CyberAar

Programs / CyberAar

CyberAar

Launching soon Public ... reports

CyberAar's official program, the company behind AarMe. Scope: AarMe platform, API and main cyberaar.io website. Opening to selected hackers soon.

Bounty: Defined at launch Opening: Coming soon
-- Reports
submitted
-- Under
review
-- Vulns
accepted
-- Avg
response

Statistics available when the programme opens.

Get early access

Scope

Assets in scope

Asset URL Criticality
AarMe Platform aarme.cyberaar.io Critical
Form API cyberaar.io/api/* Sensitive
Main website cyberaar.io Standard

Rewards

Bounty table

Reward structure based on CVSS severity x asset criticality. Amounts will be published when the programme officially opens.

Severity (CVSS) Critical Sensitive Standard
Critical 9.0 - 10.0 -- -- --
High 7.0 - 8.9 -- -- --
Medium 4.0 - 6.9 -- -- --
Low 0.1 - 3.9 Hall of Fame Hall of Fame Hall of Fame

Rules

Engagement rules

In scope

  • Injection (SQLi, XSS, XXE, SSTI...)
  • Authentication and session management
  • Access control and IDOR
  • Sensitive data exposure
  • Malicious file upload
  • SSRF and RCE

Out of scope

  • DoS / DDoS attacks
  • Social engineering
  • Modifying or deleting real data
  • Disclosure before confirmed fix
  • Automated scanning without PoC
  • Clickjacking without demonstrated impact

SLA

Response commitments

24 business hours

Automated acknowledgement upon submission.

5 business days

Initial triage and severity assignment.

30 days

Target remediation for Critical and High findings.

90 days

Target remediation for Medium and Low. Coordinated disclosure possible after this deadline.

The programme is launching soon. Register to be notified first.

Get early access Rules