SecurityBoat

TriNetra · Offensive Testing

Always-on hunting. Pay for the bug that mattered.

Run a Vulnerability Disclosure Program or a rewarded Bug Bounty — public or private — with vetted researchers testing your scope continuously. Every submission runs through the same triage engine as PTaaS, every reward maps to a published severity tier, and nothing reaches the public hacktivity feed without two separate approvals.

TriNetra Bug Bounty Programs console — the full program list with type, visibility, and status
Programs — 7 live programs across VDP and Bug Bounty, with type, visibility, and status at a glance. · Illustrative sanitized demo data — not customer results.

The problem

A scanner runs once a week and a pentest runs once a year. Attackers work on neither schedule — they probe continuously, chain small issues into big ones, and specifically look for business-logic flaws no scanner is programmed to recognize. The gap between "when we last tested" and "what's true right now" is exactly where the costliest, most novel findings live.

How Bug Bounty answers it

Bug Bounty puts a vetted researcher community on that gap permanently, paid only for valid, in-scope findings. Program setup, triage, disclosure, and payouts run in one console — a program is a living object with a real activity log and chat, not a one-time brief you file and forget.

How it actually works

A real operating console, not a static brief

Once active, every program opens into 12 tabs — a full operating surface, not a status page.

TriNetra Bug Bounty Programs console
Programs console — the real program list with type, visibility, status, and findings counts. · Illustrative sanitized demo data — not customer results.
OverviewScopeRewardsFindingsTeamPayoutsActivityLeaderboardCollaboratorsUpdatesChatIntegrations

Rewards run on published tiers

Every accepted submission resolves against a published per-severity tier — no negotiating a payout after the fact.

Bug Bounty Rewards tab — P1 Critical $5,000 through P5 Info $100
The Rewards tab — real per-severity payout tiers, P1 Critical down to P5 Info. · Illustrative sanitized demo data — not customer results.

Disclosure

Nothing publishes without two approvals

AllPending TPMPending ClientPublishedRejected
TriNetra Disclosure Requests — reports moving through TPM review and client approval
Disclosure Requests — a report visibly moving through TPM review and client approval before it publishes. · Illustrative sanitized demo data — not customer results.

Hacktivity shows your program is real

MediumCVSS 6.5

Server-Side Request Forgery via webhook URL

Server-Side Request Forgery (CWE-918)

Bug Bounty Program · Priya N. · 21 Jun 2026View →

Capabilities

What ships in the box

VDP or Bug Bounty, your call

Start with a points-only disclosure channel or go straight to a rewarded program — switch operating models as your program matures.

12-tab program console

Overview, Scope, Rewards, Findings, Team, Payouts, Activity, Leaderboard, Collaborators, Updates, Chat, Integrations — everything a program needs lives in one object.

Published P1–P5 reward tiers

Payouts resolve automatically from the tier a finding is scored into — no ad hoc negotiation per report.

Two-stage disclosure approval

TPM review, then your explicit approval — visible as distinct states on every disclosure card, before anything reaches Hacktivity or a public page.

Real Hacktivity feed

Published disclosures carry CVSS, vulnerability class, researcher credit, and publish date — proof to researchers and prospects alike that your program is active and handled professionally.

Same findings engine as PTaaS

Bounty submissions share triage states, CVSS v4.0 scoring, and remediation routing with every other TriNetra module — one governed record of risk, not a separate silo.

FAQ

Common questions

What's the difference between a VDP and a Bug Bounty?

A VDP is a points-only channel — researchers report in good faith for reputation, not cash. A Bug Bounty adds monetary rewards resolved from published per-severity tiers (P1 through P5). Many programs start as a private VDP and graduate to a rewarded program without migrating anything.

Do researchers see our program before we're ready?

No. Programs launch private and invite-only if you choose, submissions are gated to invited researchers, and a program only reaches the public directory or Hacktivity once you make it public and a disclosure clears both approval stages.

Who decides what a finding is worth?

Severity is scored via CVSS v4.0 through the same triage engine PTaaS uses, and the payout resolves automatically from the Rewards tab's published tiers — P1 Critical down to P5 Info.

Can a researcher publish a finding without our consent?

No. Every disclosure passes Pending TPM Review, then Pending Client, in that order, before it can reach Published. Rejected disclosures never surface publicly at all.

Put the hunt on your side.

Tell us what you're protecting and we'll help scope a program — VDP or bounty, private or public — with reward tiers that fit your risk and researchers who fit your stack.

Related: Ish · PTaaS · Attack Surface Management · Agentic Pentest