SecurityBoat

SecurityBoat Researchers

Hunt where your work gets paid, not filed.

Join SecurityBoat's vetted researcher community and hunt on real programs through TriNetra — where every submission gets a fair triage, every accepted finding earns severity-scored reputation, and every payout runs on rails, not promises.

AECM Corp — Bug Bounty Program

Private● Active
OverviewScopeRewardsFindingsTeamPayoutsActivityLeaderboardCollaboratorsUpdatesChatIntegrations
P1 · Critical$5,000
P2 · High$2,500
P3 · Medium$1,000
P4 · Low$400
P5 · Info$100

Severity-tiered rewards · accepted reports only · CVSS v4.0 scored by the same triage engine as PTaaS

Why hunt here

Built by people who submit reports, not just read them.

TriNetra's Bug Bounty module was built around a simple idea: the researcher experience is the program quality. Sloppy triage, silent rejections, and payout limbo drive good hunters away — so we engineered them out.

Fair, fast triage

Every submission enters a transparent state machine — triage → accepted → fix-in-progress → ready-for-retest → resolved — with a human-readable ID and CVSS v4.0 scoring you can see. No black holes.

Payouts on rails

Rewards resolve automatically from each program's per-severity tiers, then move through approval, verified bank transfer, and tracking — with an auto-generated invoice at the end. Your bank details stay encrypted; your payout dashboard shows exactly where every rupee or dollar is.

Reputation that compounds

Accepted findings earn severity-weighted points that build your rank on live leaderboards and your public profile — a portable record of real, validated work.

A profile that protects you

PII-safe public profiles show your display name, headline, skills, and certifications — with identity-verification and signed-agreement trust badges — and nothing you didn't choose to share.

How it works

Five steps from application to payout.

  1. 01

    Apply

    Tell us who you are and what you hunt. One short form, and a human on the SecurityBoat team reviews every application.

  2. 02

    Get vetted

    We verify identity and review your track record. Sensitive private programs may ask for additional ID or background verification — you'll always know before you opt in.

  3. 03

    Get invited

    Once vetted, invitations open up: private and public bug bounty programs matched to your skills, plus paid PTaaS engagements you can bid on through TriNetra's researcher marketplace.

  4. 04

    Submit

    Report findings straight into the platform: steps to reproduce, evidence, severity. Triage is transparent — duplicates and severity calls are grounded in program history and confirmed by humans.

  5. 05

    Get paid

    Accepted findings resolve their reward from the program's severity tiers and flow through the payout pipeline automatically — approval, verified transfer, tracking, invoice. Reputation points land on the leaderboard at the same time.

The work

Programs, engagements, and disclosure — one platform.

Bug bounty programs

Public, private (invite-only), and points-only VDPs, each scoped to a real asset inventory with rules of engagement and safe-harbor policy published up front. Per-program chat and an announcements feed keep you close to the program team.

Pentest engagements

Vetted researchers can bid on scoped PTaaS engagements across 13 asset classes — web, mobile, API, cloud, network, IoT, and more — and join teams as lead or researcher, with real-time client collaboration built in.

Coordinated disclosure

When a program allows it, resolved findings can go through the coordinated-disclosure workflow and land on public disclosure pages and the hacktivity feed — public proof of your work, on your profile.

What you earn

Pay for impact. Publish with permission.

Programs publish P1–P5 reward tiers up front — payouts resolve automatically from the tier your finding is scored into, never ad hoc negotiation per report. And when a program allows disclosure, two separate approvals stand between your work and the public hacktivity feed.

Severity-tiered rewards · accepted reports only

P1 · Critical$5,000
P2 · High$2,500
P3 · Medium$1,000
P4 · Low$400
P5 · Info$100

Disclosure Requests

AllPending TPMPending ClientPublishedRejected

Server-Side Request Forgery via webhook URL

Priya N. · CVSS 6.5 · awaiting TPM review

MEDIUMPending TPM

IDOR on /api/v2/statements/{id}

@k4rthik · CVSS 8.2 · TPM approved ✓ — your call next

HIGHPending Client

Race condition in wallet balance update

R. Iyer · CVSS 6.5 · View public page →

MEDIUMPublished

Two approvals — TPM, then you — before anything reaches Hacktivity.

Community

The hunt is here. The community is bigger.

Meetups, city chapters, talks, CTFs, and the people behind the handles — SecurityBoat's researcher community lives independently at securityboat.community.

Apply to hunt

One form. A human reads it.

A human on the SecurityBoat team reviews every application by hand. Here's exactly what the form asks — nothing more.

FieldRequired?Notes
Full nameRequiredNever shown publicly — profiles use your display name.
EmailRequiredWhere your decision lands.
UsernameRequiredYour public handle on programs and leaderboards.
LinkedInOptionalLink your professional profile if you'd like.
Years of experienceRequiredFrom under a year to 5+.
SkillsRequired (pick at least one)Web · API · Mobile · Cloud · Network & Infrastructure · AI/LLM · Code Review · Hardware/IoT.

We use this information only to review your application and manage your researcher account. Public profiles are PII-safe by design.

Start hunting

Start where the programs are.

Public programs are open to look at right now — no account needed. One application puts you in the pool for the private ones.