A bug bounty with one researcher,
chosen by name.
A public bounty program invites a crowd of strangers to the attack surface, and every severity becomes a negotiation. The private version works differently: one vetted, named, insured researcher – and rules simple enough to fit on this page. And if one researcher sounds like too little – how many of a thousand in a crowd would actually look at your asset?
Ask about the program
How it works
| Step | The private program |
|---|---|
| 1. Establishment | We sign the documents to grant me your official permission to test your assets. Comes with a one-time fee. |
| 2. The find | I search for the vulnerabilities in your system on my own schedule. |
| 3. Delivery | I deliver the discovered high-influence bugs to you by email. |
| 4. Triage | You are free to accept or reject any submission using your own common sense, and I guarantee my openness to discuss the issue. |
| 5. Growth | The asset list grows by mutual consent – no additional payment needed. |
What a finding looks like
The work is one-to-one, so the price follows common sense:
- Low severity issues are not reported under this engagement at all. Polishing is what a pentest is for. Bug bounty exists for indisputably strong issues only.
- The price of a regular finding is usually between $1,000.00 and $3,000.00, depending on what asset we secure.
Note that LSCP does not usually bill by CVSS or Rimpact® severity – although both numbers travel with the report. We suggest a flat fee for vulnerabilities that are worth your attention.
The perfect first engagement
When you pay the bug bounty establishment fee – you trust me in advance, and I highly respect that. When I come back with a vulnerability – I trust you in advance, and I expect no financial liabilities from your side. This approach minimizes risk for both sides and creates a perfect first interaction – in a paper-backed way.
The paperwork
Along with the standard NDA/MSA, we sign a one-page document that outlines the asset list, the access conditions, and the rules of engagement.
Ask about the programAnd when the Private Bug Bounty is not enough
A private bounty guarantees my proactivity – on my schedule; however it guarantees neither availability nor coverage. To guarantee my availability whenever you need me – consider Advisory. For the comprehensive testing coverage – consider Penetration Testing.
At the same time – keep growing your own cybersecurity awareness:
- For tactical growth – The Security Spirit® daily video series
- For strategic, evergreen cybersecurity topics – EXP Lore Cyber® irregular podcast
- For ongoing Threat Intelligence trends – The LSCP Newsletter, monthly
- For technical hands-on skills – The Responsible Disclosure Lab (RSS feed)