We identify the vulnerabilities. You pay per finding.
Hand-picked security researchers hunt for vulnerabilities in your systems around the clock — web applications, APIs, infrastructure, AI, and OT. For every confirmed finding you pay a fixed reward from €800. If we find nothing, you pay nothing.
Closed or public
Public platforms deliver plenty of volume and little substance. Six points where a closed program differs.
| softScheck (closed) | Public platform | |
|---|---|---|
| Testers | Hand-picked, vetted, known by name | Anonymous and open to anyone |
| Cost | Only for confirmed findings | Platform fees plus your own triage effort |
| Scope | Individual, adjustable at any time | Standardized, little flexibility |
| Reports | Pre-qualified, no duplicates | Many duplicates and false positives |
| Operation and data protection | Germany, GDPR, confidentiality | Often servers outside the EU |
| Scope of service | On request, all the way to the closed vulnerability | Usually just passing the report on |
A program under your control
We put our testers on your systems permanently. Every reported vulnerability gets verified — you pay for confirmed findings, everything else costs you nothing.
Our own security researchers
Only softScheck security researchers test your systems — certified, experienced, and each with a verified police clearance certificate.
Paid only on findings
No base fee, no platform fee. You pay for every confirmed vulnerability that was not already known to you.
Operated in Germany
The program runs on our own infrastructure in Germany, GDPR-compliant and under a confidentiality agreement.
What we test
From your web application to AI, OT, and medical technology. What goes in scope is your call.
Domains and infrastructure
We keep a continuous eye on whatever is reachable from outside.
Web applications and APIs
We test to OWASP ASVS: authentication, business logic, injection.
AI systems
LLM and ML systems, tested against the OWASP LLM Top 10 and MITRE ATLAS.
Mobile applications
iOS and Android to OWASP MASVS, including the backend services behind them.
IoT devices
Firmware, communication protocols, and the hardware itself.
OT and smart meter gateway
Industrial control systems and smart meter gateways, tested to IEC 62443.
Medical devices
Security testing within the scope of the MDR, including after market placement.
Further targets by arrangement. We define the exact scope together.
How it works
Scope and rules
Together we set which systems are in scope, when testing happens, which methods are allowed, and what the safe harbor looks like.
Testing runs
Our testers work continuously, with written authorization and complete logs.
Triage
We verify every report, filter out duplicates, and rate severity by CVSS.
Report and reward
You get a reproducible proof of concept, an assessment of the impact, and a concrete remediation proposal. The reward falls due after that.
Fix and retest
On request we support the fix and then retest whether the vulnerability is really closed.
Rewards by severity
What a vulnerability is worth depends on how badly it hurts. Payment is per confirmed finding, not per report.
e.g. unauthenticated remote code execution on a production system
e.g. authenticated SQL injection with read-only access to individual customer records
e.g. cross-site request forgery that lets an attacker change account settings
e.g. information leaked in error messages, missing security headers
The first confirmed report per vulnerability is the one that gets paid. Any further report of the same root cause in the same system counts as a duplicate. All amounts plus VAT. Your annual budget is agreed contractually and caps the total of all rewards.
What sets us apart
Certified testers
Proven offensive security certifications: OSCP+, CPTS, CWES, and CAPE.
In-house team
No open pool of participants: you always know who is working on your systems.
ISO 27001 and GDPR
Certified, operated in Germany, compliant with data protection law.
Own tooling
Tools we built ourselves for red teaming and attack surface monitoring.
Clear rules for both sides
A binding disclosure policy creates clarity for your company and for the testers.
Defined scope
Which systems may be tested, and with which methods, is settled up front.
Safe harbor
For testing within this policy the client waives legal action. Claims of third parties and statutory provisions remain unaffected.
Fixed deadlines
How fast a report is answered and a fix is delivered is binding.
Coordinated disclosure
Nothing gets published that has not been agreed — with a CVE entry on request.
How disclosure works
Report
Reports come in through a fixed, secured channel.
Confirmation and assessment
We confirm receipt and rate the report per ISO/IEC 30111.
Remediation
The fix lands within the agreed deadline.
Disclosure
Publication is coordinated, per ISO/IEC 29147.
Which obligations the program covers
A defined process for handling vulnerabilities pays into several legal requirements — which of them apply to you depends on your industry.
| Requirement | What is required | What the program covers |
|---|---|---|
| Cyber Resilience Act | A process for disclosing vulnerabilities in products with digital elements. Reporting obligations from 11 September 2026, the full requirements from 11 December 2027. | Reporting channel, assessment, and coordinated disclosure. On request we support the reporting deadlines. |
| NIS2 / BSIG | Vulnerability management and reporting channels under the German NIS2 Implementation Act (NIS2UmsuCG), in force since December 2025. | Continuous testing, documented assessment, and traceable remediation evidence. |
| EU AI Act | Testing the attack resistance of high-risk AI systems. | Testing of LLM and ML systems against the OWASP LLM Top 10 and MITRE ATLAS. |
| MDR | IT security of medical devices, including during operation. | Security testing after market placement, with reports for your technical documentation. |
| DORA | Resilience and security testing in the financial sector. | Continuous monitoring of the external attack surface and testing of the applications. |
| ISO/IEC 29147 and 30111 | Standards for receiving, handling, and disclosing vulnerabilities. | Our disclosure process is aligned with these standards. |
The program covers the handling of vulnerabilities — it does not replace a full conformity assessment, for example under the Cyber Resilience Act.
On request we take on more
We accompany the whole process, from the report to the passed retest.
Full handling
Report, triage, fix, retest — all from a single source.
Escalation
If a vulnerability is actively exploited, we respond immediately.
Reporting deadlines
We support you with the deadlines under the Cyber Resilience Act.
Connection to your systems
We hook into your existing GRC and ticketing processes.
Reporting deadlines under the Cyber Resilience Act
The moment a manufacturer learns of an actively exploited vulnerability, the CRA clock starts — in three stages. We support you on request.
Let's talk about your program
In a short intro call we clarify scope, rules, and rewards. No obligation.
- We clarify which systems belong in scope, what stays excluded, and when testing happens.
- You get a draft disclosure policy and a reward overview.
- 30 minutes. Nothing to prepare on your side.
We usually reply within one business day.