Establishes CFAA-compliant safe-harbor authorization for security researchers, defines the bug bounty scope and reward schedule, and sets the responsible disclosure timeline and conditions.
The Vulnerability Disclosure / Bug Bounty Agreement is a ready-to-use technology & digital template you can send for signature in minutes. It is written for 2 signers (organization and researcher) and, by default, expires 30 days after it is sent if left unsigned. It covers security, bug bounty, disclosure. Like every Abundera Sign template it is a convenience draft structured for ESIGN Act and UETA compliance, not a substitute for legal advice. Each signed copy is sealed with PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package in WORM storage.
Document Preview
# Vulnerability Disclosure / Bug Bounty Agreement This Vulnerability Disclosure and Bug Bounty Agreement (this "Agreement") is entered into as of the date last signed below (the "Effective Date") by and between: **Organization:** ___________, a ___________ with a principal address at ___________ ("Organization"); and **Researcher:** ___________, an individual (or entity) with a principal address at ___________ ("Researcher"). --- ## 1. Purpose and Safe Harbor 1.1 **Purpose.** Organization operates systems, applications, smart contracts, and/or protocols (as specified herein) and desires to improve their security through responsible security research. Researcher desires to conduct security research on Organization's systems. This Agreement establishes the terms under which such research is authorized, provides safe-harbor protections for Researcher, and governs the responsible disclosure and rewarding of vulnerabilities. 1.2 **Safe Harbor โ Authorization.** Organization grants Researcher express written authorization under this Agreement to access, probe, and test the In-Scope Systems (as defined in Section 2) in the manner and to the extent described herein. This authorization is intended to qualify Researcher's activities as authorized access for purposes of the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. ยง 1030 et seq., the Electronic Communications Privacy Act (ECPA), 18 U.S.C. ยง 2510 et seq., and analogous state and foreign laws. Organization waives any claim against Researcher under such laws for good-faith security research conducted strictly within the scope defined in this Agreement. 1.3 **Good Faith Standard.** Research is "good faith" for purposes of this Agreement if Researcher: (a) acts only within the In-Scope Systems; (b) complies with all Rules of Engagement in Section 3; (c) avoids accessing, modifying, or disclosing data beyond what is minimally necessary to demonstrate a vulnerability; (d) reports findings to Organization in accordance with Section 5; and (e) does not exploit any vulnerability beyond what is necessary to confirm its existence and characterize its impact. 1.4 **No Blanket Authorization.** This safe harbor applies only to the specific In-Scope Systems and testing methods permitted under this Agreement. It does not authorize access to out-of-scope systems, data, or networks, and does not immunize Researcher from liability for conduct that is not in good faith. --- ## 2. Scope 2.1 **In-Scope Systems.** The following systems, assets, and environments are in scope for this engagement: ___________ 2.2 **In-Scope Smart Contracts (if applicable).** The following smart contract addresses and repositories are in scope: ___________ 2.3 **Out-of-Scope Systems.** The following are expressly out of scope and may not be tested under any circumstances: ___________ 2.4 **Out-of-Scope Vulnerability Classes.** The following vulnerability classes are out of scope for reward purposes (though Researcher should still disclose them): (a) Denial-of-service attacks against production infrastructure that require sustained resource consumption;