SecurityBoat Researchers
Hunt where your work gets paid, not filed.
Join SecurityBoat's vetted researcher community and hunt on real programs through TriNetra — where every submission gets a fair triage, every accepted finding earns severity-scored reputation, and every payout runs on rails, not promises.
AECM Corp — Bug Bounty Program
Private● ActiveSeverity-tiered rewards · accepted reports only · CVSS v4.0 scored by the same triage engine as PTaaS
Why hunt here
Built by people who submit reports, not just read them.
TriNetra's Bug Bounty module was built around a simple idea: the researcher experience is the program quality. Sloppy triage, silent rejections, and payout limbo drive good hunters away — so we engineered them out.
Fair, fast triage
Payouts on rails
Reputation that compounds
A profile that protects you
How it works
Five steps from application to payout.
- 01
Apply
Tell us who you are and what you hunt. One short form, and a human on the SecurityBoat team reviews every application.
- 02
Get vetted
We verify identity and review your track record. Sensitive private programs may ask for additional ID or background verification — you'll always know before you opt in.
- 03
Get invited
Once vetted, invitations open up: private and public bug bounty programs matched to your skills, plus paid PTaaS engagements you can bid on through TriNetra's researcher marketplace.
- 04
Submit
Report findings straight into the platform: steps to reproduce, evidence, severity. Triage is transparent — duplicates and severity calls are grounded in program history and confirmed by humans.
- 05
Get paid
Accepted findings resolve their reward from the program's severity tiers and flow through the payout pipeline automatically — approval, verified transfer, tracking, invoice. Reputation points land on the leaderboard at the same time.
The work
Programs, engagements, and disclosure — one platform.
Bug bounty programs
Pentest engagements
Coordinated disclosure
What you earn
Pay for impact. Publish with permission.
Programs publish P1–P5 reward tiers up front — payouts resolve automatically from the tier your finding is scored into, never ad hoc negotiation per report. And when a program allows disclosure, two separate approvals stand between your work and the public hacktivity feed.
Severity-tiered rewards · accepted reports only
Disclosure Requests
AllPending TPMPending ClientPublishedRejectedServer-Side Request Forgery via webhook URL
Priya N. · CVSS 6.5 · awaiting TPM review
IDOR on /api/v2/statements/{id}
@k4rthik · CVSS 8.2 · TPM approved ✓ — your call next
Race condition in wallet balance update
R. Iyer · CVSS 6.5 · View public page →
Two approvals — TPM, then you — before anything reaches Hacktivity.
Community
The hunt is here. The community is bigger.
Meetups, city chapters, talks, CTFs, and the people behind the handles — SecurityBoat's researcher community lives independently at securityboat.community.
Where to go next
See the marketplace mechanics, in detail.
Apply to hunt
One form. A human reads it.
A human on the SecurityBoat team reviews every application by hand. Here's exactly what the form asks — nothing more.
| Field | Required? | Notes |
|---|---|---|
| Full name | Required | Never shown publicly — profiles use your display name. |
| Required | Where your decision lands. | |
| Username | Required | Your public handle on programs and leaderboards. |
| Optional | Link your professional profile if you'd like. | |
| Years of experience | Required | From under a year to 5+. |
| Skills | Required (pick at least one) | Web · API · Mobile · Cloud · Network & Infrastructure · AI/LLM · Code Review · Hardware/IoT. |
We use this information only to review your application and manage your researcher account. Public profiles are PII-safe by design.
Start hunting
Start where the programs are.
Public programs are open to look at right now — no account needed. One application puts you in the pool for the private ones.
