$ live - sovereign bug bounty · scope you control

AarMe

Register my organisation Create my hacker account →

[root@aarme ~]# scope --list_

Rewards

Rewards defined per programme

CVSS severity classifies the vulnerability. The bounty is set by the organisation based on asset criticality and published when each programme opens. Payment via Wave, Orange Money or PayPal.

Critical
CVSS 9.0 – 10.0
Priority handling
High
CVSS 7.0 – 8.9
Priority handling
Medium
CVSS 4.0 – 6.9
Standard handling
Low
CVSS 0.1 – 3.9
Hall of Fame

Bounty set by the organisation after CyberAar validation. See full rules

Process

How it works

01

Organisation publishes programme

Defines scope, assets to test, engagement rules and applicable severity levels.

02

Community hunts and submits

Bug Hunters explore the authorised scope and submit structured reports: description, reproduction steps, impact, proof.

03

CyberAar validates, org rewards

Every report is triaged and qualified by CyberAar. Validated findings lead to FCFA payment via Wave, Orange Money or PayPal.

Organisations

For organisations

Complement periodic audits with continuous evaluation. Attack surfaces evolve constantly - surveillance must keep pace.

Pay-Per-Finding

You only pay for vulnerabilities validated by CyberAar. Every finding is qualified and proven exploitable before any payment.

Private programme

Restrict testing to a curated set of vetted, invite-only hackers. The programme and its assets are invisible to non-invitees - access delivered over a dedicated VPN tunnel. Ideal for banking systems, ERPs and critical infrastructure.

Expert validation

CyberAar triages and qualifies every report before forwarding. You receive actionable reports, no noise.

Scope

Asset classification

The more critical the asset, the higher the reward.

Asset type Level
Public website Standard
E-commerce site Standard
Business application Sensitive
Public API Sensitive
Mobile application Sensitive
ERP / CRM Critical
Cloud infrastructure Critical
Banking application Critical
Payment system Critical

Hackers

For hackers

Public and private programmes, impact-proportional rewards, public recognition.

FCFA rewards

Bounties set by asset criticality and CVSS severity. Wave, Orange Money or PayPal payment per validated finding.

Hall of Fame

Top contributors are featured on the platform. Public ranking, permanent recognition.

CyberAar swag

Exceptional hunters receive exclusive CyberAar merch: t-shirts, hoodies, gear - on top of bounties.

Transparency

What everyone can verify

AarMe runs on a simple principle: each party sees what concerns them. No black box, no arbitrary decisions.

Organisations

  • +You only pay for vulnerabilities triaged and validated by CyberAar
  • +Every forwarded report is reproducible and proven exploitable
  • +Programme statistics visible in real time: volume, average response time
  • +Private programme: only invited hackers know the programme and its assets exist

Hackers

  • +Live report tracking: status, note and full activity history at any time
  • +Bounty defined and published by the programme before your first submission
  • +Contractual SLA: 5 business days for qualification of every report
  • +Legal safe harbour: no prosecution for tests conducted within the defined scope

Organisations

What you receive

Not a raw scanner alert. A finding reproduced, qualified and rated by a CyberAar engineer before it reaches you. You only pay for what clears that filter.

CRITICAL CVSS 9.1 · AARME-2026-0142 Validated by CyberAar

Illustrative example

Unauthenticated SSRF reaching the internal metadata service

Asset
api.example-client.sn
Reproduction
4 verified steps
Impact
Instance credential disclosure
Suggested fix
Included

Qualified within 5 working days · Identity-verified researcher · Replayed before hand-off

1You set the scope and the budget. Nothing outside it is tested.
2Private programme: only invited, verified researchers get access.
3You receive validated reports. You pay on validation, not on attempts.
Register my organisation →

Early access

Join the first wave

Create your account now and get your identity verified. You will be ready to hunt the moment the first programme opens.

An error occurred. Please retry or contact us at [email protected].