Bugloud · Researcher Edition
Researcher Terms & Conditions
The terms you accept as a security researcher on Bugloud. They govern how you register, test authorized targets, submit findings, and get paid. A separate set of terms governs Companies that run Programs.
Version 3.1 · Effective 2023 · Last updated 2026
1. Definitions & Interpretation
In these Researcher Terms, capitalised words have the meanings below.
- Platform — the Bugloud website at bugloud.com, its subdomains, applications, APIs and related services operated by Exordium.
- Exordium / we / us / our — Exordium Data Management Cyber Security Services L.L.C (licence no. CN-4658519), legal owner and operator of the Bugloud Platform.
- Researcher / you — an individual who registers to discover and report vulnerabilities through the Platform (also "Hacker").
- Company — an organisation that registers to run one or more Programs, and that you may test only within the authorized Scope it publishes.
- Program Brief — the scope, rules of engagement, reward table and disclosure policy a Company sets for a Program. It defines exactly what you are and are not permitted to do.
- Scope / In-Scope Asset — the specific systems, domains, applications, APIs or assets a Company expressly authorises for testing. Anything not listed is out of scope.
- Reward / Bounty — a monetary amount a Company elects to pay for an accepted Submission.
- Payout — the amount remitted to you after deduction of the Platform Fee and any applicable charges.
- Platform Fee — the percentage Bugloud deducts from a Reward, set by your plan (Free 20%, Pro 10%, Elite 0%).
- KYC — Know-Your-Customer / identity-verification checks you must complete before any Payout.
- Applicable Law — the laws of the United Arab Emirates and of the Emirate of Abu Dhabi.
2. Structure & Order of Precedence
Your agreement with Bugloud is made up of, in this order of precedence: (a) the applicable Program Brief for a Program you participate in; (b) these Researcher Terms & Conditions and any Order for a paid plan; (c) the Code of Conduct; (d) the Privacy Policy; and (e) the Responsible Disclosure Policy.
A Program Brief may make a Program’s rules stricter than these Terms but can never grant you rights beyond what these Terms and Applicable Law allow, nor authorise testing of assets a Company does not own or control. If a conflict arises, the higher-ranked document prevails, except that no document may override a mandatory requirement of Applicable Law.
3. Acceptance & Electronic Agreement
By creating an account, ticking "I agree", or accessing or using the Platform, you enter into a binding agreement on these Terms. You agree that electronic acceptance, records and signatures are valid and admissible, and that Bugloud’s records of your acceptance (account ID, timestamp, IP address and version accepted) are evidence of your agreement. If you do not agree, do not use the Platform.
4. Eligibility, Capacity & Verification
Age & capacity. You must be at least 18 years old and have legal capacity to contract, to hold a paid Researcher account or receive a Payout. No prior experience is required — Researchers of all levels are welcome, from beginners to seasoned professionals.
Verification (KYC). To receive any Payout you must provide accurate legal name, residential address, nationality, a valid government photo ID (Emirates ID or passport) and any tax/registration details we reasonably require. We may withhold a Payout until verification is complete and may use third-party identity providers.
One account & accuracy. You may hold one account per person. You are responsible for all activity under your account and for keeping your credentials secure, and must notify us promptly of any suspected compromise. You must keep your registration information current, accurate and complete.
5. Researcher Accounts & Plans
Plans & Platform Fee. Registering, browsing Programs and submitting Reports is free. Your plan sets the Platform Fee deducted from Rewards: Free — 20%, Pro (AED 49/month) — 10%, Elite (AED 99/month) — 0%. The fee that applies is the one in effect at the time a Reward is awarded. Paid plans renew each billing cycle until cancelled.
Our role. Bugloud operates a neutral coordination platform and payment facilitator. We are not your employer, agent, partner or joint venturer, are not a party to the security testing itself, and do not ourselves fund Rewards. We facilitate the relationship between you and the Company.
Program types. (a) Bug Bounty — a continuous Program paying a Reward per accepted, valid finding; (b) VDP — a disclosure channel that offers recognition, not a monetary Reward; (c) Pentest — a time-boxed, scoped engagement, often using vetted Researchers.
6. Authorization & Scope
Authorized testing only. You may access and test only the In-Scope Assets a Company has expressly authorised in its Program Brief, and only in the manner the Brief permits. That authorization is a limited, revocable permission granted through the Platform. To the extent a Company is legally entitled to do so, your good-faith, in-scope activity is treated as authorized access and not a violation of the Company’s rights.
Out-of-scope access is a crime. Any access to, or testing of, a system that is out of scope, or that no Company has authorised (or is not entitled to authorise), is unauthorized access and a criminal offence under UAE law, regardless of your intent. No Program Brief, and nothing in these Terms, can authorise testing of assets a Company does not own or control, or bind or restrain the UAE Public Prosecution or any authority.
