Terms of the Bug Bounty Platform for Owners

Terms on which a business that owns a website or a service publishes a bug bounty program on the platform. The owner proves with documents that the system is theirs and sets the rewards. The Operator acquires the reports from the researchers in its own name and supplies every valid report to the owner for its price: the reward together with the commission, debited from the advance of the owner.

1.Definitions

1.1

In these Terms the following terms have the following meaning:

  1. (a)“Operator” means Osaühing Ida Portal, registry code 10970449, registered office: Kivilinna tn 18-49, 20604 Narva, Ida-Viru maakond, Estonia, which provides its services under the name Security Test Team;
  2. (b)“Platform” means the bug bounty platform that the Operator runs on the website securitytest.team;
  3. (c)“Owner” means the legal person, or the natural person acting in the course of his or her business or profession, who has concluded the Contract with the Operator;
  4. (d)“Researcher” means a natural person who is registered on the Platform under the Terms of the Bug Bounty Platform for Researchers and takes part in Programs;
  5. (e)“Asset” means a website, an application, an interface or another information system that a Program names as subject to research;
  6. (f)“Program” means the terms on which the Owner invites Researchers to look for vulnerabilities in its Assets: the scope, the exclusions, the table of Rewards and the rules the Owner adds to the Platform Rules;
  7. (g)“Program Agreement” means the document signed by the Owner and the Operator which states the Program and refers to these Terms;
  8. (h)“Platform Rules” means the rules of research set out in the Terms of the Bug Bounty Platform for Researchers;
  9. (i)“Report” means the message of a Researcher about a vulnerability of an Asset, sent through the Platform;
  10. (j)“Valid Report” means a Report about a vulnerability of an Asset in scope which the Operator has reproduced, which is the first Report of that vulnerability and which was obtained within the Program and the Platform Rules;
  11. (k)“Severity” means the qualitative rating of a vulnerability under the Common Vulnerability Scoring System, version 4.0: low, medium, high or critical;
  12. (l)“Reward” means the amount decided on for a Valid Report under Section 8, which the Operator pays to the Researcher as the fee for finding, verifying and reporting the vulnerability;
  13. (m)“Commission” means the remuneration of the Operator, calculated as a share of the Reward under Section 9;
  14. (n)“Price” means the price of a Valid Report which the Owner pays to the Operator: the Reward together with the Commission;
  15. (o)“Advance” means the prepayment of the Owner under Section 9 on account of Prices not yet determined;
  16. (p)“Contract” means the contract concluded between the Operator and the Owner on these Terms.

2.Nature and subject of the Contract

2.1

These Terms are the standard terms on which the Operator concludes the Contract. They become part of the Contract when the Owner signs the Program Agreement, which refers to them.

2.2

Under the Contract the Operator verifies the Owner, publishes the Program, receives and examines the Reports and supplies the Valid Reports to the Owner, and the Owner pays the Operator the Price of every Valid Report.

2.3

The Operator acquires from each Researcher, in its own name and for its own account, the service of finding, verifying and reporting a vulnerability, and supplies to the Owner its own service: the Valid Report. The Operator pays the Reward to the Researcher as its own debt. This obligation of the Operator does not depend on payment by the Owner.

2.4

The Owner has no payment obligation towards the Researchers, and the Researchers have no claim against the Owner for a Reward. The Owner makes every payment under the Contract to the Operator.

2.5

The Platform is offered to businesses: to legal persons and to natural persons who act in the course of their business or profession. The Operator does not conclude the Contract with consumers. By sending the application and by signing the Program Agreement the Owner confirms that it acts in the course of its business or profession.

3.Conclusion of the Contract

3.1

The person who wishes to publish a Program sends an application through the form of the Platform or by email to info@securitytest.team. The Operator replies within 1 business day. An application obliges neither the applicant nor the Operator to conclude the Contract.

3.2

After the verification of Section 4 has been passed and the Program has been agreed, the Operator sends the Program Agreement for signature.

3.3

The Program Agreement is signed by the Operator and by a person entitled to represent the Owner, either by hand or with a qualified electronic signature within the meaning of Regulation (EU) No 910/2014, such as the Estonian digital signature given with an identity card, Mobile-ID or Smart-ID, or a signature given with a European Digital Identity Wallet. The parties agree that a signature given in one of these ways satisfies the form they have agreed for the Contract.

