PUBLIC VDP · PLAN 3
How HACNEX Public VDP Works
HACNEX provides an independent responsible-disclosure channel that allows
security researchers to report vulnerabilities identified during authorized
security testing, including to companies that do not already have a HACNEX
account or paid program.
Authorized security testing
→
Vulnerability identified
→
HACNEX submission
→
PGP encrypted
→
Company Security Email
→
Admin review
Authorization Required
HACNEX does not grant testing permission
This public VDP is a reporting channel, not an authorization mechanism.
A HACNEX account or submission does not give permission to test a company,
website, application, API, or infrastructure.
Researchers must obtain appropriate authorization before performing
security testing and are responsible for complying with applicable law,
applicable security policies, and the target's disclosure requirements.
HACNEX RESEARCHER COMPETITION
200 companies will be available for the competition
The upcoming HACNEX Researcher Competition is planned to include up to
200 participating companies. Registered researchers will
be notified when the participating-company directory and applicable
reporting scopes are published.
Once a company is officially published as active for the competition,
researchers can open its listing, review the authorized scope and
reporting requirements, and use the designated report flow.
For Researchers
What can a researcher use this for?
A researcher can use the public form when they identify a security
vulnerability during authorized security testing and want a structured
way to notify the affected company.
- Enter the company and affected URL.
- Provide the company's Security Email.
- Provide the company's PGP public key.
- Submit the vulnerability with reproduction and impact details.
Security
What does HACNEX do?
HACNEX verifies the supplied PGP key with GnuPG and encrypts the sensitive
vulnerability package before persistent storage and delivery.
The company receives the encrypted report at the Security Email supplied
for that particular submission. Replies can be associated with the HACNEX
submission thread.
For Companies
What advantage does the company get?
A company can receive security research without first joining a paid HACNEX
program. The researcher supplies the destination Security Email and the
company's PGP public key, allowing the report to be routed directly to the
intended security contact.
This gives companies another reporting channel for responsible disclosure
and helps them receive reports from researchers conducting authorized
security testing.
Researcher Rewards
3-Month HACNEX Researcher Competition
During each three-month competition period, researchers with the highest
eligible HACNEX points may receive cash prizes. Points are subject to
HACNEX administrative validation; submitting a report alone does not
automatically award points or payment.
Rewards are subject to eligibility requirements, validated points,
competition rules, and the published reward terms.
Competition duration: 3 months
Participating companies: up to 200
Researcher swag: first 50 valid reporters
TOTAL COMPETITION PRIZE POOL
₹1,50,000
Prize allocation and eligibility will follow the published competition terms.
Typical Researcher Flow
1. Authorization
Confirm that you are authorized to perform security testing against
the target.
2. Find
Identify a security vulnerability during the authorized testing.
3. Prepare
Collect the company website, affected URL, Security Email and PGP
public key.
4. Verify
Use the PGP verification button to confirm that the supplied key is
valid and encryption-capable.
5. Submit
Log in or create a researcher account and submit the report.
What the Company Receives
Direct delivery
The encrypted report is sent to the Security Email supplied for that
submission.
PGP protection
The confidential vulnerability package is encrypted for the supplied
company PGP key.
HACNEX context
The email explains that a security researcher used the HACNEX public
submission form and includes the submission reference.
Admin Review
Validation comes first
HACNEX administration can review the submission and determine whether
it qualifies for points, rewards, or another status under the applicable
rules.
No automatic scoring
A report does not receive points simply because it was submitted.
No testing authorization
HACNEX review or acceptance of a report does not provide authorization
to continue testing the target.
Important
Responsible disclosure
Researchers must only test systems they are authorized to test and should
follow applicable law and the target's published disclosure rules.
HACNEX is an independent reporting intermediary and does not grant
permission to test any company, website, application, API, or
infrastructure. HACNEX does not represent the target company and cannot
guarantee acceptance, remediation, payment, or any action by the company.
Ready to submit?
Use the public Plan 3 submission form after confirming that your testing
was authorized. You can open the form and fill in the fields before
logging in; an authenticated researcher account is required when the
report is actually submitted.
Go to Public VDP Submission