This Policy is made and entered into on "1/10/2024" by and between [Tester/Bug Hunter Name] ("TBH")
and VBB ("VBB"), collectively referred to as the "Parties".
ARTICLE 1: DEFINITIONS
For the purposes of this Policy, the following definitions shall apply:
-
"Bug" means a flaw or vulnerability in the target system, software, or application.
-
"Bug Bounty" means the payment made by VBB to TBH for a valid bug report.
-
"Bug Report" means a detailed report submitted by TBH to VBB, describing a bug and providing steps to reproduce it.
-
"Confidential Information" means all information and data exchanged between the Parties under this Policy, including but not limited to, bug reports, target information, and communication with VBB.
-
"Intellectual Property Rights" means all patents, trademarks, copyrights, and other intellectual property rights.
-
"Target" means the system, software, or application being tested or hunted for bugs.
-
"Testing" means the process of identifying and reporting bugs in the target.
-
"VBB Bug Bounty Program" means the program established by VBB to reward TBH for valid bug reports.
ARTICLE 2: PRE-TESTING AND BUG HUNTING REQUIREMENTS
2.1. Target Information: TBH must read all information about the target before starting the test or bug-hunting process.
2.2. Reporting Policy: TBH must follow the Reporting Policy as outlined in their profile, including the provided guidelines and templates.
2.3. Bug Hunting Process: TBH must use their best efforts to identify and report bugs in the target, in accordance with the VBB Bug Bounty Program.
ARTICLE 3: TESTING AND BUG REPORTING REQUIREMENTS
3.1. Documentation: TBH must provide details in the form of a document as requested by the VBB Team.
3.2. Bug Report: TBH must submit a detailed bug report, including but not limited to: * A clear and concise description of the bug * Steps to reproduce the bug * Expected and actual results * Any relevant screenshots or videos
3.3. Bug Classification: TBH must classify the bug according to the VBB bug classification guidelines.
3.4. Bug Severity: TBH must assign a severity level to the bug based on the VBB severity guidelines.
ARTICLE 4: COMMUNICATION AND RESPONSE
4.1. Waiting for Response: TBH must wait for the VBB response for better clarification and valuable feedback on the bug report or test results.
4.2. Public Disclosure: TBH must not post any report publicly before receiving permission from the VBB Team to disclose the information. Failure to comply may result in punishment, loss, and potential legal action.
ARTICLE 5: TESTING AND BUG HUNTING RESTRICTIONS
5.1. No Exploitation: TBH must not exploit the bug for personal gain or to cause harm to the target.
5.2. No Denial of Service: TBH must not attempt to cause a denial of service (DoS) or distributed denial of service (DDoS) attack on the target.
5.3. No Unauthorized Access: TBH must not attempt to gain unauthorized access to the target's systems or data.
5.4. Following Instructions: TBH must follow the steps requested by the VBB Team under the report.
ARTICLE 6: PAYMENT AND REWARDS
6.1. Bug Bounty: TBH is eligible to receive a bug bounty payment for each valid bug report submitted, as per the VBB Bug Bounty Program.
6.2. Payment Terms: TBH must provide valid payment details, including but not limited to, bank account information or PayPal details.
ARTICLE 7: CONFIDENTIALITY
7.1. Confidentiality Obligations: TBH agrees to keep confidential all Confidential Information exchanged under this Policy.
7.2. Non-Disclosure: TBH must not disclose any Confidential Information to any third party, except as required by law or with the prior written consent of VBB.
ARTICLE 8: INTELLECTUAL PROPERTY
8.1. Assignment of Rights: TBH assigns to VBB all Intellectual Property Rights in and to the bug reports and any other materials submitted under this Policy.
8.2. Ownership: VBB shall own all Intellectual Property Rights in and to the bug reports and any other materials submitted under this Policy.
ARTICLE 9: GOVERNING LAW
9.1. Governing Law: This Policy shall be governed by and construed in accordance with the laws of [Maharashtra|INDIA].
ARTICLE 10: ENTIRE AGREEMENT
10.1. Entire Agreement: This Policy constitutes the entire understanding of the Parties and supersedes all prior agreements, understandings, and discussions between the Parties.
10.2. Amendments: This Policy may be amended or modified only in writing signed by both Parties.
ARTICLE 11: TERMINATION
11.1. Termination: Either Party may terminate this Policy upon [NUMBER] days' written notice to the other Party.
11.2. Survival: The provisions of this Policy shall survive termination and continue to be binding on the Parties.
ARTICLE 12: NOTICES
12.1. Notices: Any notices required or permitted to be given under this Policy shall be in writing and shall be delivered personally or by certified mail, return receipt requested.
12.2. Address: Any notices shall be addressed to the Parties at the addresses specified in this Policy.
ARTICLE 13: FORCE MAJEURE
13.1. Force Majeure: Neither Party shall be liable for any failure or delay in performing its obligations under this Policy due to circumstances beyond its reasonable control.
13.2. Notice: The Party affected by the force majeure event shall give written notice to the other Party as soon as reasonably possible.
ARTICLE 14: CONFIDENTIALITY
14.1. Confidentiality: TBH agrees to keep confidential all Confidential Information exchanged under this Policy.
14.2. Non-Disclosure: TBH must not disclose any Confidential Information to any third party, except as required by law or with the prior written consent of VBB.