Security Research

Collaboration makes security stronger. Work with us to find and fix vulnerabilities—responsibly and with recognition.

Security Disclosure background

Disclosure Policy

At Nullforge, security is a partnership. By working with ethical hackers and researchers, we uncover and fix issues before they can be abused. We recognize valid reports with exclusive swag, our Hall of Fame, and collectible bug bounty badges. Your research strengthens our defenses—and builds your reputation.

What We’re Looking For

In-scope targets

  • Nullforge Hive Platform (private bounty—by invite only)
  • Nullforge Main Website (www.nullforge.net)
  • Nullforge Blog (blog.nullforge.net)

High-value vulnerability classes

  • Remote Code Execution (RCE)
  • Authentication Bypass
  • Privilege Escalation
  • Sensitive Data Exposure
  • Business Logic Flaws

Bounty

Critical

Premium Nullforge Swag + Hall of Fame + Virtual Badge

High

Swag Pack + Hall of Fame + Virtual Badge

Medium

Hall of Fame + Virtual Badge

Low

Hall of Fame + Virtual Badge

Informational

Hall of Fame + Virtual Badge

Badge System

Every valid report contributes to your badge progression.

Explorer

Explorer

Submit your first valid web vulnerability report.

Trooper

Trooper

Submit 10 valid web vulnerability reports.

Raider

Raider

Submit 30 valid web vulnerability reports.

Hydra

Hydra

Submit 50 valid web vulnerability reports.

Centurion

Centurion

Submit 100 valid web vulnerability reports.

Paladin

Paladin

First critical severity (e.g., RCE, full ATO).

Obsidian

Obsidian

New vuln class or bypass of existing mitigations.

Elite

Elite

Sustained, high-impact contributions across the program.

Rules of Engagement

  • Stay within scope.
  • Do not access, modify, or delete data that isn’t yours.
  • Avoid service disruption (no DoS or spam).
  • Act responsibly and ethically — Safe Harbor applies.

Safe Harbor

We stand behind good-faith research. Follow the program rules and you’re authorized to test and report without fear of legal action.

Hall of Fame List »
DICT Initiative »



Built on trust. Secured by collaboration.


Join the hunt! ↗