Terms of the Bug Bounty Platform for Researchers

Terms on which a researcher takes part in the programs of the platform. The researcher tests within the rules and reports to the platform only. The Operator acquires every valid report in its own name and pays the whole reward the owner of the program has decided on, to the researcher or to the researcher’s business, without withholding anything from it.

1.Definitions

1.1

In these Terms the following terms have the following meaning:

  1. (a)“Operator” means Osaühing Ida Portal, registry code 10970449, registered office: Kivilinna tn 18-49, 20604 Narva, Ida-Viru maakond, Estonia, which provides its services under the name Security Test Team;
  2. (b)“Platform” means the bug bounty platform that the Operator runs on the website securitytest.team;
  3. (c)“Researcher” means the natural person who has accepted these Terms and whose registration the Operator has confirmed;
  4. (d)“Owner” means the legal person, or the natural person acting in the course of his or her business or profession, who has published a Program on the Platform;
  5. (e)“Asset” means a website, an application, an interface or another information system that a Program names as subject to research;
  6. (f)“Program” means the terms on which an Owner invites Researchers to look for vulnerabilities in its Assets: the scope, the exclusions, the table of Rewards and the rules the Owner adds to the Platform Rules;
  7. (g)“Platform Rules” means the rules of research set out in Section 4;
  8. (h)“Report” means the message of the Researcher about a vulnerability of an Asset, sent through the Platform;
  9. (i)“Valid Report” means a Report about a vulnerability of an Asset in scope which the Operator has reproduced, which is the first Report of that vulnerability and which was obtained within the Program and the Platform Rules;
  10. (j)“Severity” means the qualitative rating of a vulnerability under the Common Vulnerability Scoring System, version 4.0: low, medium, high or critical;
  11. (k)“Reward” means the amount the Operator pays for a Valid Report as the fee for finding, verifying and reporting the vulnerability;
  12. (l)“Payee” means the person to whom a Reward is paid under Section 8;
  13. (m)“Contract” means the contract concluded between the Operator and the Researcher on these Terms.

2.Subject and conclusion of the Contract

2.1

Under the Contract the Operator gives the Researcher access to the Programs and acquires from the Researcher, in its own name and for its own account, the service of finding, verifying and reporting vulnerabilities of the Assets, and the Researcher carries out research within the Programs and the Platform Rules. The Operator pays the Reward for every Valid Report.

2.2

The Operator supplies the Valid Reports to the Owners as its own service. The obligation of the Operator to pay a Reward does not depend on payment by the Owner. The Researcher has no claim against an Owner for a Reward, and an Owner has no payment obligation towards the Researcher.

2.3

The person who wishes to take part sends an application through the form of the Platform and accepts these Terms in it. The Operator replies within 1 business day.

2.4

The Contract is concluded at the moment the Operator confirms the registration of the Researcher. The Operator may decline an application without stating reasons.

2.5

The Contract is a framework. It creates no obligation of the Researcher to carry out research or to send Reports. The Researcher decides alone whether, when, where and how to carry out research and in which Program to take part.

2.6

The Researcher acts independently and at his or her own expense, in his or her own name or on behalf of the Payee under Section 8. The Contract creates no employment, agency or partnership between the Researcher and the Operator or an Owner. The Platform Rules and the rules of a Program set the limits of the authorisation of the Owner; they are not instructions on how to carry out the work.

2.7

The Operator makes no decision about the Researcher solely by automated means, including a decision on a Report, on a Reward or on the participation of the Researcher. Every Report is examined by a person.

3.Who may take part

3.1

A person may be a Researcher who:

  1. (a)is at least 18 years old and has full legal capacity;
  2. (b)is not listed under the international sanctions binding in Estonia: the restrictive measures of the European Union and the sanctions of the Government of the Republic of Estonia;
  3. (c)is not controlled by, and does not act on behalf of, a person so listed;
  4. (d)is not a member of the personnel of the Operator.

3.2

A Researcher does not take part in a Program whose Owner the Researcher works for, or has worked for in the twelve months before the Report, as an employee or a contractor, and does not report a vulnerability the Researcher learned of in the course of such work.

3.3

A Researcher has one registration. The registration is not transferred to another person.

