scope, its exclusions and its rules.

  3. Research

    You test what is in scope, with your own accounts, and stop at the proof.

  4. Report

    You send the report through the channel of the platform. We examine it within 5 business days of its receipt.

  5. Reward

    The owner decides on the reward within 10 business days of receiving the report. We pay it within 10 business days of the decision.

03Report

A report that is paid

A reward is paid for a vulnerability we can reproduce.

  • The address and the parameter or the component concerned
  • The steps to reproduce the vulnerability from a clean state
  • What an attacker could achieve
  • The evidence: requests, responses, screenshots, without the data of other people
  • Your assessment of the severity on the CVSS 4.0 scale, if you have one

04Payment

How a reward is paid

  • The whole reward

    You receive the whole amount the owner has decided on. We withhold nothing: our commission is paid by the owner.

  • Who can be paid

    Researchers resident in Estonia for tax purposes are paid as sole proprietors or through a company. Researchers resident elsewhere can also be paid as private persons when they do the research outside Estonia.

  • By bank transfer

    In euros, within 10 business days of the decision, to an account in your name or in the name of your business.

  • With documents

    A business invoices us for the reward. A private person receives from us a document that names the program, the report and the amount.

  • Taxes

    You or your business pay the taxes on the reward where they are due.

  • Reporting to the tax authority

    Under the EU rules for platforms (DAC7), we report once a year to the Estonian Tax and Customs Board the rewards paid to researchers resident in the European Union, with the data that identifies them. You see that data before it is reported.

05Questions

What researchers ask

What if somebody has reported the vulnerability before me?

The first report is rewarded. You receive an answer that says your report is a duplicate.

What if I disagree with the rating?

Write why. We examine the report again and answer with reasons. That rating is final.

Can I publish what I have found?

After the fix and with the written consent of the owner. Not before.

Can I be pursued for the research?

The owner of every program authorises research within its rules and commits not to pursue the researchers who follow them. The commitment does not cover what is done outside the rules.

Do I have to give my real name?

To us, before the first payment: a reward cannot be paid to an unknown person. In reports and in acknowledgements you appear under the name you choose.

06Registration

Register as a researcher

  • Reply within 1 business day
  • The whole reward is yours
  • Payment within 10 business days of the decision
  • Your name stays with us while you keep to the rules

Register as a researcher

Tell us who you are and what you are good at. We reply within 1 business day.

Who to reply to

We reply to this address unless you choose another channel.

Preferred channel
About you

A link to your profile on a bug bounty platform, on GitHub or to your own website.

What you test, which programs you have taken part in, what you have found. No details of vulnerabilities that have not been fixed.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. A secure channel is agreed after the first reply.

Automated abuse check