Tailored scope · No strings attached

Bug bounty for businesses in Cádiz

Continuous offensive research on your assets, with a scope defined in writing and a responsible disclosure agreement. NULLSTRATA plays the attacker: we actively hunt real vulnerabilities.

Get my free audit

What's included?

  • Continuous offensive research on the assets you define in the scope.
  • Written scope and signed responsible disclosure agreement.
  • Discovery and demonstration of real, exploitable vulnerabilities.
  • Continuous reporting with severity, impact and reproducible evidence.
  • Periodic review session on findings and trends.

Who is it for?

For businesses with continuously exposed assets (SaaS, e-commerce, APIs) that want a sustained offensive approach over time, not a one-off test.

How a continuous programme works

  1. 01

    We define the scope

    Which assets are in, which techniques are allowed and which limits are never crossed. All in writing.

  2. 02

    Sustained research

    We analyse and attack continuously, not in a one-off window, covering the changes you ship every week.

  3. 03

    Reporting cycle

    We notify findings with severity and evidence; you fix and we verify the issue is closed.

Bug bounty vs. one-off pentest

A pentest is a snapshot on a given date. A continuous programme is a film: it covers new code, deployments and infrastructure changes that a one-off test will never see.

Scope and rules of engagement

  • Assets authorised in writing: domains, IP ranges and test accounts.
  • Allowed and forbidden techniques, with agreed time windows.
  • Definition of responsible disclosure and publication timelines.
  • Direct channel for critical incidents.

What we measure

  • Valid vulnerabilities by severity.
  • Mean time to detect and to remediate (MTTD / MTTR).
  • Trends by category to prioritise your roadmap.

We answer your questions before we start

How is this different from a bug report channel?

NullStrata is the one actively attacking; we don't manage reports sent by third parties. The scope, the authorisation and the research are ours.

Do you pay bounties to third parties?

No. Our model is a continuous offensive research service with reporting and verification, without pay-per-finding to third parties.

Is one test a year really enough?

Tell us which assets you expose and we'll design a continuous research programme for you.

Get my free audit