PUBLIC VDP · PLAN 3

How HACNEX Public VDP Works

HACNEX provides an independent responsible-disclosure channel that allows security researchers to report vulnerabilities identified during authorized security testing, including to companies that do not already have a HACNEX account or paid program.

Authorized security testing → Vulnerability identified → HACNEX submission → PGP encrypted → Company Security Email → Admin review
Authorization Required

HACNEX does not grant testing permission

This public VDP is a reporting channel, not an authorization mechanism. A HACNEX account or submission does not give permission to test a company, website, application, API, or infrastructure.

Researchers must obtain appropriate authorization before performing security testing and are responsible for complying with applicable law, applicable security policies, and the target's disclosure requirements.

HACNEX RESEARCHER COMPETITION

200 companies will be available for the competition

The upcoming HACNEX Researcher Competition is planned to include up to 200 participating companies. Registered researchers will be notified when the participating-company directory and applicable reporting scopes are published.

Once a company is officially published as active for the competition, researchers can open its listing, review the authorized scope and reporting requirements, and use the designated report flow.

View Competition Companies →
For Researchers

What can a researcher use this for?

A researcher can use the public form when they identify a security vulnerability during authorized security testing and want a structured way to notify the affected company.

  • Enter the company and affected URL.
  • Provide the company's Security Email.
  • Provide the company's PGP public key.
  • Submit the vulnerability with reproduction and impact details.
Security

What does HACNEX do?

HACNEX verifies the supplied PGP key with GnuPG and encrypts the sensitive vulnerability package before persistent storage and delivery.

The company receives the encrypted report at the Security Email supplied for that particular submission. Replies can be associated with the HACNEX submission thread.

For Companies

What advantage does the company get?

A company can receive security research without first joining a paid HACNEX program. The researcher supplies the destination Security Email and the company's PGP public key, allowing the report to be routed directly to the intended security contact.

This gives companies another reporting channel for responsible disclosure and helps them receive reports from researchers conducting authorized security testing.

Researcher Rewards

3-Month HACNEX Researcher Competition

During each three-month competition period, researchers with the highest eligible HACNEX points may receive cash prizes. Points are subject to HACNEX administrative validation; submitting a report alone does not automatically award points or payment.

Rewards are subject to eligibility requirements, validated points, competition rules, and the published reward terms.

Competition duration: 3 months
Participating companies: up to 200
Researcher swag: first 50 valid reporters
TOTAL COMPETITION PRIZE POOL
₹1,50,000
Prize allocation and eligibility will follow the published competition terms.
Typical Researcher Flow

1. Authorization

Confirm that you are authorized to perform security testing against the target.

2. Find

Identify a security vulnerability during the authorized testing.

3. Prepare

Collect the company website, affected URL, Security Email and PGP public key.

4. Verify

Use the PGP verification button to confirm that the supplied key is valid and encryption-capable.

5. Submit

Log in or create a researcher account and submit the report.

What the Company Receives

Direct delivery

The encrypted report is sent to the Security Email supplied for that submission.

PGP protection

The confidential vulnerability package is encrypted for the supplied company PGP key.

HACNEX context

The email explains that a security researcher used the HACNEX public submission form and includes the submission reference.

Admin Review

Validation comes first

HACNEX administration can review the submission and determine whether it qualifies for points, rewards, or another status under the applicable rules.

No automatic scoring

A report does not receive points simply because it was submitted.

No testing authorization

HACNEX review or acceptance of a report does not provide authorization to continue testing the target.

Important

Responsible disclosure

Researchers must only test systems they are authorized to test and should follow applicable law and the target's published disclosure rules.

HACNEX is an independent reporting intermediary and does not grant permission to test any company, website, application, API, or infrastructure. HACNEX does not represent the target company and cannot guarantee acceptance, remediation, payment, or any action by the company.

Ready to submit?

Use the public Plan 3 submission form after confirming that your testing was authorized. You can open the form and fill in the fields before logging in; an authenticated researcher account is required when the report is actually submitted.

Go to Public VDP Submission