SERVICES / BUG BOUNTY & DISCLOSURE
Researchers will find your bugs. Give them a front door.
Security researchers probe internet-facing systems whether you invite them or not. A disclosure program turns that from a liability into free coverage: a legal path to report, clear scope, and a team that answers. We build and run these programs — and we know both sides, because we hunt too.
Engagement details
We're on the researcher side of this every week
Hash researchers have been acknowledged for responsibly disclosed vulnerabilities by Microsoft, Google, OpenAI, PayPal, NASA, Duolingo, and Île-de-France Mobilités. When we design your program, we know exactly what makes researchers report properly instead of tweeting.
What we set up for you
- Policy and safe harbor.A disclosure policy that protects good-faith researchers and your company, plus security.txt so reports reach the right inbox.
- Scope and rewards.What's in, what's out, and what a finding is worth — sized to your budget, from thanks-and-hall-of-fame to paid bounties.
- Triage.We validate incoming reports, kill the duplicates and the noise, and hand your team only what's real — with severity and fix guidance.
- Platform or self-hosted.We run both: your program on an established bounty platform, or a lightweight self-hosted flow. Whichever fits your size and budget.
Who this is for
Any company in Lebanon or MENA with users on the internet. Banks and fintechs get regulatory pressure to have one; startups get world-class testing they couldn't hire; everyone gets to hear about their worst bug from a researcher instead of an incident.
Common questions
- Isn't this just a pentest?
No — they complement. A pentest is a bounded engagement with guaranteed coverage of a scope. A disclosure program is continuous, unbounded, and pay-per-result. Mature security programs run both.
- What if we can't afford big bounties?
Start with a vulnerability disclosure program: no bounties, just recognition and a clear process. Researchers report to VDPs every day. Add rewards when you're ready.
- Won't we drown in reports?
That's what triage is for. We sit between you and the inbox — your engineers only ever see validated, deduplicated, severity-ranked findings.
- Is this legal in Lebanon?
Yes — a well-written policy defines authorized testing and protects both sides. That policy is the first thing we write.
Programs designed by researchers acknowledged by Microsoft, Google, OpenAI, and NASA.
Open the front door.
We'll design a program your budget can sustain and your engineers won't hate.
Request a briefing