4.Platform Rules

4.1

A Researcher who takes part in a Program:

  1. (a)researches only the Assets the Program names as in scope, and asks the Operator before acting where the Program is unclear;
  2. (b)uses only the accounts and the data the Researcher has created, or those the Owner has provided for the research;
  3. (c)does not read, alter, copy or keep data that does not belong to the Researcher. A Researcher who has obtained access to such data stops, does not copy it, deletes whatever of it the Researcher holds, reports at once and confirms the deletion to the Operator;
  4. (d)uses the least action that proves the vulnerability, leaves no means of access behind and does not move from the Asset to other systems;
  5. (e)does not degrade the Asset: carries out no denial-of-service attacks, sends no mass messages and does not scan at a rate that affects availability;
  6. (f)does not use social engineering, phishing or physical access, unless the Program permits them in so many words;
  7. (g)reports a vulnerability through the Platform only and without delay, and does not share, sell or publish it;
  8. (h)demands no payment and sets no conditions for a Report other than the Reward of the Program;
  9. (i)complies with the law that applies to the Researcher and with the rules the Owner has added to the Program.

4.2

The rules of a Program may make the Platform Rules stricter. Where they differ, the stricter rule applies.

5.Authorisation of research

5.1

By publishing a Program its Owner authorises the Researchers to whom the Program is open to research the Assets in scope within the Program and the Platform Rules, and undertakes not to initiate or support legal proceedings against a Researcher for research carried out in good faith within them.

5.2

If a third party brings proceedings against the Researcher for such research, the Operator confirms that the research was carried out within a Program of the Platform.

5.3

The authorisation and the undertakings are given by the Owner and bind the Owner. They cover only research carried out in good faith within the Program and the Platform Rules. They do not cover the systems of third parties, including those of hosting, cloud and other providers and the services of third parties that an Asset uses; they do not bind public authorities and do not replace the law of other States, including the law of the State where the Researcher carries out the research.

6.Reports

6.1

A Report is sent through the channel the Operator has given the Researcher at registration. A Report contains:

  1. (a)the Program and the Asset concerned;
  2. (b)the address and the parameter or the component concerned;
  3. (c)the steps to reproduce the vulnerability from a clean state;
  4. (d)what an attacker could achieve;
  5. (e)the evidence, from which the data of other persons has been removed.

6.2

A specialist of the Operator examines a Report within 5 business days of its receipt: the specialist reproduces the vulnerability, establishes whether the Report is a Valid Report and determines the Severity. The Operator informs the Researcher of the result and of its reasons.

6.3

Where several Reports describe the same vulnerability, the first of them is the Valid Report.

6.4

If the Researcher disagrees with the result, the Researcher states the reasons in writing. The Operator examines the Report again; where possible, a person other than the one who examined it first does so. The result of that examination is final between the parties, without prejudice to recourse to a court.

7.Rewards

7.1

For a Valid Report the Operator pays the Reward. The Reward is the fee for finding, verifying and reporting the vulnerability, and not a prize.

7.2

The Owner of the Program decides on the amount of the Reward within 10 business days of receiving the report, within the table of the Program for the Severity the Operator has determined. If the Owner has not decided within that period, the Reward is the lowest amount of the table for that Severity. The Operator informs the Researcher of the amount.

7.3

The obligation of the Operator to pay the Reward arises on the day the amount has been decided on or the period for the decision has expired. It does not depend on payment by the Owner.

7.4

The Researcher receives the whole Reward. The Operator withholds nothing from it; the commission of the Platform is paid by the Owner in addition to the Reward. The Reward does not include value added tax.

7.5

The Operator pays the Reward within 10 business days of the decision, in euros, by bank transfer to the account of the Payee. Where the conditions of Section 9 are not met on the day of the decision, the period runs from the day they are met. Each party bears the charges of its own bank.

7.6

No Reward is paid for a Report:

  1. (a)that is not a Valid Report;
  2. (b)that was obtained in breach of the Program, of the Platform Rules or of the law;
  3. (c)of a Researcher who does not meet the conditions of Section 3;
  4. (d)of a vulnerability that the Researcher has disclosed to a third party.

7.7

The taxes and the contributions due on the Reward are paid by the Researcher or by the Payee in the State where they are due.

8.Who receives the payment

8.1

The Operator pays Rewards only where Estonian law requires it neither to withhold tax from the Reward nor to pay social tax on it. A Reward is therefore paid only to a Payee, which is one of the following:

  1. (a)the Researcher as a private person, if the Researcher is not resident in Estonia for tax purposes and carries out the research outside Estonia;
  2. (b)the Researcher as a sole proprietor entered in the commercial register of Estonia or of another State of the European Economic Area, where the Reward is business income of that sole proprietor;
  3. (c)a legal person which the Researcher is authorised to represent: a legal person of Estonia; or a foreign legal person that is not located in a jurisdiction on the EU list of non-cooperative jurisdictions for tax purposes, for research carried out outside Estonia.

8.2

A Researcher who is resident in Estonia for tax purposes, or who carries out the research in Estonia, therefore receives Rewards only as a sole proprietor or through a legal person.

