We pay security researchers who responsibly disclose valid vulnerabilities in our systems. Find a bug, report it right, earn a reward. Simple.
Rewards are based on the CVSS v3.1 score and confirmed business impact of the vulnerability.
Exceptional reports with novel attack chains or significant business impact may receive additional bonus rewards at our discretion. All rewards are subject to tax withholding as required by Indian law.
| Target | Status | Reward Eligible |
|---|---|---|
| isecintel.com | In Scope | Yes |
| *.isecintel.com (all subdomains) | In Scope | Yes |
| ISec Intel mobile apps | In Scope | Yes |
| ISec Intel internal tools (if accessible) | In Scope | Yes โ bonus |
| Third-party SaaS we use | Out of Scope | No |
| Client environments | Strictly OOS | No |
Valid findings are credited in our Security Hall of Fame with the researcher's permission. Top contributors are featured on our LinkedIn page and may be invited to participate in private programmes.
Our Hall of Fame will be published once the programme receives its first valid submissions. Be the first to claim your spot.
Violation of these rules will result in disqualification and may result in legal action.