Skip to main content
DEFENZ

DEFENZ · Companies

Bug bounty for your company

Pre-funded escrow in USD, managed triage, per-program safe harbor, and researcher payouts within 14 days.

Industries

Banks, telecoms, fintech and the public sector

  • Banks
  • Telecoms
  • Fintech
  • Insurance
  • Public sector
  • E-commerce

Why DEFENZ

What you concretely gain

  • You only pay for validated findings

    An unvalidated report triggers no payment. Severity is assigned by our triage, not self-declared.

  • Our triage team filters the noise

    Duplicates, out-of-scope reports and reports without proof are discarded before they cost you anything.

  • Pre-funded escrow, not an advance

    Funds are locked before testing starts. You never fund research that has no answer yet.

  • Invoice in USD, no FX cost

    No USD/EUR conversion, no international banking fees. Invoice in CFA francs.

Trust centre

What our mechanisms guarantee

Each item below describes a mechanism we operate, not a compliance claim. Evidence is exportable.

  • Pre-funded escrow, reconciled nightly

    Our escrow is credited before a program opens and reconciled daily against payouts and invoices. Any discrepancy blocks disbursements.

  • Append-only audit log, 3 years

    Every transition (submission, triage, verification, payout) is timestamped and immutable. CSV export on request.

  • Bilingual safe harbor per program

    Scope and testing rules are written and accepted before publication, in French and English. Out-of-scope work is neither tested nor paid.

  • Researcher levels L0 → L3

    Phone verification, identity document and enhanced checks. Programs can require 2FA, proof of concept or invitation.

  • Evidence with short-lived signed URLs

    PoC and supporting files stored outside the application server. Read via a 5-minute signed URL, every access logged.

  • Public disclosure under a pseudonym

    Published reports use a masked identifier. The public pseudonym is configurable by the researcher.

Programme reporting

What you get as a program owner

A program-owner dashboard that answers the only question that matters: is my budget being spent well?

Board-ready security metrics, in $.

  • Time to acknowledge

    Time from report opening to acknowledgement.

  • Time to triage

    Time from acknowledgement to validated severity (P1–P5).

  • Escrow utilisation

    Share of escrow already converted into validated rewards.

  • Cost per validated vuln

    Average reward paid per validated report, after commission.

  • Reports by severity

    P1–P5 breakdown of reports received over the period.

  • Duplicates grouped

    Share of reports automatically grouped as duplicates.

  • Retest rate

    Share of fixes verified by a second testing pass.

Metric illustrations: real values appear as soon as a program is running. No data is simulated.

Companies

From day one to the first validated report

  1. D0

    D0 — Contract

    MSA + initial 750 USD escrow.

  2. D1

    D1 — Scope

    URLs, apps, versions + signed authorization letter.

  3. D2

    D2 — Rewards

    P1–P5 USD table + 48h / 5d / 14d SLA.

  4. D3

    D3 — Hunters

    Hunters invited after identity verification (L0 minimum).

  5. D4

    D4 — Public page

    Program live + leaderboard.

  6. D5

    D5 — Dry run

    Test report + 25 USD test payout.

  7. D6

    D6 — Go-live

    Announcement + D7 review (MTTA, alerts).

Ready to launch your programme?

Response within 24 business hours, quoted proposal within 48 hours after the call. Pre-funded escrow before anything goes public.

48-hour acknowledgement · P1–P5 triage in 5 business days · Payout within 14 days of verification.