Rewards
Severity | Payout |
Critical | $500 |
High | $300 |
Medium | $200 |
Low | $100 |
Communication | SLA |
Initial Communication | Upon receipt of new report |
Triage | 2-5 business days from receipt of new report |
Bounty Payout | 7-10 business days from Triage |
Response to Researcher questions | 2-5 days from posted question |
Eligibility
Toric reserves the right to decide the weakness and severity of a report and whether the vulnerability was previously reported. Rewards are granted entirely at the discretion of Toric.
To qualify for a reward under this program, you should:
- Be the first to report a vulnerability.
- Send a clear textual description of the report along with steps to reproduce the vulnerability.
- Include attachments such as screenshots or proof of concept code as necessary.
- Disclose the vulnerability report directly and exclusively to us.
Payment
Toric supports the following payment methods:
- Bank Transfer: The bounty amount is credited to your bank account. **any international fees will be at the cost of the reporter