Skip to content
defend.gl

Help and support

Frequently asked questions

Find answers to the questions we get most often about penetration testing, bug bounty, VDP, Safe Harbor, and the Community Fund. If something is missing, we would love to hear from you.

Questions & answers

What we get asked most often

From the difference between penetration testing, bug bounty, and VDP to Safe Harbor and the Community Fund – here we gather the answers so you can quickly find what you are looking for.

Defend.gl connects Greenlandic businesses and public authorities with ethical hackers and security specialists, so vulnerabilities are found and reported responsibly – through penetration testing, bug bounty programmes, and Vulnerability Disclosure Programmes (VDP).

A penetration test is a scoped test carried out at a specific point in time by selected testers. A bug bounty programme is ongoing testing from a wider community of ethical hackers throughout the year, with rewards for approved findings. A VDP is an open, secure channel where security researchers can report vulnerabilities voluntarily, without a reward.

Most organisations start with a penetration test to get a concrete picture of their security. A VDP then provides an official channel for ongoing, voluntary reporting, and a bug bounty programme adds continuous testing with financial incentives once you are ready for it. Contact us and we will find the right order for you.

Safe Harbor is our policy for when security testing is considered authorised and lawful. As long as a researcher tests within the agreed scope, avoids destructive actions, and reports in good faith, we consider the effort protected – and do not threaten legal action against it.

Yes, as long as you follow the Safe Harbor policy and the specific programme's rules: testing only within the defined scope, no destructive actions, and vulnerabilities reported privately to us first.

Contact us and tell us briefly about your systems and needs. Together we will work out whether a penetration test, a VDP, or a bug bounty programme is the right starting point, and put together an offer tailored to your scope.

Contact us to hear about current opportunities. As a researcher on the platform, you must follow our Safe Harbor policy and each programme's rules on scope and reporting.

It depends on scope, system type, and which service makes sense for you. Contact us and we will put together a no-obligation offer tailored to your specific needs.

Use our reporting form. The more detailed a description, step-by-step reproduction, and impact assessment you can provide, the faster we can confirm and act on the finding.

Yes, we advise on NIS2, DORA, GDPR, and ISO 27001, and our testing and reporting structure can feed into the documentation you need to present to a regulator, a customer, or an auditor. We assess your specific situation when you contact us.

The Community Fund reinvests in security testing for Greenlandic organisations that do not have the budget for it themselves – for example NGOs, smaller businesses, and public institutions with limited resources. No profit is taken out of the fund.

Our primary focus is Greenlandic businesses and public authorities, but we also work with organisations that operate in Greenland or have Greenlandic customers. Contact us to hear about your options.

Have more questions?

Contact us directly, or report a vulnerability if you have already found one.