-
The Bug Bounty Platform is not responsible for any damage or problems
arising from the client's communications or activities with the researcher
or other clients, either through services or other independent transactions.
-
The platform ensures that all reports submitted by the researcher are
checked, verifies their completeness, accuracy, and conformity with the
client's criteria and evaluates them based on the list of rewards and Gaps.
In the case that the researcher violates this, the platform has the right to
make the appropriate decision regarding the report.
-
The platform is responsible for examining the programs that the client
raises them, before they are presented to the researcher, and in the case of
any deficiency, inaccuracy or reliability of any of the programs, the
platform notifies the client of them to modify or enable the platform to
modify them to ensure the protection of all parties from any damage that may
occur as a result the use.
-
The platform takes a preliminary procedure regarding examining the Gaps’s
report submitted by the researcher within (5) to (10) working days, unless
this cannot be caused due to a violation of the will of those responsible
for it.
Needs more info
It means that there is an inquiry and a request from the
evaluation team on the platform, and the researcher must provide the
required information within 7 days, and if there is no response within the
specified period, the report will be closed and considered null and the
researcher does not deserve any reward.
Triage Review
It means that the report is awaiting triage review
and the triage team is obligated to respond within 5 working days, after that it will be move to company review status.
Company Review
It means that the report is awaiting client review, and
the client is obligated to respond within 14 working days, and this case
will be approved. After the verification process of the vulnerability and
before the evaluation of the report in the event that there is any question
of the evaluation team.
Resolved
Means that the report has been approved by the client.
The client shall pay the reward to the researcher (if a reward is specified
in the request).
Not Applicable
It means that the report does not comply with the
policies of the client's request, or that it violated one of its
conditions, or that it does not apply to this request.
Duplicated
Means that the report is redundant and this vulnerability
was previously reported.
Irrelevant severity
It means that the report is less than the risk specified
in the client's request, and the report will not be displayed to the
client until the level of risk specified by him is modified.
Out of scope
Means that the report is outside the range specified by
the client.
Spam
It means that the report is not desirable, and this will
negatively affect the researcher's evaluation, and his account will be
suspended if this is repeated.