Bug Bounty Policy
Purpose and Scope
This Bug Bounty Policy sets the rules researchers must follow when participating in bug bounty programs hosted on Descrimen. The policy applies to all submissions regardless of program.
Programs may publish additional rules in their program briefs. Where a program brief is stricter than this policy, the program brief controls. Where a program brief is more permissive, this policy controls.
Safe Harbor
Descrimen expects programs to grant safe harbor to researchers who conduct research in good faith and in compliance with this policy. Safe harbor means the program will not pursue legal action against a researcher for the act of finding and reporting a vulnerability, provided the researcher followed the rules.
Safe harbor does not protect researchers who violate this policy, who attack out of scope, who exfiltrate data, or who disclose findings in violation of the disclosure section. Safe harbor is a commitment from the program, not a guarantee from Descrimen.
In-Scope Research Only
Only assets explicitly listed in the program brief are in scope. Researchers must not test assets that are out of scope even if those assets are owned by the program. If a researcher is unsure whether an asset is in scope, the researcher must request clarification through the platform before testing.
Testing a third-party dependency is in scope only if the dependency is explicitly listed. Finding an issue in an upstream protocol does not entitle the researcher to a bounty from the downstream program.
Prohibited Methods
The following methods are prohibited regardless of scope:
- Denial of service, including flooding, amplification, and resource exhaustion
- Social engineering of program team members, contractors, or users
- Physical attacks against data centers, offices, or personnel
- Use of malware, ransomware, or persistent backdoors
- Brute forcing of authentication systems in production
- Modification, deletion, or exfiltration of data that does not belong to the researcher
- Use of exploited credentials obtained outside the program
If a researcher accidentally impacts production availability or data, the researcher must stop immediately and report the impact in the submission.
Reporting Timeline
Researchers must submit findings within 24 hours of discovery. The 24-hour window runs from the moment the researcher is confident the vulnerability is reproducible. Earlier submission is encouraged.
If a researcher discovers an active exploit in the wild, the researcher must submit immediately and flag the submission as critical. Descrimen will prioritize triage for submissions flagged as active exploitation.
Findings discovered incidentally while working on a different program must be submitted to the correct program within 24 hours, not held for later use.
Original Work
Submissions must be the original work of the researcher who submits them. Plagiarism is prohibited. This includes copying text from public advisories, prior reports, or another researcher's draft.
If a finding builds on prior public work, the researcher must cite that work in the submission. Failure to cite prior work may result in rejection and forfeit.
A finding that has already been publicly disclosed—by the researcher or anyone else—before the program acknowledges the report is treated as already public. Such findings are not eligible for bounty unless the program brief states otherwise.
Disclosure
Researchers must not publicly disclose a finding until the program agrees in writing. The default disclosure timeline is 90 days from submission. The 90-day clock starts at submission, not at validation.
A program may request an extension. Extensions are granted in 30-day increments up to a maximum of 180 days total. Beyond 180 days, the researcher may disclose unless the program has a valid legal basis to prevent disclosure.
Coordinated disclosure is the expected path. Researchers must share a draft advisory with the program at least 7 days before public release. The program may request redactions for ongoing exploitation risk; redactions are limited to specific technical details, not the existence of the vulnerability.
Validation and Payout
Payout is at program discretion after validation. Validation confirms that the finding is real, in scope, and not a duplicate. Validation timeline is set by the program in the brief.
Programs may downgrade severity during validation. Programs may reject findings that lack proof of impact, that are theoretical, or that have been previously addressed in a fix not yet deployed.
Descrimen charges a 4% fee on validated findings. The fee is deducted at payout. There is no fee for rejected or duplicate findings.
Severity Classification
Programs define their own reward tables. Descrimen uses a standard four-tier severity scale for triage:
- Critical: direct loss of funds, governance takeover, or remote code execution on production assets
- High: conditional loss of funds, privilege escalation, or significant protocol-level impact
- Medium: limited impact, requires specific conditions, or affects non-critical paths
- Low: minor issues, information disclosure, or hardening recommendations
AI triage assigns an initial severity. The program assigns the final severity at validation.
First-to-Find Rule
Only the first submission of a unique bug gets paid. Submissions are ordered by submission timestamp as recorded by Descrimen. Timestamps are recorded at intake, not at the moment of discovery.
A "unique bug" is a single root cause. Variants that share a root cause are treated as the same bug. Researchers who submit variants after the first submission will be informed of duplication without revealing the original researcher's identity.
Duplicate Handling
If two or more researchers submit the same bug, the first submission is eligible for payout. Later submissions are closed as duplicate and receive no reward.
A finding that is a duplicate of an issue already known to the program—in their internal tracker—before the submission timestamp is closed as known. The program must provide evidence of prior knowledge if requested.
Duplicate status does not affect researcher reputation. Researchers who frequently submit duplicates will be prompted to check existing reports before submitting.
Out-of-Scope Findings
Findings outside the declared scope of the program receive no reward. Out-of-scope findings may still be reported through the platform for goodwill, but the program has no obligation to pay.
If a researcher discovers a critical issue in an out-of-scope asset, the researcher should report it to the asset owner directly or via Descrimen's general intake.
AI-Assisted Submissions
Researchers may use AI tools to assist with research, drafting, and review. Submissions that were generated or substantially drafted by AI must be marked as AI-assisted at submission time. Marking is required for transparency and triage accuracy.
Bulk AI-generated submissions that lack manual verification, reproduction, or impact analysis are prohibited under the Acceptable Use Policy. Researchers who flood the queue with low-quality AI output will have submissions rejected and may lose submission privileges.
A submission marked AI-assisted is reviewed on the same standard as a manual submission. AI assistance does not lower the bar for payout, and does not transfer responsibility for accuracy.