DEFENZ — defenz.org platform bug bounty
- Reports
- 2
- 1st response
- < 1 day
- Rewards
- Jusqu'à 5,000 $
Signed contract + safe harbor · pre-funded escrow · VAT invoice · 48 h acknowledgement and USD payout
Team credentialsWhat every program covers
Every step is timestamped and exportable for your internal audit.
The problem
APIs, subdomains, mobile apps and exposed services change constantly. Without continuous visibility, you can't tell what is actually exposed.
Scanners produce volume, not value. Without human validation and exploitability context, critical fixes drown in noise.
Testing and reporting live in separate tools. Teams collect screenshots instead of using live security activity as ongoing evidence.
Continuous offensive security
From the first test to the final payout, every step is traced.
Continuous hunting inside a contractual scope; you only pay for valid vulnerabilities.
A governed public channel for external reports, with no bounty obligation.
48h acknowledgment, P1–P5 severity validated in 5 days, duplicates grouped, disputes mediated.
Pre-funded escrow; USD payouts within 14 days, with receipts.
Pre-funded escrow · tamper-evident audit log · CSV export
Recent activity
Publicly released reports will appear here after hunter consent and company validation.
Live now
For companies
For researchers
The journey
The company declares its assets and funds escrow. Our team approves before publication.
Researchers test only authorized assets and file structured reports (CVSS, PoC, HTTP requests).
48h acknowledgment, P1–P5 severity validated in 5 days, duplicates grouped.
Fix verified, reward paid in USD within 14 days.
Open hunting or invited researchers, with per-program requirements (KYC, PoC, 2FA).
Only P1–P5 validated reports reach the company; noise is filtered out.
USD vault, 20% commission, receipts and reconciliation.
MTTA, escrow and earnings: every role gets a live space.
Priority sectors
Transparency
Real statistics from the DEFENZ database, reported unfiltered.
The severity breakdown will appear once reports have been triaged.
Legal framework
Every test, state transition and payout is written to an append-only audit log retained 3 years. Personal data is encrypted and coordinated disclosure is the default.
Pricing
The baseline for launching a first programme with submissions.
990USD/ yr
Minimum escrow 750 USD
Recommended for teams that want triage handled for them.
2,490USD/ yr
Minimum escrow 2,500 USD
Everything in Starter, plus:
Researcher coordination, retest and oversight for critical lines.
5,990USD/ yr
Minimum escrow 8,000 USD
Everything in Business, plus:
Unlimited coverage, dedicated TAM and quarterly review.
14,990USD/ yr
Minimum escrow 16,000 USD
Everything in Professional, plus:
Estimating your bounty budget? See the severity ladder (P1–P5) →
Good to know
No scope = no test. Out-of-scope testing is rejected and logged under a contractual safe harbor.
In USD, within 14 days of a verified fix. Funds are pre-funded and escrowed for the life of the program.
An expert team: 48h acknowledgment, severity validated in 5 days. Duplicates are grouped, never penalized.
Encrypted personal data, 3-year audit log, bilingual safe harbor, deletion on request.
SME from 99 USD/month + 20% per reward, or on quote. 249 USD setup, 19.25% VAT extra.
See how DEFENZ discovers your exposure, validates risk, prioritizes remediation and produces audit-ready evidence.
DEFENZ · USD · EUR · XAF · NGN · GHS