Social Engineering & Awareness
Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.
Service
We design and run your responsible disclosure and bug bounty program with our own community of researchers.
The challenge
Security researchers find vulnerabilities in all kinds of organizations. Our own consultants have reported flaws to Peruvian and international companies through responsible disclosure.
When an organization has no clear channel, those reports get lost, reach the wrong person or end up published without coordination. A responsible disclosure or bug bounty program turns that outside effort into orderly findings your team can fix.
We help you design, launch and run it with our own community of researchers: from the policy to the validation of every report and the coordination of fixes.
What we do
We start with a disclosure policy and, when your organization is ready, expand it into a program with rewards.
Reporting channel, scope, rules of engagement and safe harbor for good-faith researchers, published along with your security.txt file.
A program with researchers from the Kamaya Secure community, invited based on the scope and technology to assess: full control over who tests your systems.
We receive every report, discard duplicates and false positives, reproduce the vulnerability and rate its severity.
A reward table by severity and support in deciding each payout, within the budget you set.
Timely, professional responses that protect your relationship with the community and your brand’s reputation.
Response and remediation times, findings by severity and the evolution of your attack surface.
How we work
01
We check that your organization can receive and fix findings; if needed, we recommend a penetration test first.
02
We define in- and out-of-scope assets, rules, safe harbor and rewards together with your legal and security teams.
03
We start with a small group of researchers from our community to fine-tune processes before expanding the program.
04
We validate every report and hand it to your team with evidence, severity and a recommendation.
05
We support the fix, verify the solution and keep the researcher informed.
06
We publicly recognize researchers and review the program based on its metrics.
Deliverables
Reference standards
Frequently asked questions
If you have never assessed your systems, start with a penetration test and a disclosure policy without rewards. That way you avoid receiving many basic findings your team cannot keep up with.
A disclosure policy provides a channel and rules for reporting vulnerabilities, usually without payment. A bug bounty adds monetary rewards to encourage participation.
The program precisely defines what can be tested and how, and excludes techniques that could affect operations. The rules and safe harbor should be reviewed with your legal team, considering Peru’s Cybercrime Law No. 30096.
Your organization sets the budget. We propose the reward table and recommend the amount of each payout based on the validated severity.
We trigger a priority response protocol: we validate the finding, alert your team immediately and, if there are signs of exploitation, coordinate with our incident response service.
Other services
Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.
We assess your industrial control systems (IT/OT segmentation, IEC 62443 and NERC CIP) without stopping operations.
We contain the incident, identify the root cause and guide recovery following NIST SP 800-61.
Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.