3.4

The Contract is concluded at the moment the Program Agreement has been signed by both parties. The Operator confirms the conclusion by email and sends the Owner a copy of the signed Program Agreement and of these Terms in the version in force on that day. The Operator keeps the signed Program Agreement for the period stated in the Privacy Policy.

3.5

The Contract is concluded in the language of the website of the Platform that the Owner has used for the application, or in English. The Program Agreement states the language.

3.6

Until the Contract is concluded, the Operator may decline an application, in particular where:

  1. (a)the verification of Section 4 has not been passed;
  2. (b)the applicant does not act in the course of its business or profession;
  3. (c)the applicant, a person who owns 50% or more of it or a person who controls it is listed under the international sanctions binding in Estonia: the restrictive measures of the European Union and the sanctions of the Government of the Republic of Estonia;
  4. (d)the applicant is established in Russia, to which Article 5n of Council Regulation (EU) No 833/2014 prohibits the provision of technical testing and analysis services and IT consultancy services;
  5. (e)a system named in the application is used for an activity prohibited by law;
  6. (f)the publication of the Program would breach the law.

4.Verification of the Owner

4.1

A Program is published only after the Operator has verified the Owner and that the Assets belong to the Owner. For the verification the Owner provides:

  1. (a)a legal person: an extract from the commercial register or an equivalent document of the State of its registration; a natural person acting in the course of his or her business or profession: an extract from the register in which the business is entered and an identity document;
  2. (b)the document from which the right of the signatory to represent the Owner follows, unless that right follows from the register;
  3. (c)the names of the persons who own 50% or more of the Owner or otherwise control it, unless they follow from the register;
  4. (d)for every Asset, the proof of control over it: a domain name record or a file with the code issued by the Operator;
  5. (e)where control over an Asset cannot be proved in that way, the documents from which the right of the Owner to the Asset follows: the registration of the domain name or the contract with the provider;
  6. (f)where an Asset is placed with a hosting, cloud or other provider whose rules require that security testing be notified or consented to, the confirmation that the provider has been notified or has consented.

4.2

The Operator compares the documents with public registers, checks the Owner and the persons who own or control it against the lists of the international sanctions binding in Estonia, and may require further documents and explanations.

4.3

The Owner represents and warrants that the documents and the information it has provided are true, that it is the owner of the Assets or has been authorised by their owner, and that the research of the Assets within the Program does not breach the rights of third parties.

4.4

The Owner informs the Operator without delay if it ceases to control an Asset or if the data it has provided changes. The Operator removes such an Asset from the Program or suspends the Program.

4.5

The Owner compensates the Operator and the Researchers for the damage caused by the fact that a representation or warranty of this section proves untrue, including the claims of third parties.

5.The Program

5.1

The Program states:

  1. (a)the Assets that may be researched, and the Assets and techniques that are excluded;
  2. (b)the table of Rewards: the amount or the range of amounts for each Severity;
  3. (c)the rules the Owner adds to the Platform Rules;
  4. (d)whether the Program is public, open to every Researcher, or private, open to the Researchers the Owner has approved.

5.2

The lowest Reward of a Program is not lower than €50.

5.3

The rules of a Program may make the Platform Rules stricter. A rule of a Program that makes them looser is valid only where the Platform Rules permit it in so many words.

5.4

The Owner may change the Program. A change applies to the Reports received after the Operator has published it. A change that reduces the Rewards or the scope does not apply to the Reports received before it was published.

5.5

The Owner may suspend or close the Program at any time by a notice to the Operator. The Reports received before the Program was suspended or closed are examined under the Program, and the Owner pays the Price of those that are Valid Reports.

5.6

The Operator may suspend the Program where the Owner is in breach of the Contract, where the Advance is insufficient under Section 9, where the research of an Asset has become unlawful, or as a measure under Section 10.

6.Authorisation of research

6.1

By publishing the Program the Owner authorises every Researcher to whom the Program is open to research the Assets in scope within the Program and the Platform Rules.

6.2

With respect to research carried out in good faith within the Program and the Platform Rules, the Owner does not initiate or support legal proceedings against the Researcher and does not assert that the Researcher has circumvented technical protection measures.

6.3

If a third party brings proceedings against a Researcher for such research, the Owner makes it known that the actions of the Researcher were authorised by it.

