Scope
What you can and cannot do
Each organisation publishes its own scope when launching a programme. The rules below apply by default across the entire platform.
Allowed
- ✓Testing on assets explicitly listed in the programme
- ✓Fuzzing, injection, attack surface analysis within the defined scope
- ✓Non-destructive evidence collection (screenshots, logs)
- ✓Access using a test account provided or created for that purpose
Prohibited
- ✕Testing outside the scope defined by the organisation
- ✕Denial of service attacks (DoS/DDoS)
- ✕Accessing, modifying, or deleting real data
- ✕Social engineering of employees or customers
- ✕Sharing the vulnerability before it is fixed
Process
How to submit a report
Reproduce
Reproduce the vulnerability reliably before submitting. A non-reproducible report cannot be qualified.
Document
Description, reproduction steps, screenshots or video, estimated impact, CVSS reference where applicable.
Submit
Via the platform submission form. An automated acknowledgement is sent immediately.
Wait
CyberAar validates the report within 5 business days. No public disclosure before the fix is confirmed and all parties agree.
Classification
Vulnerability classification
Severity is assessed using the CVSS scale. Bounties are set by each organisation based on asset criticality, not vulnerability severity alone. Amounts are published when each programme opens.
Critical
9.0 – 10.0
Priority handling
High
7.0 – 8.9
Priority handling
Medium
4.0 – 6.9
Standard handling
Low
0.1 – 3.9
HoF recognition
SLA
Our commitments
Automated acknowledgement upon submission.
Initial evaluation and severity qualification.
Coordinated disclosure: you may publish after confirmed fix or 90 days, whichever comes first.
Target remediation timeline, adapted to CVSS score (Critical/High prioritised).
Policy
Report policy
Duplicates
When identical reports are submitted, the first (by timestamp) is retained for the bounty. The second hacker is credited in the Hall of Fame. No partial reward.
Severity appeal
If you believe your report was under-rated, reply to your confirmation email with your CVSS justification. We will re-evaluate within 5 business days.
Individual payment
Each bounty is paid individually upon KYC approval. The amount is defined per programme. No payment pooling.
Identity & payment
KYC verification
Identity verification is required before any report submission. It happens entirely from your account: documents are encrypted the moment they arrive, reviewed by the CyberAar team (24 to 48 business hours), then destroyed as soon as a decision is recorded. We keep no copy and never accept them by email.
Creating your account
- ✓Account created with a password and two-factor authentication
- ✓Documents uploaded from your account, encrypted on arrival
- ✓Verification within 24-48 business hours
- ✓Documents destroyed on decision, only an attestation is kept
After account activation
- →Report submission unlocked
- →National ID card or passport accepted, any country
- →Wave or Orange Money (UEMOA zone), PayPal everywhere else
- →Payment within 15 business days after accepted report
Identity documents are processed by CyberAar for KYC verification and payment purposes, in accordance with law n° 2008-12 on personal data protection and OHADA obligations. Retained for 5 years, then permanently deleted. Never shared with partner organisations.
Private programme
Invite-only access
A private programme is visible and accessible only to hackers explicitly invited by CyberAar on behalf of the organisation. The programme name, assets and scope are not publicly visible.
Invitation required
Only hackers selected and approved by CyberAar receive access. Any testing attempt without an invitation is out of scope.
Dedicated VPN access
Programme assets are delivered over a dedicated VPN tunnel provided by CyberAar. No private asset is exposed on the public internet.
Full confidentiality
Invited hackers are bound by a confidentiality agreement. No disclosure of the scope, assets or discovered vulnerabilities is permitted without explicit consent from the organisation.
Legal safe harbour
Hackers acting in good faith, in compliance with these rules and the scope defined by the organisation, will not face any legal action from CyberAar. We commit to working with our partner organisations to extend this protection to valid reports submitted through the platform. Safe harbour does not cover deliberate access or actions outside the defined scope.
Create your account and get your identity verified. Report submission opens after that.
Changelog
- 2026-07-25 Added PayPal as payment method (Wave, Orange Money, PayPal). Private programme section (invitation, dedicated VPN, confidentiality).
- 2026-07-24 Removed public bounty amounts: rewards defined per programme based on asset criticality.
- 2026-07-24 Report policy section: duplicates, severity appeals, individual payment.
- 2026-07-24 Per-asset bounty table. Remediation deadline 30 → 90 days.
- 2026-07-24 Coordinated disclosure policy (90 days) made explicit.
- 2026-07-23 Public launch - programme open to hackers and organisations.