Skip to content
defend.gl

Continuous security testing

Bug bounty programme

A bug bounty programme opens your systems to a community of verified ethical hackers who continuously look for vulnerabilities — all year round, not just at the time of a test. You pay a reward for each approved finding, so you only pay for real value.

Continuous security

Security that never takes a break

The threat landscape and your systems keep changing. A test carried out at one point in time says nothing about your security a month later. Bug bounty solves this by turning security testing into an ongoing process rather than a one-off event.

Bug bounty replaces the one-off snapshot with an ongoing community of verified ethical hackers looking for new vulnerabilities all year round — not just when a test happened to be booked.

The programme

How a programme works

All submitted findings are assessed against a shared standard, CVSS for assessing vulnerability severity, so severity and reward stay consistent across reports.

  1. Setup

    We help define scope, programme rules and reward structure together with you.

  2. Launch

    The programme opens as private or public, depending on your need for control and coverage.

  3. Participation

    Verified ethical hackers test your systems within the agreed scope and submit reports when they find something.

  4. Triage

    Incoming reports are validated and prioritised by our team before they reach you.

  5. Payout

    Approved findings are rewarded with a payout that increases with the severity of the vulnerability. Part of the programme's revenue can go to the Community Fund, which funds bug bounty for Greenlandic organisations without their own budget.

The community

Two sides of the same table

For businesses

You set the rules, and pay for results

You choose whether the programme is private or public, define what may be tested, and set the reward structure together with us. You get ongoing test coverage instead of a single snapshot — and only pay once our team has verified a finding. If you'd rather have an open channel for voluntary reporting without rewards, see our Vulnerability Disclosure Program.

For ethical hackers

You get access, coverage and a reward for your findings

Verified researchers get a clearly defined scope to test within, a reward for every approved finding, and Safe Harbor protection when testing takes place within the rules and is reported in good faith.

Included

What a programme includes

Ongoing, verified vulnerability reports as they are found, with an overview of the programme's progress, rewards paid out, and the improvement of your security over time.

Private programme

A closed programme with a selected group of verified ethical hackers that you invite yourself — good for sensitive systems or a cautious start.

Public programme

An open programme, visible to our entire community of ethical hackers, for maximum coverage and more perspectives on your attack surface.

Scope and reward structure

We help define what may be tested, and set rewards that match the severity of the vulnerabilities.

Triage and validation

Our team reviews and verifies every submitted report, so you only see confirmed, reproducible findings.

Safe Harbor for researchers

Ethical hackers who test within the agreed scope and report in good faith are covered by our Safe Harbor policy — giving them legal peace of mind and giving you a broader, more willing community.

Dashboard and overview

One central place with an overview of the programme's status — submitted reports, rewards paid out, and how your security develops over time.

Legal certainty

Peace of mind for both parties

Ethical hackers who test within the agreed scope and report in good faith are covered by our Safe Harbor policy. It gives researchers legal peace of mind to test — and gives you a broader, more willing community to find the vulnerabilities before others do.

Read our Safe Harbor policy
NIS2 GDPR

FAQ

Questions about bug bounty

Contact us for a quote — the price depends on scope and reward structure.

A pentest is a bounded test at a single point in time. Bug bounty is ongoing testing from a broader community, all year round.

You set the reward structure and only pay for approved, verified findings.

Yes. Researchers who test within the agreed scope and report in good faith are covered by our Safe Harbor policy.

The Community Fund is our solidarity initiative, where part of the bug bounty activity helps fund vulnerability testing for Greenlandic organisations without their own security budget.

Start a bug bounty programme

Contact us for a no-obligation quote tailored to your needs.