6.4

The authorisation and the undertakings of this section are given by the Owner and cover only research carried out in good faith within the Program and the Platform Rules. They do not cover the systems of third parties, including those of hosting, cloud and other providers and the services of third parties that an Asset uses; they do not bind public authorities and do not replace the law of other States.

7.Reports

7.1

A specialist of the Operator examines every Report within 5 business days of its receipt: the specialist reproduces the vulnerability, establishes whether the Report is a Valid Report and determines the Severity.

7.2

The Operator passes a Valid Report on to the Owner with the Severity, the evidence and the steps to reproduce the vulnerability. The Operator answers the other Reports itself.

7.3

Where several Reports describe the same vulnerability, the first of them is the Valid Report.

7.4

If the Owner disagrees with the Severity, it states the reasons in writing within the period for the decision on the Reward. The Operator examines the Report again. The Severity it then determines is final between the parties, without prejudice to recourse to a court.

7.5

The Owner informs the Operator when a vulnerability has been remedied. At the request of the Owner the Operator verifies the remedy.

7.6

An Owner that is a manufacturer of products with digital elements has its own obligation to notify actively exploited vulnerabilities under Article 14 of Regulation (EU) 2024/2847, which applies from 11 September 2026. A Report passed on by the Operator does not relieve the Owner of that obligation.

8.Rewards and the supply of Valid Reports

8.1

The Owner decides on the Reward for a Valid Report within 10 business days of receiving the report, within the table of the Program for the Severity the Operator has determined.

8.2

If the Owner has not decided within that period, the Reward is the lowest amount of the table of the Program for that Severity.

8.3

The Owner may decide on a Reward that is higher than the table of the Program provides.

8.4

A Valid Report is supplied to the Owner, and its Price is debited from the Advance under Section 9, on the day the Owner decides on the Reward or on the day the period for the decision expires.

8.5

The Operator pays the Reward to the Researcher in its own name and for its own account within 10 business days of the decision. The Researcher receives the whole Reward; the Commission is not deducted from it.

8.6

Where international sanctions prohibit the Operator from paying a Reward, the Owner pays the Price of that Valid Report only when and to the extent the Operator pays the Reward. Until then the Operator does not debit that Price from the Advance and, to the extent the law permits, informs the Owner of it.

9.Price, Advance and payments

9.1

The Owner pays the Operator the Price of every Valid Report: the Reward together with the Commission of 20% of the Reward. The Price covers the verification, the publication of the Program, the examination of the Reports and the payment of the Rewards; the Operator charges nothing else under the Contract.

9.2

Before the Program is published, the Owner pays the Advance under a prepayment invoice. The Advance is not smaller than the highest Reward of the Program together with the Commission on it.

9.3

The Advance is a prepayment on account of Prices that have not yet been determined. It is not a payment for a particular Valid Report. The Advance is paid to the account of the Operator and becomes the asset of the Operator; the Owner has a claim for money against the Operator for the part of the Advance that has not been spent. The Advance bears no interest.

9.4

When a Valid Report has been supplied under Section 8, the Operator debits its Price from the Advance and issues the Owner an invoice for every debit. Where the Advance does not cover a Price, the Owner pays the part not covered under that invoice.

9.5

When the Advance has become smaller than the highest Reward of the Program together with the Commission on it, the Owner replenishes it under a prepayment invoice. While the Advance is insufficient, the Operator may suspend the Program.

9.6

After the Program has been closed and the Reports received before its closure have been settled, the Operator returns the part of the Advance that has not been spent without delay. Where international sanctions prohibit the return, the Operator returns the amount when and to the extent the sanctions permit.

9.7

The amounts in these Terms and in the Program do not include value added tax. The supply of the Operator to the Owner is the Valid Report for the whole Price, the Reward and the Commission together. Value added tax is charged where the law requires it. An Owner that is a taxable person in another Member State of the European Union gives the Operator its VAT identification number, which the Operator checks in the VAT Information Exchange System (VIES); such an Owner accounts for the tax by reverse charge, and the invoice states it.

9.8

Payments are made in euros by bank transfer. A payment is made when the amount has been credited to the account of the Operator. Each party bears the charges of its own bank.