8.3

Where the Payee is a sole proprietor, the Researcher carries out the research in the course of that business. Where the Payee is a legal person, the Researcher carries out the research and sends the Reports on its behalf, the service is supplied by that legal person and the Reward is due to it; by naming it as the Payee, the Researcher accepts these Terms also on its behalf.

8.4

Rewards are not paid to an entrepreneur account (ettevõtluskonto) under the Simplified Business Income Taxation Act of Estonia.

8.5

Before the first payment the Researcher declares to the Operator the State in which the Researcher is resident for tax purposes, the State in which the Researcher carries out the research, and the Payee. The Researcher informs the Operator of a change without delay, and in any case before a Reward is paid for a Report sent after the change.

8.6

If a declaration of the Researcher proves untrue, the Researcher compensates the Operator for the taxes, the interest and the other charges the Operator has to pay as a result.

8.7

A Payee that is a sole proprietor or a legal person invoices the Operator for the Reward. Value added tax is charged by the Payee, or accounted for by the Operator by reverse charge, as the law requires.

8.8

For a Payee that is a private person the Operator issues a document that names the Program, the Report and the amount.

9.Information and checks before payment

9.1

Before the first payment the Researcher gives the Operator the following information and keeps it up to date:

  1. (a)the full name, the date of birth and the primary address of the Researcher;
  2. (b)the identity document of the Researcher, for the check of the identity;
  3. (c)every tax identification number of the Researcher and the State that issued it, or, where none has been issued, the place of birth;
  4. (d)the VAT identification number of the Researcher, where one has been issued;
  5. (e)where the Payee is a sole proprietor: the register in which it is entered and its registry code;
  6. (f)where the Payee is a legal person: its legal name, registered address, registry code, tax identification number and VAT identification number, its permanent establishments in the European Union, the persons who own 50% or more of it or control it, and the document from which the right of the Researcher to represent it follows;
  7. (g)the identifier of the bank account to which the Reward is paid and the name of its holder.

9.2

The account is held in the name of the Payee at a bank that is not subject to restrictive measures of the European Union prohibiting transactions with it.

9.3

The Operator checks the identity of the Researcher against the identity document without keeping a copy of it: it records the type, the number, the issuing State and the expiry date of the document, and the date, the method and the result of the check. The Operator checks the other information against public registers and against the electronic interfaces that the European Union and the Member States make available free of charge for checking tax identification and VAT identification numbers, and may require further documents.

9.4

Before every payment the Operator checks the Researcher, the Payee and the person to whom the payment is made against the lists of the international sanctions binding in Estonia. A Payee that is a legal person may not be listed, may not be owned 50% or more or controlled by a listed person and may not act on behalf of one.

9.5

The Operator pays a Reward only after it has checked the identity of the Researcher, the declarations of Section 8, the Payee and the account, and has made the check against the sanctions lists.

9.6

Where international sanctions prohibit the payment, the Operator does not pay the Reward, freezes the amount and notifies the Financial Intelligence Unit where the law requires it. The claim for the Reward remains frozen and is not paid to anyone while the sanction applies. The Operator is not liable for not paying the Reward in such a case.

10.Reporting to the tax authority

10.1

The Operator is a reporting platform operator under Council Directive 2011/16/EU, as amended by Council Directive (EU) 2021/514, and under Chapter 2⁴ of the Tax Information Exchange Act of Estonia.

10.2

Each year, by 31 January of the following year, the Operator reports to the Estonian Tax and Customs Board the information of Section 9 about the Researchers and the Payees who are resident in a Member State of the European Union or in a jurisdiction listed by the Estonian Tax and Customs Board, the Rewards paid to them in each quarter and the number of Valid Reports for which the Rewards were paid. The Estonian Tax and Customs Board exchanges the information with the State or the States of residence.

10.3

Before reporting, and by 31 January at the latest, the Operator gives each Researcher and each Payee the information about them that it will report.

10.4

If the Researcher does not give the information required for the report despite two reminders, the Operator may withhold the payment of Rewards until the information is given, but not earlier than 60 days after the first request, as § 8(1¹) of the Tax Information Exchange Act permits.

11.Rights to a Report

11.1

By sending a Report the Researcher grants the Operator a non-exclusive licence, unlimited in time and territory, to use the Report in order to examine the vulnerability and to supply the Valid Report to the Owner, with the right to grant the Owner of the Program a licence of the same kind to use the Report in order to remedy the vulnerability and to protect the Assets.

11.2

The licence is granted without separate charge. The Reward is the fee for the service of finding, verifying and reporting the vulnerability, not a payment for the licence.

11.3

The Researcher remains the author of the Report. The Operator and the Owner name the Researcher as its author only with the consent of the Researcher and under the name the Researcher has chosen.

11.4

The Researcher represents that the Report is his or her own work and that sending it does not breach the rights of third parties.

