Skip to main content
DEFENZ

Help

Frequently asked questions

Everything you need to hunt and launch programs with confidence.

How do I start hunting?

Create a free researcher account, verify your number, read an active program's scope, then submit your first report from the program page. Out-of-scope work is not tested.

What may I test, and what is forbidden?

Only the assets listed in an active program's scope, with the safe-harbor rules accepted. Everything else — other systems, personal data beyond minimal proof, critical infrastructure without authorization — is forbidden.

How are rewards calculated?

Each program shows a P1–P5 scale in USD. The estimate is visible before you submit; payout happens within 14 days of a verified fix.

When will I be paid?

After the verified fix (FIX_VERIFIED status), the team creates the payout and you are notified. Contractual deadline: 14 days maximum after verification.

What are KYC and levels?

L0: account + verified number. L1: checked ID document. L2: enhanced verification. Some programs require L1 or more; your level shows on your public profile.

I am a company: how do I launch a program?

Contact us via the Companies page: scope definition, P1–P5 scale, escrow pre-funding (minimum 750 USD), then review and go-live within 7 days. Approval requires actually funded escrow.

What if my report is a duplicate?

Duplicates are grouped, never penalized: the first valid report is rewarded. The platform flags likely duplicates at submit time.

Where do I report abuse or a flaw in DEFENZ itself?

Via the Contact page (subject: abuse/security). Logs are timestamped (Africa/Douala) and kept 3 years; rights requests are handled within 1 month.

Another question?

Contact us