Scope
Assets in scope
Rewards
Bounty table
Amount determined by CVSS severity x asset criticality. Payment via Wave or Orange Money after KYC validation.
Rules
Engagement rules
In scope
- ✓Injection (SQLi, XSS, XXE, SSTI...)
- ✓Authentication and session management
- ✓Access control and IDOR
- ✓Sensitive data exposure
- ✓Malicious file upload
- ✓SSRF and RCE
Out of scope
- ✕DoS / DDoS attacks
- ✕Social engineering
- ✕Modifying or deleting real data
- ✕Disclosure before confirmed fix
- ✕Automated scanning without PoC
- ✕Clickjacking without demonstrated impact
SLA
Response commitments
24 business hours
Automated acknowledgement upon submission.
5 business days
Initial triage and severity assignment.
30 days
Target remediation for Critical and High findings.
90 days
Target remediation for Medium and Low. Coordinated disclosure possible after this deadline.
The program is open. Submit your report directly.