Aller au contenu principal
DEFENZ

Release notes

Release notes

Every shipped change to DEFENZ, dated.

  1. FixDEFENZ-043

    Rewards and escrow in USD

    Reward ladders and escrow are now denominated in USD for every program: per-severity caps and minimum escrows were converted, and the band floors (min..max) left in XAF were reset to zero. A database integrity constraint now rejects any band whose floor exceeds its cap. The XAF pricing and settlement described in earlier entries are therefore superseded.

  2. LaunchDEFENZ-PLA

    DEFENZ.org is live

    First self-hosted bug bounty programme on the defenz.org platform. Cloudflare origin certificate (RFC 9116), pre-funded 1,000,000 XAF escrow, XAF payouts via Mobile Money.

  3. SecurityDEFENZ-041

    Independent pentest report published & remediated

    External audit defenz-org-001 (cact2s): 1 High + 1 Medium + 2 Low + 2 Info. Findings 36, 37, 38 and 39 closed: privileged platform-address reservation, server-side rate limiting, opaque registration errors, internal-field elimination in response body, trimmed /api/health, published /.well-known/security.txt (RFC 9116).

  4. FeatureDEFENZ-033

    Pro hunter workspace (DEFENZ-033 P3)

    Collapsible side icon rail, role-segmented sign-up (hunter / company / staff), separate admin sign-in portal. Lightweight, accessible, low-bandwidth-ready.

  5. FeatureDEFENZ-034

    Cloudflare R2 storage (DEFENZ-034)

    KYC documents, PoC evidence and public logos moved to R2. Short-lived signed URLs, audit log on every access, private-vs-public bucket discipline.

  6. FeatureDEFENZ-035

    Admin panel — profile & KYC review (DEFENZ-035)

    Every researcher now has a detail sheet the staff can open: KYC level, masked identity, alerts, signed documents in read-only.

  7. FeatureDEFENZ-044

    Full KYC submission workflow (DEFENZ-044)

    KYC submission (CNI, passport, selfie) from the hunter profile via 5-minute signed URLs. Staff queue with audit-logged L0→L1/L2 promotion. Profile picture (JPG/PNG/WebP 5 Mo) on the same base. CSP hardened to allow clerk.defenz.org (CSP was blocking Clerk on the custom domain).

  8. FeatureDEFENZ-043

    Reward ranges (DEFENZ-043)

    Every reward band (P1–P5) becomes a min..max XAF range. The defenz.org programme itself: P1 200k–500k, P2 100k–250k, P3 40k–100k. Schema and API extended (rewardMinP1..5).

  9. FeatureDEFENZ-040

    Transparency surfaces (DEFENZ-040)

    Public service status (/fr/status) with db/redis/auth/R2 probes + 30 s cache. Public release notes (/fr/changelog) with generation timeline. /fr/about redirected to /fr/solutions. Dynamic 1200×630 OG image.

In preparation

Planned, undated

These items are committed but not shipped. Nothing here is dated: a date is published only once the feature is in production.

  • End-to-end USD payouts
  • Sandbox environment for API testers
  • OpenAPI / Postman export
  • Public Hall of Fame per programme
  • DEFENZ Hunt Weekend (local CTF)
  • PCI-DSS alignment for payments