Community Fund
Security should not only be for those who can afford it
The Community Fund reinvests in shared Greenlandic security. Surplus from Defend.gl's memberships and bounty payouts goes back to organisations that would otherwise not be able to afford having their systems tested – no profit is taken out.
The mission
No profit is taken out
The Community Fund exists because good security must not be reserved for those with the biggest budget. Funds that businesses and ethical hackers contribute through the Defend.gl platform stay within the community: they go on to finance security testing for organisations that would otherwise be left without. No profit is taken out of the fund – the funds go directly towards protecting more organisations.
How it works
From contribution to protection
The fund is topped up on an ongoing basis by contributions from Defend.gl's business customers and by ethical hackers who choose to pass on part of their bounty. When a vulnerability is found at an organisation affiliated with the fund, the bounty is paid out from there – not by the organisation itself.
-
Contribution
Businesses and ethical hackers on the Defend.gl platform contribute to the fund on an ongoing basis.
-
Affiliation
Organisations without the budget for their own bug bounty programme can become affiliated with the fund.
-
Testing
Ethical hackers find and report vulnerabilities at affiliated organisations, just as with regular programmes.
-
Payout
The fund – not the organisation itself – pays the bounty for the vulnerability found.
Who benefits
Organisations with limited resources
The fund is aimed at those who need security testing the most and have the smallest budget for it:
- NGOs and associations working for Greenlandic society without a surplus for a security budget.
- Smaller businesses, for whom a full bug bounty programme would otherwise be out of reach.
- Public institutions with limited resources that nonetheless carry responsibility for sensitive data.
The hackers' role
Built together with the ethical hackers
The Community Fund works because security researchers are willing to spend their time on organisations that cannot pay full price themselves. It happens through the same bug bounty process as the rest of the platform – the same reporting, the same triage, the same Safe Harbor protection – but with the fund as the paying party.
See how bug bounty works at Defend.glWant to be part of the community?
Whether you want to contribute to the fund, or your organisation could benefit from it, we would love to hear from you.