Help
Frequently asked questions
Everything you need to hunt and launch programs with confidence.
How do I start hunting?
Create a free researcher account, verify your number, read an active program's scope, then submit your first report from the program page. Out-of-scope work is not tested.
What may I test, and what is forbidden?
Only the assets listed in an active program's scope, with the safe-harbor rules accepted. Everything else — other systems, personal data beyond minimal proof, critical infrastructure without authorization — is forbidden.
How are rewards calculated?
Each program shows a P1–P5 scale in USD. The estimate is visible before you submit; payout happens within 14 days of a verified fix.
When will I be paid?
After the verified fix (FIX_VERIFIED status), the team creates the payout and you are notified. Contractual deadline: 14 days maximum after verification.
What are KYC and levels?
L0: account + verified number. L1: checked ID document. L2: enhanced verification. Some programs require L1 or more; your level shows on your public profile.
I am a company: how do I launch a program?
Contact us via the Companies page: scope definition, P1–P5 scale, escrow pre-funding (minimum 750 USD), then review and go-live within 7 days. Approval requires actually funded escrow.
What if my report is a duplicate?
Duplicates are grouped, never penalized: the first valid report is rewarded. The platform flags likely duplicates at submit time.
Where do I report abuse or a flaw in DEFENZ itself?
Via the Contact page (subject: abuse/security). Logs are timestamped (Africa/Douala) and kept 3 years; rights requests are handled within 1 month.
Another question?
Contact us