Scope changes & stop-and-report. Scope changes take effect when published; a Company may revoke your authorization at any time and revocation is prospective only. Once your authorization is revoked, or a Program closes or is paused, you must stop testing immediately. You must stop and report if you stray out of Scope, or encounter personal, financial, health or government data, or evidence of a pre-existing compromise — do not download, alter, retain or further access such data beyond the minimum strictly necessary to demonstrate and report the finding.
7. Submissions, Ownership & Licences
Ownership. You retain ownership of your Submission but grant: (a) to the Company, a perpetual, irrevocable, worldwide, royalty-free, sub-licensable licence to use the Submission to assess, reproduce and remediate the vulnerability; and (b) to Bugloud, a licence to host, process and use the Submission to operate and improve the Platform and to produce aggregated, de-identified analytics.
Your warranties. You warrant that each Submission is your own original work, does not infringe any third party’s rights, was not obtained unlawfully, and contains no more third-party personal data than necessary to demonstrate the finding. Any feedback you give about the Platform is licensed to Bugloud royalty-free, perpetually and irrevocably.
8. Triage, Severity, Duplicates & Disputes
Triage & severity. Submissions are validated by the Company and/or Bugloud’s triage team against standards of reproducibility and quality; we aim to give a first response within 5 business days. Severity is assessed using CVSS and locked on acceptance; the Reward is tied to the Program’s published severity-to-reward table.
Duplicates & non-qualifying. Only the first complete, reproducible Report of a unique vulnerability is eligible for a Reward; later identical Reports carry no Reward. Reports closed as Not Applicable, Informative, Out of Scope or Invalid carry no Reward. Typical exclusions (unless chained to real impact) include missing security headers, self-XSS, theoretical issues with no demonstrated impact, denial of service, and social-engineering or physical findings.
Dispute ladder. If you disagree with a determination you may request review within 7 calendar days. Disputes follow a graduated process: (a) discussion between you and the Company; then (b) mediation by Bugloud; and only then (c) any external legal step under Section 22. The final Reward decision rests with the Company (Section 9).
9. Rewards & Payouts
Who pays & discretion. The Company funds all Rewards; Bugloud facilitates the Payout through Stripe and is not the source of funds and not liable for a Company’s failure to fund a Reward. Rewards are set and paid at the Company’s discretion within the ranges published in the Program Brief. Participation does not guarantee any Reward.
Platform Fee. The Platform Fee (Free 20% / Pro 10% / Elite 0%) is deducted from the gross Reward before Payout. Example: on the Free plan, an accepted AED 1,000 Reward yields a Payout of AED 800 after the 20% fee; on Elite, you keep the full AED 1,000.
Timing. A Reward becomes payable when the Company marks a Report "Bounty Awarded". The Company shall settle it within 14 calendar days; Bugloud shall pay you (net of the Platform Fee and after completed KYC) within 7 business days of the Company’s payment clearing. Stripe settlement timing is outside Bugloud’s control. A Company has 5 business days to approve or reject a validated Reward.
Currency & claim expiry. Rewards are denominated and settled in AED; any currency-conversion, foreign-transaction or bank charges imposed by your own bank or payout method are your responsibility. A Reward that cannot be paid because your KYC is incomplete or your payout details are missing may lapse after 6 months; unpaid Rewards blocked by failed KYC or sanctions screening are not Bugloud’s liability.
10. Fees & Taxes
Charges. Your only charges are the Pro or Elite Subscription (AED 49 or AED 99 per month). Registering, browsing Programs and submitting Reports on the Free plan are free of charge. All amounts are in AED and processed through Stripe; Bugloud does not store card details.
Refunds & VAT. UAE law does not grant a general cooling-off right for this service. A Subscription is non-refundable for the billing cycle in which it is charged; you may cancel at any time to stop future renewals, and your paid benefits continue until the end of the current cycle. Exordium is not currently registered for VAT and does not charge VAT; prices may change if VAT registration becomes mandatory, on notice.
Your taxes. You are solely responsible for declaring and paying any income, VAT or other taxes on Rewards in your own jurisdiction. Bugloud is not a tax adviser and may withhold or require tax forms where required by law.
11. Confidentiality & Coordinated Disclosure
Confidentiality. Submissions, Program Briefs (including the existence, scope and reward structure of private Programs) and other non-public information are Confidential Information. You will keep it confidential and use it only for the Program’s purpose. Confidentiality obligations survive for 3 years after disclosure, and indefinitely for trade secrets.
Identity & disclosure. You may operate under a pseudonym, but your real identity may be disclosed to the Company or to authorities where legally required or on reasonable suspicion of misconduct. The default is no public disclosure without the Company’s written consent; a Program Brief may opt into a coordinated-disclosure model. You must report a discovered vulnerability promptly and must not withhold, trade or exploit it.
