Pick a target, stay in scope, ship a report worth points.
Programs are presented like a hunting board: clear surface, clear rules, clear intake. Rooted rewards confirmed reports with platform points by severity, then writes the result to your public ledger.
Programs
27
Report reward
+100-1500
Safe harbor
4
Platform rewards
A confirmed bug is the fastest way up the ladder.
Submit here, we verify, and points are released the moment the finding is confirmed. Reports are the only track with no ceiling — the one kind of proof that cannot be bought, ground out or generated.
Healthcare-adjacent reports must stay on public web surfaces and test accounts. Do not access patient data, attempt persistence, disrupt care systems or test physical facilities.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
Research is limited to Aarts-owned public web properties, login forms, exposed APIs and configuration issues visible without intrusive scanning. No social engineering, spam or data extraction.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
Research should stay on owned web applications, account recovery, public APIs and access-control boundaries. Do not perform destructive tests or access data that is not yours.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
Target cloud control panels, account flows, DNS and hosting-adjacent APIs owned by Aarts Cloud. Keep tests non-destructive and prove impact with synthetic accounts.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
Good-faith testing is explicitly authorised by the policy.
Disclosure
Coordinate disclosure through the channel the policy lists.
Municipal digital services, public forms, authentication flows and exposed APIs are the practical focus. Avoid service disruption, citizen data access, phishing and physical testing.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is non-hostile language, but confirm the scope before you test.
Disclosure
The timeline may be defined by the policy, or not stated at all.
Test public application and API surfaces that handle accounting exports, integrations and tenant-level authorization. Keep activity to owned accounts and avoid bulk actions against connected platforms.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is non-hostile language, but confirm the scope before you test.
Disclosure
The timeline may be defined by the policy, or not stated at all.
Focus on public web routes, contact forms, auth/session issues and exposed files on Aal-owned domains. Avoid automated high-volume scanning and any attempt to access private records.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is non-hostile language, but confirm the scope before you test.
Disclosure
The timeline may be defined by the policy, or not stated at all.
Focus on public portfolio/application surfaces, contact forms, session handling and exposed configuration. Keep testing lightweight and do not attack third-party services.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Focus on owned web applications, customer account flows, session handling, exposed files and API authorization. Keep testing low volume and limited to your own accounts.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Research should focus on public product websites, download/update flows, account pages and exposed configuration. Avoid malware-like payloads, license abuse and destructive testing.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Research is limited to public web pages, forms, authentication/session behavior and obvious data exposure on owned assets. No spam, scraping, phone contact abuse or destructive payloads.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Focus on account registration, profile visibility controls, messaging boundaries and privacy-impacting web flaws using test accounts. Do not contact real users or scrape profiles.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Test public agency websites, client intake forms and exposed assets owned by A1 Agency. Do not target customer systems, third-party vendors or production data.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Research should stay on public web assets, auth/session handling and exposed configuration. Avoid high-volume scans, phishing, credential stuffing and third-party services.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Focus on owned websites, login flows, exposed documents and API boundaries. No physical attacks, social engineering, malware, persistence or access to non-public customer data.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Research is limited to A3Security-owned public assets, contact flows and exposed security.txt-linked systems. Avoid disruptive scans and any access to third-party data.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Focus on public web properties, admin exposure, session issues and configuration mistakes that can be shown safely. Do not brute force, spam or exfiltrate real data.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Focus on public customer portal flows, account/session boundaries, exposed configuration and non-destructive network-adjacent findings. Do not disrupt connectivity or customer services.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Research should cover owned public websites, forms, file exposure and simple access-control bugs. Avoid client environments, email abuse and destructive payloads.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Test public account flows, form handling, exposed files and tenant authorization using synthetic data only. Do not access financial, payroll or customer records.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Research should stay on public web pages, forms, session handling and exposed files. Avoid political content abuse, spam, scraping or any disruption to public communications.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
debasteinijmegen.nl / coordinated security research
45signal
Test only owned public web routes, contact forms, auth/session behavior and exposed files. Avoid high-volume crawling, real user data and third-party infrastructure.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Focus on public websites, customer portal authentication, API authorization and tenant separation in real-estate software workflows. Use test accounts only and avoid customer data.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Research should focus on public websites, login surfaces, exposed documents and misconfiguration. Do not access sensitive records, disrupt service or test physical security.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.
Test public fleet-management web surfaces, login flows, account authorization and API boundaries using accounts you control. Do not access vehicle, location or customer operational data.
Rooted reward
A confirmed finding moves your rank, and rank is what a company reads first. Low +100, Medium +300, High +700, Critical +1500.
Safe harbor
There is a published intake, but the legal and scope language is thin.