SecurityBoat

TriNetra · Leaderboard

Ranked by what you find, not how often you show up.

Reputation on TriNetra is computed, not self-reported. Every accepted finding on a program carries a severity score, and a program's leaderboard ranks researchers by total severity points earned from findings that actually cleared validation — a Critical you got right outweighs a stack of Informational submissions that didn't move the needle.

What counts

Only accepted findings move the number.

  • Only accepted findings contribute — submissions still in triage, or rejected as out-of-scope or duplicate, don't count toward your rank.
  • Points scale with severity, so ranking rewards depth of impact over volume of reports.
  • Ranking is computed per program first — each bounty program has its own leaderboard reflecting who's found the most impactful issues on that specific scope.

How ranking works

From submission to rank, in four moves.

01

Finding submitted

A researcher reports a finding on a program.

02

Triage & validation

A human confirms it — duplicates and out-of-scope reports stop here.

03

Severity scored

Accepted findings get a CVSS-based severity — Critical outweighs Informational.

04

Points recomputed

The program's leaderboard updates live from severity-weighted totals.

Inside the product, today

The honest state, shown straight.

app.securityboatone.ai/bug-bounty/leaderboard
Researcher role · in-product

Failed to load leaderboard: Failed to fetch

The in-product leaderboard view is admin-only today. This is the exact state a researcher role sees when opening it — not a placeholder, and not a bug.

The in-product leaderboard view is admin-only in the current build — we'd rather show you that honestly than dress up a mockup with rank numbers and handles that aren't real. What's real is the mechanism above: severity-weighted points, computed live, per program.

Proof, published

Recognition beyond the number.

Accepted, published disclosures are the live proof that recognized work is real — every one clears TPM review, then the client's approval, before it reaches the hacktivity feed. Programs that opt into a hall of fame give top contributors lasting, public recognition tied to their profile — not just a rank that resets when the next program launches.

Disclosure Requests

AllPending TPMPending ClientPublishedRejected

Server-Side Request Forgery via webhook URL

Priya N. · CVSS 6.5 · awaiting TPM review

MEDIUMPending TPM

IDOR on /api/v2/statements/{id}

@k4rthik · CVSS 8.2 · TPM approved ✓ — your call next

HIGHPending Client

Race condition in wallet balance update

R. Iyer · CVSS 6.5 · View public page →

MEDIUMPublished

Two approvals — TPM, then you — before anything reaches Hacktivity.

Beyond any one program

Looking for the full community picture?

Cross-program reputation, writeups, and researcher-to-researcher discussion live at securityboat.community — separate from any single client's program leaderboard.

Start earning rank

Start earning rank.

Browse open bids and see what a listing actually looks like.