Bugloud · Company Edition
Company Terms & Conditions
These Company Terms govern the relationship between Exordium — which owns and operates the Bugloud platform — and a Company that runs one or more security Programs. They are the Company-facing counterpart to the separate Researcher Terms.
Version 3.1 · Effective 2023 · Last updated 2026
1. Definitions & Interpretation
In these Company Terms, capitalised words have the meanings below.
- Platform — the Bugloud website at bugloud.com, its subdomains, applications, APIs and related services operated by Exordium.
- Exordium / we / us / our — Exordium Data Management Cyber Security Services L.L.C (licence no. CN-4658519), legal owner and operator of the Bugloud Platform.
- Company / Customer / you — the organisation that registers to run one or more Programs on the Platform and accepts these Terms, acting through its authorised representative.
- Researcher — an individual who registers to discover and report vulnerabilities (also "Hacker"), and to whom a Company grants limited testing authorization within a Program.
- Program Brief — the scope, rules of engagement, reward table and disclosure policy you set for a specific Program.
- Scope / In-Scope Asset — the specific systems, domains, applications, APIs or assets you expressly authorise for testing in a Program Brief.
- Reward / Bounty — a monetary amount you elect to pay for an accepted Submission.
- Setup Fee — the one-time fee of AED 105 payable for each Program launched.
- Subscription — the recurring plan you purchase (by company size and term) for access to the Platform.
- Applicable Law — the laws of the United Arab Emirates and of the Emirate of Abu Dhabi.
2. Structure & Order of Precedence
Your agreement with Bugloud is made up of, in this order of precedence: (a) the applicable Program Brief for each Program you run; (b) these Company Terms & Conditions and any Order form; (c) the Code of Conduct; (d) the Privacy Policy and Data Processing Agreement; and (e) the Responsible Disclosure Policy.
A Program Brief may make a Program’s rules stricter than these Terms but can never grant a Researcher rights beyond what these Terms and Applicable Law allow, nor authorise testing of assets you do not own or control. Where a conflict arises, the higher-ranked document prevails, except that no document may override a mandatory requirement of Applicable Law.
3. Acceptance & Electronic Agreement
By creating a Company account, ticking "I agree", or accessing or using the Platform, you enter into a binding agreement on these Terms. The individual accepting warrants that they are an authorised representative of the Company with authority to bind it. You agree that electronic acceptance, records and signatures are valid and admissible, and that Bugloud’s records of acceptance are evidence of your agreement.
4. Company Eligibility & Verification
Capacity. A Company must be a duly constituted legal entity and must act through an authorised representative who has legal capacity to bind it.
Verification before go-live. Before a Program can go live, you must provide: (a) a valid UAE trade licence (or equivalent foreign registration); (b) identification for its authorised representative; and (c) proof that you own or control each In-Scope Asset. We may verify asset ownership through third-party providers and may refuse, delay or suspend any Program where authority over the assets is unclear.
One account & accuracy. You may hold one account per entity. You are responsible for all activity under your account and for keeping your credentials secure, and must keep your registration and licensing information current, accurate and complete, notifying us of any change that affects your authority over an In-Scope Asset.
5. Company Accounts & Subscriptions
Subscription. A Company purchases a Subscription priced by company size and term (Section 9) and pays the AED 105 Setup Fee for each Program. A Subscription grants access to the Platform’s tooling and coordination services; it is not a guarantee that vulnerabilities will be found or that your systems are secure.
Our role. Bugloud operates a neutral coordination platform and payment facilitator. We are not the employer, agent, partner or joint venturer of any Researcher or Company, are not a party to the security testing itself, and do not ourselves fund Rewards.
Program types. (a) Bug Bounty — a continuous Program paying a Reward per accepted, valid finding; (b) VDP — a disclosure channel that offers recognition, not a monetary Reward; (c) Pentest — a time-boxed, scoped engagement, often using vetted Researchers.
6. Programs, Scope & the Authorization Grant
Program creation & warranties. As the Company, you define the Scope, targets, rules of engagement, reward table and disclosure policy in your Program Brief, and you warrant that you own or are fully authorised to permit testing of every In-Scope Asset and that no necessary third-party consent is missing.
Authorization grant. By publishing a Program, you grant each participating Researcher a limited, revocable authorization to access and test the In-Scope Assets strictly in accordance with the Program Brief. To the extent you are legally entitled to do so, you agree that such good-faith, in-scope activity is authorized access and not a violation of your rights, and that you will not yourself file a criminal complaint or civil claim against a Researcher for such activity.
The safe-harbor is bounded. No authorization you grant extends to any asset you do not own or control, to government, financial or third-party systems, or to any conduct beyond the Program Brief. Nothing in these Terms waives or overrides UAE criminal law or binds the UAE Public Prosecution. Researchers are bound by their own terms to test only within the Scope you define; scope changes take effect when published and revocation is prospective only.