10.Content rules and moderation

10.1

The Operator stores the Program and every other text or file the Owner provides through the Platform, and publishes the public Programs on the Platform. A Program and every such text or file may not contain:

  1. (a)content that is illegal under the law of the European Union or of a Member State;
  2. (b)content that infringes the rights of others, including intellectual property rights;
  3. (c)personal data other than the names and the contact details of the persons who act for the Owner;
  4. (d)an invitation to research a system that is not an Asset of the Owner, or to take actions that the Platform Rules prohibit;
  5. (e)malicious code, or a link to it.

10.2

The Operator reviews every Program before it is published, and the content it has been notified of. Every review and every decision under this section is made by a person. The Operator makes no decision on content by automated means.

10.3

Where content is illegal or incompatible with these Terms, the Operator may take the following measures, in a diligent, objective and proportionate manner and with due regard to the rights and the legitimate interests of the parties concerned:

  1. (a)refuse to publish the content, or remove it;
  2. (b)suspend or close the Program;
  3. (c)suspend the access of the Owner to the Platform or terminate the Contract.

10.4

The Operator notifies the Owner of every such measure, at the latest when it takes effect, with a statement of reasons under Article 17 of Regulation (EU) 2022/2065. The statement names the measure, its scope and its duration; the facts and the circumstances relied on, including whether the measure was taken on a notice; the ground: the provision of the law for illegal content or the provision of these Terms for content incompatible with them; that the decision was made by a person; and the possibilities of redress.

10.5

The Owner may request a review of the measure by email to info@securitytest.team, stating its reasons. Where possible, the request is examined by a person other than the one who took the measure. The Operator informs the Owner of the result and of its reasons without undue delay. The right of the Owner to recourse to a court is not affected.

11.Confidentiality and disclosure

11.1

The Operator keeps confidential the Reports and all other information about the Owner and the Assets that is not public. It discloses a Report only to the Researcher who wrote it, to the Owner and to the persons the Owner has named.

11.2

The Researchers are bound by confidentiality under the Platform Rules. A vulnerability is disclosed to the public only after it has been remedied and with the written consent of the Owner.

11.3

The Owner keeps confidential the Reports and the information about the Researchers. The Operator does not disclose the identity of a Researcher to the Owner without the consent of the Researcher, except where the Researcher has acted outside the Program or the Platform Rules and the Owner needs the identity to establish, exercise or defend legal claims, or where the law or a binding decision of a court or an authority requires the disclosure.

11.4

The obligation of confidentiality does not apply to information that a party is obliged to disclose by law or by a binding decision of a court or an authority.

11.5

The measures by which the Operator protects information are set out in the Information Security Policy.

12.Personal data

12.1

Each party processes the personal data of the representatives and the contact persons of the other party as an independent controller. The Operator processes such data in accordance with its Privacy Policy.

12.2

The Platform Rules prohibit the Researchers from reading, copying and keeping personal data. If a Report nevertheless contains personal data from an Asset, the Operator processes that data on behalf of the Owner as a processor within the meaning of Article 28 of Regulation (EU) 2016/679, and the Owner is the controller. This section then is the contract required by that Article.

12.3

The subject matter and the duration of the processing are the examination of the Reports during the Contract; its nature and purpose is the confirmation of vulnerabilities; the personal data and the data subjects are those a Report contains, as a rule the users of the Assets.

12.4

As a processor, the Operator:

  1. (a)processes personal data only on the documented instructions of the Owner, which are contained in the Contract, and transfers personal data outside the European Economic Area only on such instructions and in accordance with Chapter V of Regulation (EU) 2016/679, unless it is required to do so by Union or Member State law to which the Operator is subject; in such a case the Operator informs the Owner of that legal requirement before processing, unless that law prohibits it;
  2. (b)immediately informs the Owner if, in its opinion, an instruction infringes Regulation (EU) 2016/679 or other data protection provisions of the Union or of a Member State;
  3. (c)ensures that the persons authorised to process personal data are bound by confidentiality;
  4. (d)takes the measures required by Article 32 of Regulation (EU) 2016/679;
  5. (e)engages as sub-processors the providers named in the Privacy Policy, at present Cloudflare, Inc. for hosting and for the storage of data in the European Union, under the general written authorisation the Owner gives by concluding the Contract; informs the Owner by email of an intended change of the sub-processors before it takes effect, so that the Owner can object to it and, if the Operator maintains the change, terminate the Contract; and imposes on every sub-processor the same data protection obligations as this section imposes on the Operator;
  6. (f)assists the Owner in answering the requests of data subjects and in meeting the obligations of Articles 32 to 36 of Regulation (EU) 2016/679;
  7. (g)notifies the Owner without undue delay after it has become aware of a personal data breach;
  8. (h)masks personal data in the Reports it passes on;
  9. (i)when the Report has been closed, deletes the personal data or returns it to the Owner, at the choice of the Owner, and deletes the existing copies, unless Union or Member State law requires the storage of the personal data;
  10. (j)makes available to the Owner the information necessary to demonstrate compliance with this section and allows for audits by the Owner or by an auditor the Owner has mandated.

