Vulnerability research
AarMe
CyberAar's sovereign bug bounty platform. Submit vulnerabilities, earn validated rewards.
Access the AarMe platform →Why a bug bounty
An annual penetration test leaves eleven months without active assessment. The attack surface, however, evolves continuously: new dependencies, configuration changes, functional updates, published vulnerabilities in deployed components.
A bug bounty programme fills this gap. Hackers continuously test the defined scope. Every confirmed and exploitable vulnerability is compensated. The result is ongoing assessment by varied profiles, with attack angles our own auditors would not necessarily have covered.
How it works
Isolated test infrastructure dedicated to the programme. Documented scope: what is in scope, what is not, and the rules of engagement.
Every submitted report is reviewed by our technical team. Only vulnerabilities that are confirmed and exploitable within the defined scope qualify for payment.
Payment per validated finding. Up to 500,000 FCFA for critical vulnerabilities. The full compensation grid is available on the platform.
90-day remediation window before coordinated disclosure. Hackers are credited in a public register if they wish.
Responsible disclosure
If you have identified a vulnerability on our systems outside the AarMe scope, contact us directly before any publication. We commit to acknowledging receipt within 48 business hours and qualifying the report within ten days.
[email protected]Join the community
Hacker or organisation, the AarMe platform is open. Sign up or submit a report directly.