Closed bug bounty program

We identify the vulnerabilities. You pay per finding.

Hand-picked security researchers hunt for vulnerabilities in your systems around the clock — web applications, APIs, infrastructure, AI, and OT. For every confirmed finding you pay a fixed reward from €800. If we find nothing, you pay nothing.

Operated in GermanyTesters known by nameISO/IEC 27001No finding, no invoice
€0 if we find nothing
only hand-picked testers, known by name
from €800 per confirmed vulnerability, rising with severity
01 — Comparison

Closed or public

Public platforms deliver plenty of volume and little substance. Six points where a closed program differs.

softScheck (closed)Public platform
Testers Hand-picked, vetted, known by nameAnonymous and open to anyone
Cost Only for confirmed findingsPlatform fees plus your own triage effort
Scope Individual, adjustable at any timeStandardized, little flexibility
Reports Pre-qualified, no duplicatesMany duplicates and false positives
Operation and data protection Germany, GDPR, confidentialityOften servers outside the EU
Scope of service On request, all the way to the closed vulnerabilityUsually just passing the report on
02 — Model

A program under your control

We put our testers on your systems permanently. Every reported vulnerability gets verified — you pay for confirmed findings, everything else costs you nothing.

Our own security researchers

Only softScheck security researchers test your systems — certified, experienced, and each with a verified police clearance certificate.

Paid only on findings

No base fee, no platform fee. You pay for every confirmed vulnerability that was not already known to you.

Operated in Germany

The program runs on our own infrastructure in Germany, GDPR-compliant and under a confidentiality agreement.

03 — Scope

What we test

From your web application to AI, OT, and medical technology. What goes in scope is your call.

  • Domains and infrastructure

    We keep a continuous eye on whatever is reachable from outside.

  • Web applications and APIs

    We test to OWASP ASVS: authentication, business logic, injection.

  • AI systems

    LLM and ML systems, tested against the OWASP LLM Top 10 and MITRE ATLAS.

  • Mobile applications

    iOS and Android to OWASP MASVS, including the backend services behind them.

  • IoT devices

    Firmware, communication protocols, and the hardware itself.

  • OT and smart meter gateway

    Industrial control systems and smart meter gateways, tested to IEC 62443.

  • Medical devices

    Security testing within the scope of the MDR, including after market placement.

Further targets by arrangement. We define the exact scope together.

04 — Process

How it works

Scope and rules

Together we set which systems are in scope, when testing happens, which methods are allowed, and what the safe harbor looks like.

Testing runs

Our testers work continuously, with written authorization and complete logs.

Triage

We verify every report, filter out duplicates, and rate severity by CVSS.

Report and reward

You get a reproducible proof of concept, an assessment of the impact, and a concrete remediation proposal. The reward falls due after that.

Fix and retest

On request we support the fix and then retest whether the vulnerability is really closed.

05 — Rewards

Rewards by severity

What a vulnerability is worth depends on how badly it hurts. Payment is per confirmed finding, not per report.

Critical CVSS 9.0 – 10.0 €6,000

e.g. unauthenticated remote code execution on a production system

High CVSS 7.0 – 8.9 €4,000

e.g. authenticated SQL injection with read-only access to individual customer records

Medium CVSS 4.0 – 6.9 €2,000

e.g. cross-site request forgery that lets an attacker change account settings

Low CVSS 0.1 – 3.9 €800

e.g. information leaked in error messages, missing security headers

The first confirmed report per vulnerability is the one that gets paid. Any further report of the same root cause in the same system counts as a duplicate. All amounts plus VAT. Your annual budget is agreed contractually and caps the total of all rewards.

06 — Why softScheck

What sets us apart

Certified testers

Proven offensive security certifications: OSCP+, CPTS, CWES, and CAPE.

In-house team

No open pool of participants: you always know who is working on your systems.

ISO 27001 and GDPR

Certified, operated in Germany, compliant with data protection law.

Own tooling

Tools we built ourselves for red teaming and attack surface monitoring.

07 — Rules

Clear rules for both sides

A binding disclosure policy creates clarity for your company and for the testers.

Defined scope

Which systems may be tested, and with which methods, is settled up front.

Safe harbor

For testing within this policy the client waives legal action. Claims of third parties and statutory provisions remain unaffected.

Fixed deadlines

How fast a report is answered and a fix is delivered is binding.

Coordinated disclosure

Nothing gets published that has not been agreed — with a CVE entry on request.

Disclosure

How disclosure works

Report

Reports come in through a fixed, secured channel.

Confirmation and assessment

We confirm receipt and rate the report per ISO/IEC 30111.

Remediation

The fix lands within the agreed deadline.

Disclosure

Publication is coordinated, per ISO/IEC 29147.

08 — Regulation

Which obligations the program covers

A defined process for handling vulnerabilities pays into several legal requirements — which of them apply to you depends on your industry.

RequirementWhat is requiredWhat the program covers
Cyber Resilience ActA process for disclosing vulnerabilities in products with digital elements. Reporting obligations from 11 September 2026, the full requirements from 11 December 2027.Reporting channel, assessment, and coordinated disclosure. On request we support the reporting deadlines.
NIS2 / BSIGVulnerability management and reporting channels under the German NIS2 Implementation Act (NIS2UmsuCG), in force since December 2025.Continuous testing, documented assessment, and traceable remediation evidence.
EU AI ActTesting the attack resistance of high-risk AI systems.Testing of LLM and ML systems against the OWASP LLM Top 10 and MITRE ATLAS.
MDRIT security of medical devices, including during operation.Security testing after market placement, with reports for your technical documentation.
DORAResilience and security testing in the financial sector.Continuous monitoring of the external attack surface and testing of the applications.
ISO/IEC 29147 and 30111Standards for receiving, handling, and disclosing vulnerabilities.Our disclosure process is aligned with these standards.

The program covers the handling of vulnerabilities — it does not replace a full conformity assessment, for example under the Cyber Resilience Act.

09 — Response (optional)

On request we take on more

We accompany the whole process, from the report to the passed retest.

Full handling

Report, triage, fix, retest — all from a single source.

Escalation

If a vulnerability is actively exploited, we respond immediately.

Reporting deadlines

We support you with the deadlines under the Cyber Resilience Act.

Connection to your systems

We hook into your existing GRC and ticketing processes.

Deadlines

Reporting deadlines under the Cyber Resilience Act

The moment a manufacturer learns of an actively exploited vulnerability, the CRA clock starts — in three stages. We support you on request.

24h early warning
72h initial notification
14 days final report
Contact

Let's talk about your program

In a short intro call we clarify scope, rules, and rewards. No obligation.

  • We clarify which systems belong in scope, what stays excluded, and when testing happens.
  • You get a draft disclosure policy and a reward overview.
  • 30 minutes. Nothing to prepare on your side.

We usually reply within one business day.