Rewards
CVSS severity classifies the vulnerability. The bounty is set by the organisation based on asset criticality and published when each programme opens. Payment via Wave or Orange Money.
Bounty set by the organisation after CyberAar validation. See full rules
Process
Defines scope, assets to test, engagement rules and applicable severity levels.
Bug Hunters explore the authorised scope and submit structured reports: description, reproduction steps, impact, proof.
Every report is triaged and qualified by CyberAar. Validated findings lead to FCFA payment via Wave or Orange Money.
Organisations
Complement periodic audits with continuous evaluation. Attack surfaces evolve constantly — surveillance must keep pace.
You only pay for vulnerabilities validated by CyberAar. Every finding is qualified and proven exploitable before any payment.
Restrict testing to a curated set of trusted researchers. Maximum confidentiality for your most sensitive systems.
CyberAar triages and qualifies every report before forwarding. You receive actionable reports, no noise.
Scope
The more critical the asset, the higher the reward.
Researchers
Public and private programmes, impact-proportional rewards, public recognition.
Bounties set by asset criticality and CVSS severity. Wave or Orange Money payment per validated finding.
Top contributors are featured on the platform. Public ranking, permanent recognition.
Exceptional hunters receive exclusive CyberAar merch: t-shirts, hoodies, gear — on top of bounties.
Early access
The platform is under development. Register to be notified first and take part in the launch phase.