HackMe Programme

Programme rules

HackMe connects organisations and security researchers within a clear framework that protects all parties. Please read these rules before any testing.

Scope

Each organisation publishes its own scope when launching a programme. The rules below apply by default across the entire platform.

Allowed

  • Testing on assets explicitly listed in the programme
  • Fuzzing, injection, attack surface analysis within the defined scope
  • Non-destructive evidence collection (screenshots, logs)
  • Access using a test account provided or created for that purpose

Prohibited

  • Testing outside the scope defined by the organisation
  • Denial-of-service attacks (DoS/DDoS)
  • Accessing, modifying or deleting real data
  • Social engineering of employees or customers
  • Sharing the vulnerability before it is fixed

How to submit a report

01

Reproduce

Reliably reproduce the vulnerability before submitting. A non-reproducible report cannot be qualified.

02

Document

Description, reproduction steps, screenshots or video, estimated impact, CVSS reference if applicable.

03

Submit

Via the platform submission interface. An automatic acknowledgement is sent immediately.

04

Wait

CyberAar validates the report within 5 business days. No public disclosure before the fix and agreement of all parties.

Classification and rewards

Bounties are set by each organisation based on the criticality of the affected asset and the severity of the vulnerability. The indicative ranges below apply to standard programmes.

Severity CVSS Indicative range
Critical 9.0 – 10.0 150,000 – 500,000 CFA
High 7.0 – 8.9 50,000 – 150,000 CFA
Medium 4.0 – 6.9 15,000 – 50,000 CFA
Low 0.1 – 3.9 HoF recognition

Final rewards are set by the organisation and validated by CyberAar. Duplicates are not rewarded.

Our commitments

24 business hours

Automatic acknowledgement upon submission.

5 business days

First assessment and severity qualification.

Coordinated

No public disclosure without your agreement.

Within 30 days

Fix for Critical and High severity vulnerabilities.

Legal safe harbor

Researchers acting in good faith, within the bounds of these rules and the scope defined by the organisation, will not face any legal action from CyberAar. We are committed to working with our partner organisations to extend this protection to valid reports submitted through the platform. Safe harbor protection does not cover deliberate access or actions outside the defined scope.

The platform is live. Sign up or submit a vulnerability report directly.

Join the platform Submit a vuln