Report a vulnerability, get rewarded — €100 to €5,000
CYBORA runs a coordinated-disclosure bug bounty for security researchers. Find a genuine, previously unknown vulnerability in our products, APIs or infrastructure, report it responsibly, and we reward it based on real impact — from €100 for low-severity issues up to €5,000 for infrastructure compromise or a data breach.
How the program works
In scope
CYBORA-operated products, web apps, APIs and cloud infrastructure (cybora.tech, cybora.cloud, audit.cybora.cloud and the CYBORA API). The exact scope and any exclusions are confirmed when you register.
Out of scope
Third-party services we don't control, social engineering of staff, physical attacks, volumetric DoS, and automated-scanner output without a working proof of concept.
Safe harbour
Good-faith research that follows this policy is authorised. We will not pursue legal action, provided you don't access more data than needed, don't degrade service, and don't disclose before we've fixed it.
Fair triage
We acknowledge within 2 business days, validate severity with you, and pay on confirmation of a valid, unique report. First reporter of a duplicate wins.
Rules
Test only your own accounts/data, never exfiltrate real customer data, stop at proof of concept, and give us reasonable time to remediate before any public disclosure.
Recognition
With your permission, valid reporters are credited in our security acknowledgements. Rewards are paid by bank transfer in EUR.
Reward levels — from low to data breach
Final severity and reward are set by CYBORA using CVSS and real-world business impact. Ranges are indicative; exceptional reports can be rewarded above the band.
| Severity | Example | Reward (EUR) |
|---|---|---|
| Low | Minor issues: verbose errors, low-risk misconfigurations, self-only XSS with limited impact. | €100 – €300 |
| Medium | CSRF on meaningful actions, stored XSS, IDOR exposing limited non-sensitive data. | €300 – €800 |
| High | Authentication bypass, privilege escalation, significant access-control failure, SSRF. | €800 – €2,000 |
| Critical | Remote code execution, full account takeover, authentication bypass at scale. | €2,000 – €3,500 |
| Infrastructure compromise | Access to production servers, cloud control plane, secrets or CI/CD pipeline. | €3,000 – €5,000 |
| Data breach | Confirmed access to or exfiltration path for customer / personal data at scale. | up to €5,000 |
How to provide evidence
A good report is reproducible and shows real impact without causing harm. Include enough for us to confirm the issue on the first read.
- A clear title and the affected target (URL, API endpoint, or component) plus environment.
- Step-by-step reproduction instructions a reviewer can follow exactly.
- A minimal proof of concept — request/response, script, or short screen recording.
- Screenshots or a video showing the impact (redact any real personal data).
- Your assessment of severity and the realistic business impact.
- Never exfiltrate, store or share real customer data — demonstrate access, then stop.
- Encrypt sensitive details on request (PGP key available from security@cybora.tech).
How to register and submit
Registration keeps testing authorised and lets us confirm scope before you start.
- Email security@cybora.tech with the subject "Bug Bounty — registration" and your researcher name/handle.
- We reply with the confirmed scope, rules of engagement, and your unique reporter reference.
- Submit each finding as a separate report to security@cybora.tech quoting that reference.
- We acknowledge within 2 business days and agree the severity with you.
- On validation we confirm the reward tier and arrange payment in EUR; you may be credited in our acknowledgements.
- You can also use the support-request form below to start the conversation.
Sehen Sie es in Ihrem eigenen Perimeter
Tell us where you are today. A CYBORA engineer — not a salesperson — will come back with what actually applies to your situation.
- Reply within one business day
- Scoped to your regulatory frameworks
- No obligation, no sales pitch
Take control of your perimeter
Register for a pilot demonstration of the CYBORA GRC and HybridSOC platform. One team, accountable for your full cyber security lifecycle.