SecurityBoat

TriNetra · Offensive Testing

Always-on hunting. Pay for the bug that mattered.

Run a Vulnerability Disclosure Program or a rewarded Bug Bounty — public or private — with vetted researchers testing your scope continuously. Every submission runs through the same triage engine as PTaaS, every reward maps to a published severity tier, and nothing reaches the public hacktivity feed without two separate approvals.

AECM Corp — Bug Bounty Program

Private● Active
OverviewScopeRewardsFindingsTeamPayoutsActivityLeaderboardCollaboratorsUpdatesChatIntegrations
P1 · Critical$5,000
P2 · High$2,500
P3 · Medium$1,000
P4 · Low$400
P5 · Info$100

Severity-tiered rewards · accepted reports only · CVSS v4.0 scored by the same triage engine as PTaaS


The problem

A scanner runs once a week and a pentest runs once a year. Attackers work on neither schedule — they probe continuously, chain small issues into big ones, and specifically look for business-logic flaws no scanner is programmed to recognize. The gap between "when we last tested" and "what's true right now" is exactly where the costliest, most novel findings live.

How Bug Bounty answers it

Bug Bounty puts a vetted researcher community on that gap permanently, paid only for valid, in-scope findings. Program setup, triage, disclosure, and payouts run in one console — a program is a living object with a real activity log and chat, not a one-time brief you file and forget.

How it actually works

Pay for impact. Publish with permission.

Published P1–P5 reward tiers resolve automatically, and every disclosure clears TPM review and your approval before it reaches Hacktivity.

Severity-tiered rewards · accepted reports only

P1 · Critical$5,000
P2 · High$2,500
P3 · Medium$1,000
P4 · Low$400
P5 · Info$100

Disclosure Requests

AllPending TPMPending ClientPublishedRejected

Server-Side Request Forgery via webhook URL

Priya N. · CVSS 6.5 · awaiting TPM review

MEDIUMPending TPM

IDOR on /api/v2/statements/{id}

@k4rthik · CVSS 8.2 · TPM approved ✓ — your call next

HIGHPending Client

Race condition in wallet balance update

R. Iyer · CVSS 6.5 · View public page →

MEDIUMPublished

Two approvals — TPM, then you — before anything reaches Hacktivity.

Proof the program is real

Hacktivity — published only after two approvals.

Published disclosures carry CVSS, vulnerability class, researcher credit, and publish date. The two-stage gate is visible as distinct states on every disclosure card.

AllPending TPMPending ClientPublishedRejected
MediumCVSS 6.5

Server-Side Request Forgery via webhook URL

Server-Side Request Forgery (CWE-918)

Bug Bounty Program · Priya N. · 21 Jun 2026View →

Capabilities

What ships in the box.

VDP or Bug Bounty, your call

Start with a points-only disclosure channel or go straight to a rewarded program — switch operating models as your program matures.

12-tab program console

Overview, Scope, Rewards, Findings, Team, Payouts, Activity, Leaderboard, Collaborators, Updates, Chat, Integrations — everything a program needs lives in one object.

Published P1–P5 reward tiers

Payouts resolve automatically from the tier a finding is scored into — no ad hoc negotiation per report.

Two-stage disclosure approval

TPM review, then your explicit approval — visible as distinct states on every disclosure card, before anything reaches Hacktivity or a public page.

Real Hacktivity feed

Published disclosures carry CVSS, vulnerability class, researcher credit, and publish date — proof to researchers and prospects alike that your program is active and handled professionally.

Same findings engine as PTaaS

Bounty submissions share triage states, CVSS v4.0 scoring, and remediation routing with every other TriNetra module — one governed record of risk, not a separate silo.

FAQ

Common questions.

A VDP is a points-only channel — researchers report in good faith for reputation, not cash. A Bug Bounty adds monetary rewards resolved from published per-severity tiers (P1 through P5). Many programs start as a private VDP and graduate to a rewarded program without migrating anything.

Put the hunt on your side.

Tell us what you're protecting and we'll help scope a program — VDP or bounty, private or public — with reward tiers that fit your risk and researchers who fit your stack.

Related: Ish · PTaaS · Attack Surface Management · Agentic Pentest