Technology & Digital

Vulnerability Disclosure / Bug Bounty Agreement

Establishes CFAA-compliant safe-harbor authorization for security researchers, defines the bug bounty scope and reward schedule, and sets the responsible disclosure timeline and conditions.

๐Ÿ“„ 2 signers๐Ÿ“… 30-day expiry๐Ÿท Technology & Digital๐Ÿ”– security, bug-bounty, disclosure

About this template

The Vulnerability Disclosure / Bug Bounty Agreement is a ready-to-use technology & digital template you can send for signature in minutes. It is written for 2 signers (organization and researcher) and, by default, expires 30 days after it is sent if left unsigned. It covers security, bug bounty, disclosure. Like every Abundera Sign template it is a convenience draft structured for ESIGN Act and UETA compliance, not a substitute for legal advice. Each signed copy is sealed with PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package in WORM storage.

Document Preview

# Vulnerability Disclosure / Bug Bounty Agreement This Vulnerability Disclosure and Bug Bounty Agreement (this "Agreement") is entered into as of the date last signed below (the "Effective Date") by and between: **Organization:** ___________, a ___________ with a principal address at ___________ ("Organization"); and **Researcher:** ___________, an individual (or entity) with a principal address at ___________ ("Researcher"). --- ## 1. Purpose and Safe Harbor 1.1 **Purpose.** Organization operates systems, applications, smart contracts, and/or protocols (as specified herein) and desires to improve their security through responsible security research. Researcher desires to conduct security research on Organization's systems. This Agreement establishes the terms under which such research is authorized, provides safe-harbor protections for Researcher, and governs the responsible disclosure and rewarding of vulnerabilities. 1.2 **Safe Harbor โ€” Authorization.** Organization grants Researcher express written authorization under this Agreement to access, probe, and test the In-Scope Systems (as defined in Section 2) in the manner and to the extent described herein. This authorization is intended to qualify Researcher's activities as authorized access for purposes of the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. ยง 1030 et seq., the Electronic Communications Privacy Act (ECPA), 18 U.S.C. ยง 2510 et seq., and analogous state and foreign laws. Organization waives any claim against Researcher under such laws for good-faith security research conducted strictly within the scope defined in this Agreement. 1.3 **Good Faith Standard.** Research is "good faith" for purposes of this Agreement if Researcher: (a) acts only within the In-Scope Systems; (b) complies with all Rules of Engagement in Section 3; (c) avoids accessing, modifying, or disclosing data beyond what is minimally necessary to demonstrate a vulnerability; (d) reports findings to Organization in accordance with Section 5; and (e) does not exploit any vulnerability beyond what is necessary to confirm its existence and characterize its impact. 1.4 **No Blanket Authorization.** This safe harbor applies only to the specific In-Scope Systems and testing methods permitted under this Agreement. It does not authorize access to out-of-scope systems, data, or networks, and does not immunize Researcher from liability for conduct that is not in good faith. --- ## 2. Scope 2.1 **In-Scope Systems.** The following systems, assets, and environments are in scope for this engagement: ___________ 2.2 **In-Scope Smart Contracts (if applicable).** The following smart contract addresses and repositories are in scope: ___________ 2.3 **Out-of-Scope Systems.** The following are expressly out of scope and may not be tested under any circumstances: ___________ 2.4 **Out-of-Scope Vulnerability Classes.** The following vulnerability classes are out of scope for reward purposes (though Researcher should still disclose them): (a) Denial-of-service attacks against production infrastructure that require sustained resource consumption;

Fields (36)

organization legal name
text ยท required
organization entity type
select ยท required
organization address
textarea ยท required
researcher legal name
text ยท required
researcher address
textarea ยท required
in scope systems
textarea ยท required
in scope contracts
textarea
out of scope systems
textarea ยท required
bounty critical
text ยท required
bounty high
text ยท required
bounty medium
text ยท required
bounty low
text ยท required
bounty cap
currency ยท required
payment days
number ยท required
payment method
select ยท required
disclosure email
email ยท required
pgp fingerprint
text
acknowledgment hours
number ยท required
initial assessment days
number ยท required
remediation critical days
number ยท required
disclosure critical days
number ยท required
remediation high days
number ยท required
disclosure high days
number ยท required
remediation medium days
number ยท required
disclosure medium days
number ยท required
remediation low days
number ยท required
disclosure low days
number ยท required
extension max days
number ยท required
final notice days
number ยท required
agreement term months
number ยท required
governing law state
select ยท required
arbitration venue
text ยท required
organization signatory name
text ยท required
organization signatory title
text ยท required
researcher signatory name
text ยท required
researcher signatory title
text

Related Technology & Digital templates

All 39 Technology & Digital templates โ†’ ย ยทย  Browse all templates โ†’

Send this template with cryptographic proof

Every signed document gets PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package sealed in WORM storage.

Try the DemoView PricingFounding Member โ€” 50% Off