7. Triage, Severity & Disputes
Triage & severity. Submissions are validated by the Company and/or Bugloud’s triage team against standards of reproducibility and quality; we aim to give a first response within 5 business days. Severity is assessed using CVSS and locked on acceptance; the Reward is tied to your Program’s published severity-to-reward table.
Duplicates & non-qualifying. Only the first complete, reproducible Report of a unique vulnerability is eligible for a Reward. Reports closed as Not Applicable, Informative, Out of Scope or Invalid carry no Reward. Typical exclusions (unless chained to real impact) include missing security headers, self-XSS, theoretical issues with no demonstrated impact, denial of service, and social-engineering or physical findings.
Dispute ladder. Where a Researcher disagrees with a determination, disputes follow a graduated process: (a) discussion between Researcher and Company; then (b) mediation by Bugloud; and only then (c) any external legal step under Section 20. The final Reward decision rests with the Company, exercised in good faith and consistently with the published Program Brief.
8. Rewards & Payouts
You fund the Rewards. The Company funds all Rewards. Bugloud acts only as payment facilitator through Stripe; it is not the source of funds.
Reward ranges & discretion. You set the reward ranges in your Program Brief and award Rewards at your discretion within those ranges, based on the severity and impact of each accepted finding. Participation does not guarantee any Researcher a Reward.
Timing. You have 5 business days to approve or reject a validated Reward. A Reward becomes payable when you mark a Report "Bounty Awarded"; you shall settle it within 14 calendar days; Bugloud then remits to the Researcher (net of its facilitation fee and after the Researcher’s KYC is complete) within 7 business days of your payment clearing. Stripe settlement timing is outside Bugloud’s control.
Facilitation fee. You pay the full Reward. Bugloud’s facilitation fee is charged to the Researcher out of the Reward and is not an additional cost to the Company. Rewards are denominated and settled in AED.
Failure to fund. Bugloud is not liable for a Company’s failure to fund a Reward. Persistent failure to fund awarded Rewards is a material breach and may lead to suspension or termination (Section 16) and indemnity under Section 15.
9. Fees, Subscriptions & Taxes
Subscription grid. A Company subscribes by company size and term. Annual billing gives two months free.
| Company size | Monthly | Annual (2 months free) |
|---|---|---|
| Startup — 1–20 employees | AED 1,500 | AED 15,000 |
| Small business — 21–100 | AED 3,000 | AED 30,000 |
| Mid-market — 101–500 | AED 4,500 | AED 45,000 |
| Enterprise — 500+ | AED 6,000 | AED 60,000 |
Setup Fee & startups. A one-time AED 105 Setup Fee is payable for each Program launched (non-refundable once a Program is created). A startup with 1–20 employees receives its first month free on presentation of a valid, approved UAE trade licence.
Billing, refunds & VAT. All amounts are in AED and processed through Stripe; Bugloud does not store card details. Subscriptions renew each term until cancelled. UAE law does not grant a general cooling-off right; Subscriptions are non-refundable once the associated Program has gone live, and where no Program has launched a Subscription may be cancelled for a pro-rata refund within 14 calendar days. Exordium is not currently registered for VAT and does not charge VAT; prices may change if VAT registration becomes mandatory, on notice.
10. Confidentiality & Coordinated Disclosure
Confidentiality. Submissions, Program Briefs (including the existence, scope and reward structure of private Programs) and other non-public information are Confidential Information of the disclosing party. Each party will keep it confidential and use it only for the Program’s purpose. Confidentiality obligations survive for 3 years after disclosure, and indefinitely for trade secrets.
Coordinated disclosure & identity. The default is no public disclosure without the Company’s written consent; your Program Brief may opt into a coordinated-disclosure model with a defined timeline, where public disclosure follows only after remediation and mutual agreement. A Researcher may operate under a pseudonym; their real identity may be disclosed to you or to authorities where legally required or on reasonable suspicion of misconduct.
11. Third-Party Services
The Platform relies on and links to third-party services, including Stripe (payments), identity/verification providers, hosting, email and analytics providers. Your use of those services is governed by the third party’s own terms, and Bugloud is not responsible for them. Card data is handled directly by Stripe under PCI-DSS; Bugloud does not receive or store raw card data.
12. Intellectual Property
Platform IP & submission licences. Bugloud owns all rights in the Platform, its software, trademarks and content; you receive only a limited, revocable, non-transferable licence to use the Platform for its intended purpose. A Researcher retains ownership of their Submission but grants you a perpetual, irrevocable, worldwide, royalty-free, sub-licensable licence to use the Submission to assess, reproduce and remediate the vulnerability — giving you the rights you need to fix the reported issues.
