AarMe Programme

Programme Rules

AarMe connects organisations with security researchers in a clear, protective framework for all parties. Read these rules before any testing.

Scope

What you can and cannot do

Each organisation publishes its own scope when launching a programme. The rules below apply by default across the entire platform.

Allowed

  • Testing on assets explicitly listed in the programme
  • Fuzzing, injection, attack surface analysis within the defined scope
  • Non-destructive evidence collection (screenshots, logs)
  • Access using a test account provided or created for that purpose

Prohibited

  • Testing outside the scope defined by the organisation
  • Denial of service attacks (DoS/DDoS)
  • Accessing, modifying, or deleting real data
  • Social engineering of employees or customers
  • Sharing the vulnerability before it is fixed

Process

How to submit a report

01

Reproduce

Reproduce the vulnerability reliably before submitting. A non-reproducible report cannot be qualified.

02

Document

Description, reproduction steps, screenshots or video, estimated impact, CVSS reference where applicable.

03

Submit

Via the platform submission form. An automated acknowledgement is sent immediately.

04

Wait

CyberAar validates the report within 5 business days. No public disclosure before the fix is confirmed and all parties agree.

Classification

Vulnerability classification

Severity is assessed using the CVSS scale. Bounties are set by each organisation based on asset criticality, not vulnerability severity alone. Amounts are published when each programme opens.

Critical

9.0 – 10.0

Priority handling

High

7.0 – 8.9

Priority handling

Medium

4.0 – 6.9

Standard handling

Low

0.1 – 3.9

HoF recognition

SLA

Our commitments

24 business hours

Automated acknowledgement upon submission.

5 business days

Initial evaluation and severity qualification.

90 days max

Coordinated disclosure: you may publish after confirmed fix or 90 days, whichever comes first.

Under 90 days

Target remediation timeline, adapted to CVSS score (Critical/High prioritised).

Policy

Report policy

Duplicates

When identical reports are submitted, the first (by timestamp) is retained for the bounty. The second researcher is credited in the Hall of Fame. No partial reward.

Severity appeal

If you believe your report was under-rated, reply to your confirmation email with your CVSS justification. We will re-evaluate within 5 business days.

Individual payment

Each bounty is paid individually upon KYC approval. The amount is defined per programme. No payment pooling.

Identity & payment

KYC verification

AarMe is open with no prior identity check. A unique HMR-XXXXXX researcher ID is assigned automatically at registration. Verification only takes place when a bounty is paid.

At registration

  • HMR-XXXXXX ID assigned automatically
  • Immediate platform access
  • No documents required
  • Report submission available right away

When a bounty is paid

  • Identity verification required once
  • ECOWAS national ID or passport accepted
  • Wave or Orange Money number required
  • Payment within 15 business days after KYC

Identity documents are processed by CyberAar solely for payment purposes, in accordance with Senegalese law n° 2008-12 on personal data protection. Retained for 90 days after payment, then permanently deleted. Never shared with partner organisations.

Legal safe harbour

Researchers acting in good faith, in compliance with these rules and the scope defined by the organisation, will not face any legal action from CyberAar. We commit to working with our partner organisations to extend this protection to valid reports submitted through the platform. Safe harbour does not cover deliberate access or actions outside the defined scope.

The platform is open. Sign up or submit a report directly.

Join the platform Submit a vuln

Changelog