Sign in Get started
Solutions
ComplianceDigital ForensicsAccount SecurityWebsite SecurityWeb OptimizationSEO / GEOBusiness IntelligenceUI / UXStartupsDigital TransformationWhite LabelAI Code AuditAI / MLConsulting & AdvisoryBusiness Strategy
Products
Web HostingVPS HostingSSL CertificatesSiteLock SecurityWebsite BackupEmail Spam FilterOX App Suite360 MonitoringWeebly BuilderSite BuilderSEO (Marketgoo)Account SecurityDomainsAll Products
More
NetworkSecurity AboutCareersContactRoadmapLegal
Bug Bounty programme

Find it. Report it. Earn your name.

Internetivo has run online services since 2010 and has never been breached. Help us keep it that way: approved researchers test a staging copy of the platform, and every accepted report earns points, a public track record and a reward.

Approval only Staging, never production Points on acceptance
At a glance

A programme built on trust.

Small, approval-gated and fair: the same reward for the same finding, whoever you are.

100

points for a Critical

High 50, Medium 20, Low 5. Points are awarded when a report is accepted, never at submission.

5

business days

We aim to give a first response within five business days, then a realistic remediation timeline.

90

days to disclose

Coordinated disclosure: up to 90 days from your report, or sooner once a fix has shipped, agreed with you.

How it works

Four steps from sign-up to first report.

Testing starts only after we approve you and confirm your scope in writing.

1. Register

Create an account on internetivo.com. You take part under a handle; your legal name never appears publicly.

2. Apply

Open a ticket in the Bug Bounty department. Tell us your handle and the kind of testing you do.

3. Get your scope

If we approve you, we confirm your scope and rules in writing, including the staging copy you may test.

4. Test and report

One report per issue, with steps to reproduce and the minimum proof. One record of your own is always enough.

What to look for

Severity and points.

Your report proposes a severity; we confirm it against this published rubric. The examples are indicative, not exhaustive.

SeverityWhat qualifiesPoints
CriticalAuthentication bypass, remote code execution, mass exposure of personal data, or anything that moves money.100
HighCross-tenant data access, privilege escalation, or stored XSS in an admin view.50
MediumReflected XSS, CSRF on a state-changing action, or an IDOR on non-sensitive records.20
LowInformation disclosure with limited impact, or missing hardening headers.5
InformativeBest-practice notes, raw scanner output, or theoretical issues with no demonstrated impact.0

Points build a public track record shown as handle and points only. A track record earns faster triage and, over time, a wider scope: trust is extended gradually. Specific reward amounts are confirmed when you are accepted and announced for each programme or event.

Where you test

Staging only. Real people stay safe.

internetivo.com serves real people, real data and real money, so it is out of scope for everyone.

Coming up

Bug bounty weekend, 31 October to 2 November 2026

Our first time-boxed event for approved researchers, on a staging copy named in your approval, with a prize pool of about EUR 1,000 paid per accepted report on the scale above.

See the weekend
Rules of engagement

Report it, do not prove it on anyone else.

Safe harbour covers approved participants acting in good faith and within their granted scope.

Stay in scope

Do not test before you are approved, and only within the scope we grant you. Use only accounts you created yourself.

One record is enough

Never exfiltrate data or touch another person’s account, data or money. Prove the issue with your own record and stop there.

Test by hand

No automated scanners, no denial of service, and no social engineering or phishing of our staff or customers.

Disclose together

Do not disclose an issue publicly before it is fixed and the timing is agreed. We credit you if you would like to be named.

Full policy: scope, safe harbour and disclosure

FAQ

Bug Bounty questions, answered.

Can I test internetivo.com directly?

No. Approved researchers test a staging copy that we name in their approval. internetivo.com is out of scope for everyone because it serves real people, real data and real money. Production testing may be offered later, by name, to researchers with a completed event and a clean track record.

How am I rewarded?

You earn points when a report is accepted and its severity confirmed. Accepted rewards are paid by bank transfer, outside the platform, after an identity and sanctions check. Amounts are confirmed when you are accepted and announced for each programme or event.

Do I have to verify my identity?

Not to take part. You report and earn points under a handle and an email. Identity verification, sanctions screening and a payout destination in your verified name are needed only for your first payout.

Who can be paid?

We can pay researchers in most countries in EUR, but we cannot pay anyone located in, or a national or resident of, a country or region under sanctions or embargo, anyone on an applicable sanctions list, or where our payment partners cannot lawfully operate. Reputation and leaderboard standing are open to every valid reporter regardless of payability.

I found something but I am not in the programme. What now?

Please do not investigate further and do not access anyone else’s data. Register an account, report it through the Bug Bounty channel and do not disclose it publicly. We will take it from there.

What happens to a duplicate?

Duplicates are recorded against the original report with a timestamp, which protects both sides.

Ready to test with us?

Apply once, get your scope in writing, and start building a track record on a platform that has never been breached.