What changes when your
program runs on CertiK Hunt
From kickoff to controlled launch
Intake
Share your surface, known audit findings, and disclosure constraints so CertiK can route the program conversation.
CertiK vetting
CertiK reviews scope, verifies assets, and records reward handling terms before the program opens.
Program live
The program opens to invited researchers whose prior work matches your stack and risk areas.
Verified findings
Verified findings reach one accountable owner with severity, duplicate checks, and disclosure status already documented.
Three formats, one network
The same vetted researchers work across all three. Protocol intake today is for private bug bounty programs — the other two are how the network builds and proves the people who will eventually look at your code.
Security challenges
Focused, time-boxed investigations CertiK runs to test judgment and technique. They are how researchers earn their way onto the network and prove what they can do before they ever see your scope.
Audit contests
Time-bound competitive review of a fixed codebase, with the whole qualified field looking at once. Useful ahead of a launch or a major upgrade, when you want depth in a narrow window.
Private bug bounty programs
Continuous coverage of your live surface by invited researchers whose prior work matches your stack. CertiK reproduces every submission and sets severity before it reaches you.
Two triage modes
Two ways CertiK runs your program. Researchers always see one private intake path; you choose how much CertiK handles before findings reach your team.
Start a CertiK Hunt program
Share enough context for CertiK to route the conversation and recommend the right triage mode.
- Inquiries stay private to CertiK. Reports are encrypted AES-256 at rest.
- Time-sensitive launches can be routed to your CertiK contact.
- Audited and non-audited protocols welcome.