Find it. Report it. Earn your name.
Internetivo has run online services since 2010 and has never been breached. Help us keep it that way: approved researchers test a staging copy of the platform, and every accepted report earns points, a public track record and a reward.
A programme built on trust.
Small, approval-gated and fair: the same reward for the same finding, whoever you are.
points for a Critical
High 50, Medium 20, Low 5. Points are awarded when a report is accepted, never at submission.
business days
We aim to give a first response within five business days, then a realistic remediation timeline.
days to disclose
Coordinated disclosure: up to 90 days from your report, or sooner once a fix has shipped, agreed with you.
Four steps from sign-up to first report.
Testing starts only after we approve you and confirm your scope in writing.
1. Register
Create an account on internetivo.com. You take part under a handle; your legal name never appears publicly.
2. Apply
Open a ticket in the Bug Bounty department. Tell us your handle and the kind of testing you do.
3. Get your scope
If we approve you, we confirm your scope and rules in writing, including the staging copy you may test.
4. Test and report
One report per issue, with steps to reproduce and the minimum proof. One record of your own is always enough.
Severity and points.
Your report proposes a severity; we confirm it against this published rubric. The examples are indicative, not exhaustive.
| Severity | What qualifies | Points |
|---|---|---|
| Critical | Authentication bypass, remote code execution, mass exposure of personal data, or anything that moves money. | 100 |
| High | Cross-tenant data access, privilege escalation, or stored XSS in an admin view. | 50 |
| Medium | Reflected XSS, CSRF on a state-changing action, or an IDOR on non-sensitive records. | 20 |
| Low | Information disclosure with limited impact, or missing hardening headers. | 5 |
| Informative | Best-practice notes, raw scanner output, or theoretical issues with no demonstrated impact. | 0 |
Points build a public track record shown as handle and points only. A track record earns faster triage and, over time, a wider scope: trust is extended gradually. Specific reward amounts are confirmed when you are accepted and announced for each programme or event.
Staging only. Real people stay safe.
internetivo.com serves real people, real data and real money, so it is out of scope for everyone.
Bug bounty weekend, 31 October to 2 November 2026
Our first time-boxed event for approved researchers, on a staging copy named in your approval, with a prize pool of about EUR 1,000 paid per accepted report on the scale above.
See the weekendReport it, do not prove it on anyone else.
Safe harbour covers approved participants acting in good faith and within their granted scope.
Stay in scope
Do not test before you are approved, and only within the scope we grant you. Use only accounts you created yourself.
One record is enough
Never exfiltrate data or touch another person’s account, data or money. Prove the issue with your own record and stop there.
Test by hand
No automated scanners, no denial of service, and no social engineering or phishing of our staff or customers.
Disclose together
Do not disclose an issue publicly before it is fixed and the timing is agreed. We credit you if you would like to be named.
Bug Bounty questions, answered.
Can I test internetivo.com directly?
No. Approved researchers test a staging copy that we name in their approval. internetivo.com is out of scope for everyone because it serves real people, real data and real money. Production testing may be offered later, by name, to researchers with a completed event and a clean track record.
How am I rewarded?
You earn points when a report is accepted and its severity confirmed. Accepted rewards are paid by bank transfer, outside the platform, after an identity and sanctions check. Amounts are confirmed when you are accepted and announced for each programme or event.
Do I have to verify my identity?
Not to take part. You report and earn points under a handle and an email. Identity verification, sanctions screening and a payout destination in your verified name are needed only for your first payout.
Who can be paid?
We can pay researchers in most countries in EUR, but we cannot pay anyone located in, or a national or resident of, a country or region under sanctions or embargo, anyone on an applicable sanctions list, or where our payment partners cannot lawfully operate. Reputation and leaderboard standing are open to every valid reporter regardless of payability.
I found something but I am not in the programme. What now?
Please do not investigate further and do not access anyone else’s data. Register an account, report it through the Bug Bounty channel and do not disclose it publicly. We will take it from there.
What happens to a duplicate?
Duplicates are recorded against the original report with a timestamp, which protects both sides.
Ready to test with us?
Apply once, get your scope in writing, and start building a track record on a platform that has never been breached.