Process
It defines the scope, assets to test, engagement rules and severity levels.
Bug Hunters explore the authorised scope and submit structured reports: description, reproduction steps, impact, proof.
Every report is triaged and qualified by the CyberAar team. Validated findings are forwarded and trigger payment.
Organisations
Complement your point-in-time audits with continuous assessment. The attack surface evolves constantly; monitoring must follow.
You pay only for vulnerabilities validated by CyberAar. Every finding is qualified and genuinely exploitable before any payment is triggered.
Restrict access to a curated set of trusted researchers. Maximum confidentiality for your most sensitive systems.
The CyberAar team triages and qualifies every report before forwarding it. You receive actionable reports, not noise.
Scope
Assets are classified by criticality: business value, data sensitivity, exposure and potential impact of compromise. The more critical the asset, the higher the associated reward.
Researchers
Public and private programmes, rewards proportional to impact, public recognition.
Bounties defined by asset criticality and vulnerability severity. Paid per validated finding.
Top contributors featured on the platform and our pages. Monthly and annual rankings, bonuses for rare findings.
Outstanding hunters receive exclusive CyberAar goodies - in addition to their bounties.
Early access
The platform is under development. Register to be notified first and take part in the launch phase.