12.5

Where a Report shows that personal data in an Asset were actually accessed or copied, the Operator informs the Owner of it without undue delay, so that the Owner can assess whether it must notify a personal data breach under Article 33 of Regulation (EU) 2016/679. Under the Platform Rules a Researcher who has obtained access to personal data stops, does not copy the data, deletes whatever of it the Researcher holds and confirms the deletion to the Operator.

13.Warranties and liability

13.1

The Operator does not warrant that Reports will be received, that the Researchers will find every vulnerability of the Assets, or that an Asset without Reports has no vulnerabilities.

13.2

The Researchers are independent persons. In researching the Assets they are not employees, agents or subcontractors of the Operator: they research the Assets under the authorisation the Owner has given by publishing the Program.

13.3

The Operator is not liable for damage that a Researcher causes by acting outside the Program and the Platform Rules, unless the Operator has breached its own obligations under the Contract. The Operator ends the participation of such a Researcher, informs the Owner and discloses the identity of the Researcher under Section 11.

13.4

The Operator is liable without limitation for damage it has caused intentionally or through gross negligence, and for death, bodily injury and damage to health.

13.5

In all other cases, the following applies:

  1. (a)the total liability of the Operator is limited to the Commission the Owner has paid in the twelve months before the damage was caused;
  2. (b)the Operator is not liable for loss of profit and indirect damage, or for damage caused by third parties who exploit a vulnerability of an Asset.

13.6

A party is not liable for a breach caused by force majeure: a circumstance beyond its control which it could not reasonably have been expected to take into account, to avoid or to overcome.

14.Term and termination

14.1

The Contract enters into force at the moment it is concluded and remains in force until the Program has been closed and the parties have performed their obligations.

14.2

Each party may terminate the Contract at any time by a notice to the other party. The Program is closed on the day the notice is received.

14.3

The termination does not release the Owner from the payment of the Price of the Valid Reports received before the Program was closed.

14.4

The provisions on the authorisation of research, confidentiality, personal data, liability, governing law and jurisdiction remain in force after the Contract has ended.

15.Governing law and jurisdiction

15.1

The Contract is governed by the law of the Republic of Estonia.

15.2

The parties seek to resolve a dispute by negotiation. A claim is made in writing, and the party that has received it answers without undue delay.

15.3

A dispute that is not resolved by negotiation is resolved by the court of the Republic of Estonia in whose jurisdiction the registered office of the Operator is located.

16.Final provisions

16.1

The Operator may change these Terms. It notifies the Owner of a change by email no later than 30 days before the change takes effect. An Owner who does not agree to the change may terminate the Contract before that day.

16.2

The Contract consists of the Program Agreement and these Terms. If the Program Agreement differs from these Terms, the Program Agreement prevails.

16.3

Notices under the Contract are sent by email: to the Operator at the address stated in these Terms, to the Owner at the address stated in the Program Agreement.

16.4

The Owner does not transfer the Contract to a third party without the written consent of the Operator. This does not restrict the assignment of a claim for money.

16.5

If a provision of these Terms is invalid, the validity of the remaining provisions is not affected.

16.6

These Terms are drawn up in English and are published in translation. If a translation differs from the English text, the English text prevails.

17.Details of the Operator

17.1

The Operator:

DetailValue
NameOsaühing Ida Portal
Legal formPrivate limited company (osaühing)
RegisterCommercial Register of the Republic of Estonia
Registry code10970449
Registered officeKivilinna tn 18-49, 20604 Narva, Ida-Viru maakond, Estonia
Emailinfo@securitytest.team
Telephone+372 5852 4760 (SMS only)

17.2

The bank details of the Operator are stated in the invoice.