Licence to Bugloud & takedown. You grant Bugloud a licence to host and process your Program data to operate and improve the Platform and to produce aggregated, de-identified analytics. If you believe content infringes your intellectual property, notify us at [email protected]; we operate a notice-and-takedown and counter-notice process and may terminate repeat infringers.
13. Warranties & Disclaimers
The Platform and all services are provided "as is" and "as available", without warranties of any kind, to the maximum extent permitted by Applicable Law. Bugloud does not warrant that security testing will find all vulnerabilities, or that your systems are or will be secure. Crowd-sourced testing is inherently non-exhaustive. Bugloud does not warrant the accuracy of any automated or AI-assisted triage output.
14. Limitation of Liability
To the maximum extent permitted by Applicable Law, no party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, data, revenue or goodwill. Bugloud’s total aggregate liability to a Company is capped at the fees the Company paid Bugloud in the 12 months before the claim. Nothing excludes liability that cannot be excluded under Applicable Law, including for fraud, gross negligence, wilful misconduct, or death or personal injury.
15. Indemnification
By the Company. You will indemnify and hold harmless Bugloud, Exordium and their officers and staff against claims, losses and costs arising from: (a) your breach of these Terms or of Applicable Law; (b) a claim that an In-Scope Asset was not yours to authorise, or that testing you authorised harmed a third party or a system you did not own or control; and (c) your failure to fund Rewards you have awarded.
By Bugloud. Bugloud gives a narrow indemnity for third-party claims that the Platform itself infringes intellectual property, subject to prompt notice, our sole control of the defence, and your cooperation.
16. Term, Suspension & Termination
These Terms apply from acceptance until terminated; a Subscription runs for the term stated in the Order. We may suspend access or a Program immediately for breach, non-payment, failure to fund Rewards, suspected illegal activity, sanctions or verification failure, unclear authority over an In-Scope Asset, or a risk to Platform integrity or other users.
Either party may terminate for a material breach not cured within 30 days of notice. You may close your account at any time; Setup and Subscription fees are non-refundable except as stated in Section 9. Licences to already-submitted Reports survive; on termination we will handle pending Rewards and open Programs in good faith, and you remain liable to fund Rewards already awarded.
17. AML, Sanctions & Export Control
You warrant that the Company, its owners and its controllers are not subject to, and not owned or controlled by a person on, the UN Security Council, UAE (Local Terrorist List / targeted financial sanctions), OFAC, EU or UK sanctions lists, and are not located in a comprehensively sanctioned jurisdiction. We may screen the Company and its representatives, conduct enhanced due diligence, refuse, delay or reverse any transaction, and report suspicious activity to the UAE Financial Intelligence Unit, without notice or liability, to comply with law. You must not use the Platform to facilitate any transfer of controlled technology in breach of export-control laws.
18. Data Protection
Bugloud processes personal data in accordance with its Privacy Policy and the UAE Personal Data Protection Law (Federal Decree-Law 45/2021). Where Bugloud and the Company process personal data in connection with a Program, the parties will agree their respective controller/processor roles and enter Bugloud’s Data Processing Agreement (DPA), which forms part of these Terms wherever personal data is processed. You must ensure your Program Brief instructs Researchers to minimise collection of third-party personal data, not to exfiltrate or store it, and to report immediately if personal data becomes accessible during testing.
19. General Provisions
- Force majeure — neither party is liable for failure or delay (except payment obligations) caused by events beyond its reasonable control, including internet or Stripe outages, cyber-attacks, and government action.
- Assignment — Bugloud may assign these Terms, including on a merger or sale of business. You may not assign without our consent.
- No waiver — a failure to enforce a right is not a waiver of it.
- Severability — an invalid provision is modified to the minimum extent needed to be enforceable, and the rest remains in force.
- Entire agreement — the documents in Section 2 are the entire agreement and supersede prior understandings; a purchase order’s terms have no effect.
- Notices — we may give notice via the Platform or email; you consent to electronic notices.
- Evidential value — Platform logs and records are agreed to have full evidential value in any dispute, unless proven to have been manipulated.
20. Governing Law & Disputes
These Terms are governed by the laws of the United Arab Emirates and the Emirate of Abu Dhabi. Subject to the internal mediation step in Section 7, the parties submit to the exclusive jurisdiction of the Abu Dhabi Courts (the Abu Dhabi Judicial Department). Exordium operates under a UAE mainland trade licence. To the extent permitted by Applicable Law, each party waives any right to bring or participate in a class or representative action.
21. Changes & Contact
We may update these Terms. We will give at least 15 days’ notice of material changes by email or a Platform notice; continued use after changes take effect is acceptance. We keep dated, versioned archives of prior Terms.
Contact. Exordium Data Management Cyber Security Services L.L.C, Al Hadi 3 St, Al MZEER’AH, Abu Dhabi, UAE. Email [email protected]. General inquiries: [email protected].