TriNetra · Offensive Testing
Always-on hunting. Pay for the bug that mattered.
Run a Vulnerability Disclosure Program or a rewarded Bug Bounty — public or private — with vetted researchers testing your scope continuously. Every submission runs through the same triage engine as PTaaS, every reward maps to a published severity tier, and nothing reaches the public hacktivity feed without two separate approvals.
AECM Corp — Bug Bounty Program
Private● ActiveSeverity-tiered rewards · accepted reports only · CVSS v4.0 scored by the same triage engine as PTaaS
The problem
A scanner runs once a week and a pentest runs once a year. Attackers work on neither schedule — they probe continuously, chain small issues into big ones, and specifically look for business-logic flaws no scanner is programmed to recognize. The gap between "when we last tested" and "what's true right now" is exactly where the costliest, most novel findings live.
How Bug Bounty answers it
Bug Bounty puts a vetted researcher community on that gap permanently, paid only for valid, in-scope findings. Program setup, triage, disclosure, and payouts run in one console — a program is a living object with a real activity log and chat, not a one-time brief you file and forget.
How it actually works
Pay for impact. Publish with permission.
Published P1–P5 reward tiers resolve automatically, and every disclosure clears TPM review and your approval before it reaches Hacktivity.
Severity-tiered rewards · accepted reports only
Disclosure Requests
AllPending TPMPending ClientPublishedRejectedServer-Side Request Forgery via webhook URL
Priya N. · CVSS 6.5 · awaiting TPM review
IDOR on /api/v2/statements/{id}
@k4rthik · CVSS 8.2 · TPM approved ✓ — your call next
Race condition in wallet balance update
R. Iyer · CVSS 6.5 · View public page →
Two approvals — TPM, then you — before anything reaches Hacktivity.
Proof the program is real
Hacktivity — published only after two approvals.
Published disclosures carry CVSS, vulnerability class, researcher credit, and publish date. The two-stage gate is visible as distinct states on every disclosure card.
Server-Side Request Forgery via webhook URL
Server-Side Request Forgery (CWE-918)
Capabilities
What ships in the box.
VDP or Bug Bounty, your call
12-tab program console
Published P1–P5 reward tiers
Two-stage disclosure approval
Real Hacktivity feed
Same findings engine as PTaaS
Works with
Stronger together.
FAQ
Common questions.
A VDP is a points-only channel — researchers report in good faith for reputation, not cash. A Bug Bounty adds monetary rewards resolved from published per-severity tiers (P1 through P5). Many programs start as a private VDP and graduate to a rewarded program without migrating anything.
Put the hunt on your side.
Tell us what you're protecting and we'll help scope a program — VDP or bounty, private or public — with reward tiers that fit your risk and researchers who fit your stack.
Related: Ish · PTaaS · Attack Surface Management · Agentic Pentest
