AarMe Programme

Rules

AarMe connects organisations with hackers in a clear, protective framework for all parties. Read these rules before any testing.

Scope

What you can and cannot do

Each organisation publishes its own scope when launching a programme. The rules below apply by default across the entire platform.

Allowed

  • Testing on assets explicitly listed in the programme
  • Fuzzing, injection, attack surface analysis within the defined scope
  • Non-destructive evidence collection (screenshots, logs)
  • Access using a test account provided or created for that purpose

Prohibited

  • Testing outside the scope defined by the organisation
  • Denial of service attacks (DoS/DDoS)
  • Accessing, modifying, or deleting real data
  • Social engineering of employees or customers
  • Sharing the vulnerability before it is fixed

Process

How to submit a report

01

Reproduce

Reproduce the vulnerability reliably before submitting. A non-reproducible report cannot be qualified.

02

Document

Description, reproduction steps, screenshots or video, estimated impact, CVSS reference where applicable.

03

Submit

Via the platform submission form. An automated acknowledgement is sent immediately.

04

Wait

CyberAar validates the report within 5 business days. No public disclosure before the fix is confirmed and all parties agree.

Classification

Vulnerability classification

Severity is assessed using the CVSS scale. Bounties are set by each organisation based on asset criticality, not vulnerability severity alone. Amounts are published when each programme opens.

Critical

9.0 – 10.0

Priority handling

High

7.0 – 8.9

Priority handling

Medium

4.0 – 6.9

Standard handling

Low

0.1 – 3.9

HoF recognition

SLA

Our commitments

24 business hours

Automated acknowledgement upon submission.

5 business days

Initial evaluation and severity qualification.

90 days max

Coordinated disclosure: you may publish after confirmed fix or 90 days, whichever comes first.

Under 90 days

Target remediation timeline, adapted to CVSS score (Critical/High prioritised).

Policy

Report policy

Duplicates

When identical reports are submitted, the first (by timestamp) is retained for the bounty. The second hacker is credited in the Hall of Fame. No partial reward.

Severity appeal

If you believe your report was under-rated, reply to your confirmation email with your CVSS justification. We will re-evaluate within 5 business days.

Individual payment

Each bounty is paid individually upon KYC approval. The amount is defined per programme. No payment pooling.

Identity & payment

KYC verification

Identity verification is required before any report submission. It happens entirely from your account: documents are encrypted the moment they arrive, reviewed by the CyberAar team (24 to 48 business hours), then destroyed as soon as a decision is recorded. We keep no copy and never accept them by email.

Creating your account

  • Account created with a password and two-factor authentication
  • Documents uploaded from your account, encrypted on arrival
  • Verification within 24-48 business hours
  • Documents destroyed on decision, only an attestation is kept

After account activation

  • Report submission unlocked
  • National ID card or passport accepted, any country
  • Wave or Orange Money (UEMOA zone), PayPal everywhere else
  • Payment within 15 business days after accepted report

Identity documents are processed by CyberAar for KYC verification and payment purposes, in accordance with law n° 2008-12 on personal data protection and OHADA obligations. Retained for 5 years, then permanently deleted. Never shared with partner organisations.

Private programme

Invite-only access

A private programme is visible and accessible only to hackers explicitly invited by CyberAar on behalf of the organisation. The programme name, assets and scope are not publicly visible.

Invitation required

Only hackers selected and approved by CyberAar receive access. Any testing attempt without an invitation is out of scope.

Dedicated VPN access

Programme assets are delivered over a dedicated VPN tunnel provided by CyberAar. No private asset is exposed on the public internet.

Full confidentiality

Invited hackers are bound by a confidentiality agreement. No disclosure of the scope, assets or discovered vulnerabilities is permitted without explicit consent from the organisation.

Legal safe harbour

Hackers acting in good faith, in compliance with these rules and the scope defined by the organisation, will not face any legal action from CyberAar. We commit to working with our partner organisations to extend this protection to valid reports submitted through the platform. Safe harbour does not cover deliberate access or actions outside the defined scope.

Create your account and get your identity verified. Report submission opens after that.

Create my account Submit a vuln

Changelog