TriNetra · Offensive Testing
Always-on hunting. Pay for the bug that mattered.
Run a Vulnerability Disclosure Program or a rewarded Bug Bounty — public or private — with vetted researchers testing your scope continuously. Every submission runs through the same triage engine as PTaaS, every reward maps to a published severity tier, and nothing reaches the public hacktivity feed without two separate approvals.

The problem
A scanner runs once a week and a pentest runs once a year. Attackers work on neither schedule — they probe continuously, chain small issues into big ones, and specifically look for business-logic flaws no scanner is programmed to recognize. The gap between "when we last tested" and "what's true right now" is exactly where the costliest, most novel findings live.
How Bug Bounty answers it
Bug Bounty puts a vetted researcher community on that gap permanently, paid only for valid, in-scope findings. Program setup, triage, disclosure, and payouts run in one console — a program is a living object with a real activity log and chat, not a one-time brief you file and forget.
How it actually works
A real operating console, not a static brief
Once active, every program opens into 12 tabs — a full operating surface, not a status page.

Rewards run on published tiers
Every accepted submission resolves against a published per-severity tier — no negotiating a payout after the fact.

Disclosure
Nothing publishes without two approvals

Hacktivity shows your program is real
Server-Side Request Forgery via webhook URL
Server-Side Request Forgery (CWE-918)
Capabilities
What ships in the box
VDP or Bug Bounty, your call
12-tab program console
Published P1–P5 reward tiers
Two-stage disclosure approval
Real Hacktivity feed
Same findings engine as PTaaS
Works with
Stronger together
Ish
PTaaS
Attack Surface Management
Agentic Pentest
FAQ
Common questions
What's the difference between a VDP and a Bug Bounty?
A VDP is a points-only channel — researchers report in good faith for reputation, not cash. A Bug Bounty adds monetary rewards resolved from published per-severity tiers (P1 through P5). Many programs start as a private VDP and graduate to a rewarded program without migrating anything.
Do researchers see our program before we're ready?
No. Programs launch private and invite-only if you choose, submissions are gated to invited researchers, and a program only reaches the public directory or Hacktivity once you make it public and a disclosure clears both approval stages.
Who decides what a finding is worth?
Severity is scored via CVSS v4.0 through the same triage engine PTaaS uses, and the payout resolves automatically from the Rewards tab's published tiers — P1 Critical down to P5 Info.
Can a researcher publish a finding without our consent?
No. Every disclosure passes Pending TPM Review, then Pending Client, in that order, before it can reach Published. Rejected disclosures never surface publicly at all.
Put the hunt on your side.
Tell us what you're protecting and we'll help scope a program — VDP or bounty, private or public — with reward tiers that fit your risk and researchers who fit your stack.
Related: Ish · PTaaS · Attack Surface Management · Agentic Pentest