12.Content rules and moderation

12.1

The Operator stores the Reports, the messages and every other text or file the Researcher sends through the Platform. They may not contain:

  1. (a)content that is illegal under the law of the European Union or of a Member State;
  2. (b)content that infringes the rights of others, including intellectual property rights;
  3. (c)personal data beyond what is necessary to prove the vulnerability;
  4. (d)functioning malicious code beyond a proof of concept that demonstrates the vulnerability.

12.2

Every review and every decision under this section and under Section 15 is made by a person. The Operator makes no decision on content by automated means.

12.3

Where content is illegal or incompatible with these Terms, the Operator may take the following measures, in a diligent, objective and proportionate manner and with due regard to the rights and the legitimate interests of the parties concerned:

  1. (a)refuse the content or remove it;
  2. (b)suspend or end the participation of the Researcher in a Program or on the Platform;
  3. (c)refuse or withhold the Reward for the Report concerned.

12.4

The Operator notifies the Researcher of every such measure, at the latest when it takes effect, with a statement of reasons under Article 17 of Regulation (EU) 2022/2065. The statement names the measure, its scope and its duration; the facts and the circumstances relied on, including whether the measure was taken on a notice; the ground: the provision of the law for illegal content or the provision of these Terms for content incompatible with them; that the decision was made by a person; and the possibilities of redress.

12.5

The Researcher may request a review of the measure by email to info@securitytest.team, stating the reasons. Where possible, the request is examined by a person other than the one who took the measure. The Operator informs the Researcher of the result and of its reasons without undue delay. The right of the Researcher to recourse to a court is not affected.

13.Confidentiality and disclosure

13.1

The Researcher keeps confidential the vulnerabilities, the Reports, the correspondence about them and everything that is not public about a Program and its Owner, the existence of a private Program included.

13.2

A vulnerability is disclosed to the public only after it has been remedied and with the written consent of the Owner, given through the Platform.

13.3

The obligation of confidentiality remains in force after the Contract has ended.

14.Personal data

14.1

The Operator processes the personal data of the Researcher in accordance with its Privacy Policy.

14.2

The Operator does not disclose the identity of the Researcher to an Owner without the consent of the Researcher, except where the Researcher has acted outside the Program or the Platform Rules and the Owner needs the identity to establish, exercise or defend legal claims, or where the law or a binding decision of a court or an authority requires the disclosure. In Reports and in acknowledgements the Researcher appears under the name the Researcher has chosen.

15.Breach of these Terms

15.1

If the Researcher has breached these Terms or the rules of a Program, the Operator may suspend or end the participation of the Researcher, refuse the Reward for the Report obtained in breach and inform the Owner concerned. The Operator notifies the Researcher of the measure with a statement of reasons and informs the Researcher of the possibilities of redress under Section 12.

15.2

The Researcher is liable for the damage the Researcher has caused by actions outside the Program and the Platform Rules.

16.Liability of the Operator

16.1

The Operator is liable to the Researcher for the payment of a Reward from the day the Reward has been decided on or the period for the decision has expired.

16.2

The Operator does not warrant that Programs are open at any time, that a Program remains unchanged or that a Report will be rewarded.

16.3

The Operator is liable without limitation for damage it has caused intentionally or through gross negligence, and for death, bodily injury and damage to health.

16.4

In all other cases the total liability of the Operator is limited to the Rewards due to the Researcher.

17.Term and termination

17.1

The Contract enters into force at the moment it is concluded and is concluded for an indefinite period.

17.2

Each party may terminate the Contract at any time by a notice to the other party.

17.3

The Rewards for the Valid Reports sent before the Contract ended are paid under these Terms.

18.Governing law and jurisdiction

18.1

The Contract is governed by the law of the Republic of Estonia.

18.2

The parties seek to resolve a dispute by negotiation. A dispute that is not resolved by negotiation is resolved by the court of the Republic of Estonia in whose jurisdiction the registered office of the Operator is located.

18.3

Mandatory provisions of the law that protect the Researcher and cannot be derogated from by agreement remain unaffected.

19.Final provisions

19.1

The Operator may change these Terms. It notifies the Researcher of a change by email no later than 30 days before the change takes effect. A Researcher who does not agree to the change may terminate the Contract before that day.

19.2

Notices under the Contract are sent by email: to the Operator at info@securitytest.team, to the Researcher at the address stated in the application.

19.3

The Researcher does not transfer the Contract to a third party without the written consent of the Operator. This does not restrict the assignment of a claim for money.

19.4

If a provision of these Terms is invalid, the validity of the remaining provisions is not affected.

19.5

These Terms are drawn up in English and are published in translation. If a translation differs from the English text, the English text prevails.