CYCLE-BASED VDP
Is the Vulnerability Disclosure Program
charged per cycle?
+
Yes. HACNEX's Vulnerability Disclosure Program uses
a cycle-based pricing model. Each cycle can include
an agreed duration, report allowance and level of
service. The organization can activate another cycle
when the current cycle or allocated report limit is
completed.
CYCLE-BASED VDP
What is included in a VDP cycle?
+
A VDP cycle may include a hosted disclosure page,
approved program scope, researcher submission access,
a defined report allowance and basic report
coordination. The exact services depend on the cycle
selected by the organization.
CYCLE-BASED VDP
What happens when a VDP cycle ends?
+
When the cycle duration or report allowance ends,
the organization can renew or activate another cycle.
If no new cycle is activated, the program may be
paused or disabled so researchers know that new
testing and submissions are not currently accepted.
ALL PROGRAMS
Will HACNEX test our systems without permission?
+
No. HACNEX will not perform or authorize security
testing without written permission, an approved
scope and clearly defined program rules. Researchers
may only test assets explicitly included by your
organization.
MANAGED VDP
What is included in the Managed VDP?
+
Under a Managed VDP, HACNEX receives researcher
submissions, performs an initial review, checks
whether the issue is within scope, identifies obvious
duplicate or invalid reports and coordinates
communication between the researcher and your
organization.
MANAGED VDP
Does HACNEX validate every submitted report?
+
Validation depends on the selected program and service
level. Managed plans can include checks for scope
eligibility, reproduction details, evidence, security
impact and duplicate status before a report is
escalated to the organization.
PRIVATE BUG BOUNTY
Who can participate in a Private Bug Bounty Program?
+
Only researchers invited or approved for the private
program can access its scope and testing instructions.
Your organization can decide the number of researchers,
required experience and other participation conditions.
PRIVATE BUG BOUNTY
Are private program details visible publicly?
+
No. Private program details are shared only with
approved researchers and authorized organization
representatives. Access may be restricted according
to the program rules and confidentiality requirements.
PAY PER VALID BUG
How does the Pay-Per-Valid-Bug Program work?
+
Your organization pays an agreed platform or triage
fee when a security report is confirmed as valid,
unique, within scope and actionable. Invalid,
duplicate, previously known or out-of-scope reports
are handled according to the agreed service terms.
PAY PER VALID BUG
Do we pay for invalid or duplicate reports?
+
Normally, pay-per-valid-bug charges apply only to
reports that meet the agreed validation requirements.
The exact treatment of duplicate, informative,
out-of-scope or previously known reports will be
defined in the service agreement.
REWARDS
Do we have to offer financial bug bounties?
+
No. A Vulnerability Disclosure Program can operate
without monetary researcher rewards. Researchers may
receive acknowledgment, reputation points or another
form of recognition. Financial rewards can be added
when your organization chooses a bug bounty model.
PROGRAM SCOPE
Can we define which systems researchers may test?
+
Yes. Your organization controls the program scope,
including approved domains, applications, APIs and
testing environments. You can also list excluded
assets, prohibited testing methods, rate limits and
data-handling requirements.
REPORT HANDLING
What happens after a researcher submits a report?
+
The report is recorded on the HACNEX platform and
handled according to the selected service. HACNEX may
review the affected asset, reproduction steps, impact,
evidence, scope eligibility and duplicate status
before forwarding or escalating the report.
RESPONSE TIME
How quickly are new reports reviewed?
+
Response targets depend on the selected program and
service agreement. Standard initial review may take
approximately two to three working days. Faster
response targets for critical reports can be included
in managed service plans.
COMMUNICATION
Will researchers communicate directly with our organization?
+
This depends on the program configuration. HACNEX can
act as the communication layer between your organization
and the researcher. Direct communication may also be
permitted when the organization requests it and the
researcher agrees.
PROGRAM CONTROL
Can we pause, update or stop our program?
+
Yes. Your organization can request changes to the
program scope, rules, rewards or availability. A
program can also be paused or disabled so researchers
are informed that new testing and submissions are
temporarily or permanently closed.
PRICING
How does HACNEX charge for its services?
+
HACNEX charges through cycle-based VDP plans,
managed triage services, private bug bounty management,
custom security programs and pay-per-valid-bug fees.
Pricing depends on the selected cycle, report allowance,
program scope and level of management required.