LIVE

Vulnerability research

AarMe

CyberAar's sovereign bug bounty platform. Submit vulnerabilities, earn validated rewards.

Access the AarMe platform →

Why a bug bounty

An annual penetration test leaves eleven months without active assessment. The attack surface, however, evolves continuously: new dependencies, configuration changes, functional updates, published vulnerabilities in deployed components.

A bug bounty programme fills this gap. Hackers continuously test the defined scope. Every confirmed and exploitable vulnerability is compensated. The result is ongoing assessment by varied profiles, with attack angles our own auditors would not necessarily have covered.

How it works

Scope

Isolated test infrastructure dedicated to the programme. Documented scope: what is in scope, what is not, and the rules of engagement.

Qualification

Every submitted report is reviewed by our technical team. Only vulnerabilities that are confirmed and exploitable within the defined scope qualify for payment.

Compensation

Payment per validated finding. Up to 500,000 FCFA for critical vulnerabilities. The full compensation grid is available on the platform.

Disclosure

90-day remediation window before coordinated disclosure. Hackers are credited in a public register if they wish.

Responsible disclosure

If you have identified a vulnerability on our systems outside the AarMe scope, contact us directly before any publication. We commit to acknowledging receipt within 48 business hours and qualifying the report within ten days.

[email protected]

Join the community

Hacker or organisation, the AarMe platform is open. Sign up or submit a report directly.

Access AarMe Programme rules