Scope
What you can and cannot do
Each organisation publishes its own scope when launching a programme. The rules below apply by default across the entire platform.
Allowed
- ✓Testing on assets explicitly listed in the programme
- ✓Fuzzing, injection, attack surface analysis within the defined scope
- ✓Non-destructive evidence collection (screenshots, logs)
- ✓Access using a test account provided or created for that purpose
Prohibited
- ✕Testing outside the scope defined by the organisation
- ✕Denial of service attacks (DoS/DDoS)
- ✕Accessing, modifying, or deleting real data
- ✕Social engineering of employees or customers
- ✕Sharing the vulnerability before it is fixed
Process
How to submit a report
Reproduce
Reproduce the vulnerability reliably before submitting. A non-reproducible report cannot be qualified.
Document
Description, reproduction steps, screenshots or video, estimated impact, CVSS reference where applicable.
Submit
Via the platform submission form. An automated acknowledgement is sent immediately.
Wait
CyberAar validates the report within 5 business days. No public disclosure before the fix is confirmed and all parties agree.
Classification
Vulnerability classification
Severity is assessed using the CVSS scale. Bounties are set by each organisation based on asset criticality, not vulnerability severity alone. Amounts are published when each programme opens.
Critical
9.0 – 10.0
Priority handling
High
7.0 – 8.9
Priority handling
Medium
4.0 – 6.9
Standard handling
Low
0.1 – 3.9
HoF recognition
SLA
Our commitments
Automated acknowledgement upon submission.
Initial evaluation and severity qualification.
Coordinated disclosure: you may publish after confirmed fix or 90 days, whichever comes first.
Target remediation timeline, adapted to CVSS score (Critical/High prioritised).
Policy
Report policy
Duplicates
When identical reports are submitted, the first (by timestamp) is retained for the bounty. The second researcher is credited in the Hall of Fame. No partial reward.
Severity appeal
If you believe your report was under-rated, reply to your confirmation email with your CVSS justification. We will re-evaluate within 5 business days.
Individual payment
Each bounty is paid individually upon KYC approval. The amount is defined per programme. No payment pooling.
Identity & payment
KYC verification
AarMe is open with no prior identity check. A unique HMR-XXXXXX researcher ID is assigned automatically at registration. Verification only takes place when a bounty is paid.
At registration
- ✓HMR-XXXXXX ID assigned automatically
- ✓Immediate platform access
- ✓No documents required
- ✓Report submission available right away
When a bounty is paid
- →Identity verification required once
- →ECOWAS national ID or passport accepted
- →Wave or Orange Money number required
- →Payment within 15 business days after KYC
Identity documents are processed by CyberAar solely for payment purposes, in accordance with Senegalese law n° 2008-12 on personal data protection. Retained for 90 days after payment, then permanently deleted. Never shared with partner organisations.
Legal safe harbour
Researchers acting in good faith, in compliance with these rules and the scope defined by the organisation, will not face any legal action from CyberAar. We commit to working with our partner organisations to extend this protection to valid reports submitted through the platform. Safe harbour does not cover deliberate access or actions outside the defined scope.
The platform is open. Sign up or submit a report directly.
Changelog
- 2026-07-24 Removed public bounty amounts: rewards defined per programme based on asset criticality.
- 2026-07-24 Report policy section: duplicates, severity appeals, individual payment.
- 2026-07-24 Per-asset bounty table. Remediation deadline 30 → 90 days.
- 2026-07-24 Coordinated disclosure policy (90 days) made explicit.
- 2026-07-23 Public launch — programme open to researchers and organisations.