Frequently Asked Questions
Learn how DarkByte Solutions handles vulnerability disclosure, report validation, private bug bounty programs and security coordination.
Cycle-Based VDP
Run a vulnerability disclosure program for a defined cycle with an agreed duration, report allowance and service scope.
Managed VDP
DarkByte reviews, validates and coordinates reports before sending actionable findings to your organization.
Private Bug Bounty
Selected researchers privately test your approved assets under controlled program rules.
Pay Per Valid Bug
Pay an agreed platform or triage fee when a report is confirmed as valid, unique and actionable.
Cycle-Based VDP
Is the Vulnerability Disclosure Program charged per cycle?
+
Is the Vulnerability Disclosure Program charged per cycle?
Cycle-Based VDP
What is included in a VDP cycle?
+
What is included in a VDP cycle?
Cycle-Based VDP
What happens when a VDP cycle ends?
+
What happens when a VDP cycle ends?
All Programs
Will DarkByte test our systems without permission?
+
Will DarkByte test our systems without permission?
Managed VDP
What is included in the Managed VDP?
+
What is included in the Managed VDP?
Managed VDP
Does DarkByte validate every submitted report?
+
Does DarkByte validate every submitted report?
Private Bug Bounty
Who can participate in a Private Bug Bounty Program?
+
Who can participate in a Private Bug Bounty Program?
Private Bug Bounty
Are private program details visible publicly?
+
Are private program details visible publicly?
Pay Per Valid Bug
How does the Pay-Per-Valid-Bug Program work?
+
How does the Pay-Per-Valid-Bug Program work?
Pay Per Valid Bug
Do we pay for invalid or duplicate reports?
+
Do we pay for invalid or duplicate reports?
Rewards
Do we have to offer financial bug bounties?
+
Do we have to offer financial bug bounties?
Program Scope
Can we define which systems researchers may test?
+
Can we define which systems researchers may test?
Report Handling
What happens after a researcher submits a report?
+
What happens after a researcher submits a report?
Response Time
How quickly are new reports reviewed?
+
How quickly are new reports reviewed?
Communication
Will researchers communicate directly with our organization?
+
Will researchers communicate directly with our organization?
Program Control
Can we pause, update or stop our program?
+
Can we pause, update or stop our program?
Pricing
How does DarkByte charge for its services?
+
How does DarkByte charge for its services?
Start your security program
Not sure which program is right for you?
Tell us about your organization, assets and security goals. We will help you select the right cycle, report allowance and disclosure or bug bounty model.