// resources / bug bounty

Report a vulnerability, get rewarded — €100 to €5,000

CYBORA runs a coordinated-disclosure bug bounty for security researchers. Find a genuine, previously unknown vulnerability in our products, APIs or infrastructure, report it responsibly, and we reward it based on real impact — from €100 for low-severity issues up to €5,000 for infrastructure compromise or a data breach.

// the program

How the program works

In scope

CYBORA-operated products, web apps, APIs and cloud infrastructure (cybora.tech, cybora.cloud, audit.cybora.cloud and the CYBORA API). The exact scope and any exclusions are confirmed when you register.

Out of scope

Third-party services we don't control, social engineering of staff, physical attacks, volumetric DoS, and automated-scanner output without a working proof of concept.

Safe harbour

Good-faith research that follows this policy is authorised. We will not pursue legal action, provided you don't access more data than needed, don't degrade service, and don't disclose before we've fixed it.

Fair triage

We acknowledge within 2 business days, validate severity with you, and pay on confirmation of a valid, unique report. First reporter of a duplicate wins.

Rules

Test only your own accounts/data, never exfiltrate real customer data, stop at proof of concept, and give us reasonable time to remediate before any public disclosure.

Recognition

With your permission, valid reporters are credited in our security acknowledgements. Rewards are paid by bank transfer in EUR.

// severity levels & rewards

Reward levels — from low to data breach

Final severity and reward are set by CYBORA using CVSS and real-world business impact. Ranges are indicative; exceptional reports can be rewarded above the band.

SeverityExampleReward (EUR)
LowMinor issues: verbose errors, low-risk misconfigurations, self-only XSS with limited impact.€100 – €300
MediumCSRF on meaningful actions, stored XSS, IDOR exposing limited non-sensitive data.€300 – €800
HighAuthentication bypass, privilege escalation, significant access-control failure, SSRF.€800 – €2,000
CriticalRemote code execution, full account takeover, authentication bypass at scale.€2,000 – €3,500
Infrastructure compromiseAccess to production servers, cloud control plane, secrets or CI/CD pipeline.€3,000 – €5,000
Data breachConfirmed access to or exfiltration path for customer / personal data at scale.up to €5,000
// how to provide evidence

How to provide evidence

A good report is reproducible and shows real impact without causing harm. Include enough for us to confirm the issue on the first read.

  • A clear title and the affected target (URL, API endpoint, or component) plus environment.
  • Step-by-step reproduction instructions a reviewer can follow exactly.
  • A minimal proof of concept — request/response, script, or short screen recording.
  • Screenshots or a video showing the impact (redact any real personal data).
  • Your assessment of severity and the realistic business impact.
  • Never exfiltrate, store or share real customer data — demonstrate access, then stop.
  • Encrypt sensitive details on request (PGP key available from security@cybora.tech).
// how to register

How to register and submit

Registration keeps testing authorised and lets us confirm scope before you start.

  • Email security@cybora.tech with the subject "Bug Bounty — registration" and your researcher name/handle.
  • We reply with the confirmed scope, rules of engagement, and your unique reporter reference.
  • Submit each finding as a separate report to security@cybora.tech quoting that reference.
  • We acknowledge within 2 business days and agree the severity with you.
  • On validation we confirm the reward tier and arrange payment in EUR; you may be credited in our acknowledgements.
  • You can also use the support-request form below to start the conversation.
// full support request

Zobacz to na własnym perymetrze

Tell us where you are today. A CYBORA engineer — not a salesperson — will come back with what actually applies to your situation.

  • Reply within one business day
  • Scoped to your regulatory frameworks
  • No obligation, no sales pitch

By submitting you agree to our Privacy Policy.

// protecting what matters most

Take control of your perimeter

Register for a pilot demonstration of the CYBORA GRC and HybridSOC platform. One team, accountable for your full cyber security lifecycle.