Scope
Assets in scope
Rewards
Bounty table
Reward structure based on CVSS severity x asset criticality. Amounts will be published when the programme officially opens.
Rules
Engagement rules
In scope
- ✓Injection (SQLi, XSS, XXE, SSTI...)
- ✓Authentication and session management
- ✓Access control and IDOR
- ✓Sensitive data exposure
- ✓Malicious file upload
- ✓SSRF and RCE
Out of scope
- ✕DoS / DDoS attacks
- ✕Social engineering
- ✕Modifying or deleting real data
- ✕Disclosure before confirmed fix
- ✕Automated scanning without PoC
- ✕Clickjacking without demonstrated impact
SLA
Response commitments
24 business hours
Automated acknowledgement upon submission.
5 business days
Initial triage and severity assignment.
30 days
Target remediation for Critical and High findings.
90 days
Target remediation for Medium and Low. Coordinated disclosure possible after this deadline.
The programme is launching soon. Register to be notified first.