Bug bounty for businesses in Cádiz
Continuous offensive research on your assets, with a scope defined in writing and a responsible disclosure agreement. NULLSTRATA plays the attacker: we actively hunt real vulnerabilities.
Get my free auditWhat's included?
- Continuous offensive research on the assets you define in the scope.
- Written scope and signed responsible disclosure agreement.
- Discovery and demonstration of real, exploitable vulnerabilities.
- Continuous reporting with severity, impact and reproducible evidence.
- Periodic review session on findings and trends.
Who is it for?
For businesses with continuously exposed assets (SaaS, e-commerce, APIs) that want a sustained offensive approach over time, not a one-off test.
How a continuous programme works
- 01
We define the scope
Which assets are in, which techniques are allowed and which limits are never crossed. All in writing.
- 02
Sustained research
We analyse and attack continuously, not in a one-off window, covering the changes you ship every week.
- 03
Reporting cycle
We notify findings with severity and evidence; you fix and we verify the issue is closed.
Bug bounty vs. one-off pentest
A pentest is a snapshot on a given date. A continuous programme is a film: it covers new code, deployments and infrastructure changes that a one-off test will never see.
Scope and rules of engagement
- Assets authorised in writing: domains, IP ranges and test accounts.
- Allowed and forbidden techniques, with agreed time windows.
- Definition of responsible disclosure and publication timelines.
- Direct channel for critical incidents.
What we measure
- Valid vulnerabilities by severity.
- Mean time to detect and to remediate (MTTD / MTTR).
- Trends by category to prioritise your roadmap.
We answer your questions before we start
How is this different from a bug report channel?
NullStrata is the one actively attacking; we don't manage reports sent by third parties. The scope, the authorisation and the research are ours.
Do you pay bounties to third parties?
No. Our model is a continuous offensive research service with reporting and verification, without pay-per-finding to third parties.
Is one test a year really enough?
Tell us which assets you expose and we'll design a continuous research programme for you.
Get my free audit