DEFENZ · Companies
Bug bounty for your company
Pre-funded escrow in USD, managed triage, per-program safe harbor, and researcher payouts within 14 days.
Industries
Banks, telecoms, fintech and the public sector
- Banks
- Telecoms
- Fintech
- Insurance
- Public sector
- E-commerce
Why DEFENZ
What you concretely gain
You only pay for validated findings
An unvalidated report triggers no payment. Severity is assigned by our triage, not self-declared.
Our triage team filters the noise
Duplicates, out-of-scope reports and reports without proof are discarded before they cost you anything.
Pre-funded escrow, not an advance
Funds are locked before testing starts. You never fund research that has no answer yet.
Invoice in USD, no FX cost
No USD/EUR conversion, no international banking fees. Invoice in CFA francs.
Trust centre
What our mechanisms guarantee
Each item below describes a mechanism we operate, not a compliance claim. Evidence is exportable.
Pre-funded escrow, reconciled nightly
Our escrow is credited before a program opens and reconciled daily against payouts and invoices. Any discrepancy blocks disbursements.
Append-only audit log, 3 years
Every transition (submission, triage, verification, payout) is timestamped and immutable. CSV export on request.
Bilingual safe harbor per program
Scope and testing rules are written and accepted before publication, in French and English. Out-of-scope work is neither tested nor paid.
Researcher levels L0 → L3
Phone verification, identity document and enhanced checks. Programs can require 2FA, proof of concept or invitation.
Evidence with short-lived signed URLs
PoC and supporting files stored outside the application server. Read via a 5-minute signed URL, every access logged.
Public disclosure under a pseudonym
Published reports use a masked identifier. The public pseudonym is configurable by the researcher.
Programme reporting
What you get as a program owner
A program-owner dashboard that answers the only question that matters: is my budget being spent well?
Board-ready security metrics, in $.
Time to acknowledge
Time from report opening to acknowledgement.
Time to triage
Time from acknowledgement to validated severity (P1–P5).
Escrow utilisation
Share of escrow already converted into validated rewards.
Cost per validated vuln
Average reward paid per validated report, after commission.
Reports by severity
P1–P5 breakdown of reports received over the period.
Duplicates grouped
Share of reports automatically grouped as duplicates.
Retest rate
Share of fixes verified by a second testing pass.
Metric illustrations: real values appear as soon as a program is running. No data is simulated.
Companies
From day one to the first validated report
- D0
D0 — Contract
MSA + initial 750 USD escrow.
- D1
D1 — Scope
URLs, apps, versions + signed authorization letter.
- D2
D2 — Rewards
P1–P5 USD table + 48h / 5d / 14d SLA.
- D3
D3 — Hunters
Hunters invited after identity verification (L0 minimum).
- D4
D4 — Public page
Program live + leaderboard.
- D5
D5 — Dry run
Test report + 25 USD test payout.
- D6
D6 — Go-live
Announcement + D7 review (MTTA, alerts).
Ready to launch your programme?
Response within 24 business hours, quoted proposal within 48 hours after the call. Pre-funded escrow before anything goes public.
48-hour acknowledgement · P1–P5 triage in 5 business days · Payout within 14 days of verification.