Skip to content

Aegis Web Security and Bug Hunting The program

We provide direct cash rewards to the first researchers who find and responsibly report a critical or verifiable security vulnerability in our Aegis web infrastructure (betterwithaegis.com) and API services.

AI USAGE AND TECHNICAL SUPPORT:You can use AI tools freely! If you don't know technical details like coding, software, SQL, database, or API at all; you can ask both the AI and our founders (kimch.d & zay) on our official Discord server about anything you are curious about or don't understand. Our only condition: The report must not be fabricated/hallucinated and must be based on a proven (PoC) security vulnerability that actually works in the system.
Cash Reward
300 ₺
Per verified open
Response Time
< 24 Hour
Quick verification & feedback
Target Area
betterwithaegis.com
Web + API Endpoints
Payment Method
IBAN / Papara / Crypto
Instant transfer

In-Scope

Technical vulnerabilities in the following areas are within the scope of the reward:

  • https://betterwithaegis.com all web pages and session mechanisms on it
  • /api/* endpoints (Privilege escalation, IDOR, SQLi, SSRF, RCE, etc.)
  • Session and Cookie Security: HMAC manipulation, token leakage, or founder privilege spoofing
  • Sensitive Data Exposure: Server environment variables, secret keys, or PII leakage

Out-of-Scope

The following actions and situations are out of scope for the bug bounty:

  • DDoS & Denial of Service: Flood attacks aimed at slowing down or crashing servers
  • Social Engineering & Phishing: Phishing attempts targeting developers or users
  • External Infrastructure Errors: General outages of Cloudflare, Discord, or hosting provider
  • Destructive Actions: Deleting or corrupting user data (PoC is sufficient to show)

Responsible Disclosure and Reward Rules

1. First to Report WinsThe researcher who submits the first valid and reproducible PoC report for the same vulnerability is eligible for the reward.
2. Privacy and DurationReport the vulnerability to us before making it public and allow us at least 48 hours to fix it.
3. Quick PaymentAs soon as the vulnerability is verified, our developers (kimch.d & zay) will contact you directly to deliver the 300 ₺ reward.
4. AI & Learning AllowedIf you don't know coding or SQL, you can get support from AI or ask us. The vulnerability must be real and reproducible.

Report Vulnerability

Fill out the form below to test and report the vulnerability.

Report directly via Discord

Faster communication and instant chat

Instead of filling out a form, you can report the vulnerability by coming directly to our official Aegis Discord server and opening a private support ticket or by messaging our founders.

Developers & Founders:
kimch.d • zay
Payment Terms

Rewards are transferred to the reported account within 24 hours at the latest after the vulnerability is verified and confirmed to be patched in our systems. In case of multiple reports of the same vulnerability, only the first report is considered.