Skip to content
Client access

Service

Bug Bounty & Vulnerability Disclosure

We design and run your responsible disclosure and bug bounty program with our own community of researchers.

Automation
Every report is checked against your program’s authorized scope, so out-of-scope submissions don’t take up your team’s time.
Human validation
Our pentesters reproduce every report and confirm its severity before it reaches you.

The challenge

Someone is already looking for vulnerabilities in your systems. Can you receive their reports?

Security researchers find vulnerabilities in all kinds of organizations. Our own consultants have reported flaws to Peruvian and international companies through responsible disclosure.

When an organization has no clear channel, those reports get lost, reach the wrong person or end up published without coordination. A responsible disclosure or bug bounty program turns that outside effort into orderly findings your team can fix.

We help you design, launch and run it with our own community of researchers: from the policy to the validation of every report and the coordination of fixes.

What we do

A complete program, from policy to reward

We start with a disclosure policy and, when your organization is ready, expand it into a program with rewards.

Responsible disclosure policy

Reporting channel, scope, rules of engagement and safe harbor for good-faith researchers, published along with your security.txt file.

Private bug bounty

A program with researchers from the Kamaya Secure community, invited based on the scope and technology to assess: full control over who tests your systems.

Triage and validation

We receive every report, discard duplicates and false positives, reproduce the vulnerability and rate its severity.

Reward management

A reward table by severity and support in deciding each payout, within the budget you set.

Researcher communication

Timely, professional responses that protect your relationship with the community and your brand’s reputation.

Program metrics

Response and remediation times, findings by severity and the evolution of your attack surface.

How we work

A gradual, controlled launch

01

Readiness assessment

We check that your organization can receive and fix findings; if needed, we recommend a penetration test first.

02

Policy and scope design

We define in- and out-of-scope assets, rules, safe harbor and rewards together with your legal and security teams.

03

Private launch

We start with a small group of researchers from our community to fine-tune processes before expanding the program.

04

Continuous triage

We validate every report and hand it to your team with evidence, severity and a recommendation.

05

Fix coordination

We support the fix, verify the solution and keep the researcher informed.

06

Recognition and improvement

We publicly recognize researchers and review the program based on its metrics.

Deliverables

An orderly channel for the security community

Reference standards

  • ISO/IEC 29147
  • ISO/IEC 30111
  • RFC 9116 (security.txt)
  • CVSS
  • Published disclosure policyA public document with scope, rules, safe harbor and reporting channel, plus your security.txt file.
  • Rules and reward tableEligibility criteria and amounts by severity, agreed with your organization.
  • Validated findings reportsEvery confirmed vulnerability with evidence, severity and remediation guidance.
  • Internal procedureA workflow for receiving, triaging, fixing and closing reports for your teams.
  • Metrics dashboardProgram indicators for leadership and for the technical team.
  • Recognition pageA Hall of Fame to publicly thank the researchers who contribute.

Frequently asked questions

What clients usually ask before we start

Is my organization ready for a bug bounty?

If you have never assessed your systems, start with a penetration test and a disclosure policy without rewards. That way you avoid receiving many basic findings your team cannot keep up with.

What is the difference between a disclosure policy and a bug bounty?

A disclosure policy provides a channel and rules for reporting vulnerabilities, usually without payment. A bug bounty adds monetary rewards to encourage participation.

Is it safe to let outsiders test our systems?

The program precisely defines what can be tested and how, and excludes techniques that could affect operations. The rules and safe harbor should be reviewed with your legal team, considering Peru’s Cybercrime Law No. 30096.

Who pays the rewards?

Your organization sets the budget. We propose the reward table and recommend the amount of each payout based on the validated severity.

What happens if someone reports a critical vulnerability?

We trigger a priority response protocol: we validate the finding, alert your team immediately and, if there are signs of exploitation, coordinate with our incident response service.

Other services

A comprehensive view of your security

Social Engineering & Awareness

Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.

OT/ICS Security

We assess your industrial control systems (IT/OT segmentation, IEC 62443 and NERC CIP) without stopping operations.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)