12. Acceptable Use & Prohibited Conduct
You must not, and must not attempt to:
- test outside the Scope of a Program, or access, alter or destroy data beyond what is necessary to demonstrate a proof of concept;
- conduct denial-of-service or load/volumetric attacks, deploy malware, or establish persistence or backdoors;
- access, exfiltrate or store other users’ or third parties’ data; move laterally into out-of-scope systems;
- perform social-engineering or physical attacks unless the Program Brief expressly permits them;
- engage in extortion, ransom or threats, or withhold a finding pending payment ("beg bounty");
- publish a vulnerability before it is authorised for disclosure;
- reverse-engineer, resell or compete with the Platform (except good-faith security research on assets you are authorised to test);
- use automated scanning that degrades service, create multiple accounts, or commit reward fraud;
- harass any person, or use the Platform for any purpose unlawful under Applicable Law.
Breaches are handled under the Code of Conduct and may result in warnings, suspension or termination (Section 18), and referral to authorities where required by law.
13. Third-Party Services
The Platform relies on and links to third-party services, including Stripe (payments), identity/KYC providers, hosting, email and analytics providers. Your use of those services is governed by the third party’s own terms, and Bugloud is not responsible for them. Card data is handled directly by Stripe under PCI-DSS; Bugloud does not receive or store raw card data.
14. Intellectual Property & Takedown
Bugloud owns all rights in the Platform, its software, trademarks and content. You receive only a limited, revocable, non-transferable licence to use the Platform for its intended purpose. Licences to your Submissions and feedback are as set out in Section 7. If you believe content on the Platform infringes your intellectual property, notify us at [email protected]; we operate a notice-and-takedown and counter-notice process and may terminate repeat infringers.
15. Warranties & Disclaimers
The Platform and all services are provided "as is" and "as available", without warranties of any kind, to the maximum extent permitted by Applicable Law. Bugloud does not warrant that any Program will be available, that any Reward will be offered or paid, or that a Company’s systems are or will be secure. Participation carries no guarantee of a finding or a Payout. Bugloud does not warrant the accuracy of any automated or AI-assisted triage output.
16. Limitation of Liability
To the maximum extent permitted by Applicable Law, no party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, data, revenue or goodwill. Bugloud’s total aggregate liability to you is capped at the greater of AED 3,700 (approximately USD 1,000) or the Payouts Bugloud processed for you in the 12 months before the claim. Nothing excludes liability that cannot be excluded under Applicable Law, including for fraud, gross negligence, wilful misconduct, or death or personal injury.
17. Indemnification
By you. You will indemnify and hold harmless Exordium, Bugloud and the relevant Company against claims, losses, liabilities and reasonable costs arising from your breach of these Terms, your out-of-scope or unlawful testing, or an infringing Submission.
By Bugloud. Bugloud gives you a narrow indemnity for third-party claims that the Platform itself infringes intellectual property, subject to your prompt notice, our sole control of the defence, and your cooperation.
18. Term, Suspension & Termination
These Terms apply from acceptance until terminated; a paid Subscription runs for the term stated in the Order. We may suspend your access immediately for breach, non-payment, suspected illegal activity, sanctions or KYC failure, or a risk to Platform integrity or other users. Either party may terminate for a material breach not cured within 30 days of notice. You may close your account at any time; Subscription fees are non-refundable except as stated in Section 10. Licences to your already-submitted Reports survive, and we will handle your pending Rewards in good faith on termination.
19. AML, Sanctions & Export Control
You warrant that you are not subject to, and not owned or controlled by a person on, the UN Security Council, UAE (Local Terrorist List / targeted financial sanctions), OFAC, EU or UK sanctions lists, and are not located in a comprehensively sanctioned jurisdiction. We may screen you, conduct enhanced due diligence, and refuse, delay, withhold or reverse any Payout, and report suspicious activity to the UAE Financial Intelligence Unit, without notice or liability, to comply with law. You must not use the Platform to facilitate any transfer of controlled technology in breach of export-control laws.
20. Data Protection
Bugloud processes personal data in accordance with its Privacy Policy and the UAE Personal Data Protection Law (Federal Decree-Law 45/2021). You must minimise collection of third-party personal data, must not exfiltrate or store it, and must report immediately if personal data becomes accessible during testing. Where you and a Company process personal data in connection with a Program, the respective controller/processor roles will be agreed and a data-processing agreement entered into where required.
21. General Provisions
- Force majeure — neither party is liable for failure or delay (except payment obligations) caused by events beyond its reasonable control, including internet or Stripe outages, cyber-attacks, and government action.
- Assignment — Bugloud may assign these Terms, including on a merger or sale of business. You may not assign without our consent.
- No waiver — a failure to enforce a right is not a waiver of it.
- Severability — an invalid provision is modified to the minimum extent needed to be enforceable, and the rest remains in force.
- Entire agreement — the documents in Section 2 are the entire agreement between you and Bugloud and supersede prior understandings.
- Notices — we may give notice via the Platform or email; you consent to electronic notices.
- Evidential value — Platform logs and records are agreed to have full evidential value in any dispute, unless proven to have been manipulated.
22. Governing Law & Disputes
These Terms are governed by the laws of the United Arab Emirates and the Emirate of Abu Dhabi. Subject to the internal mediation step in Section 8, the parties submit to the exclusive jurisdiction of the Abu Dhabi Courts (the Abu Dhabi Judicial Department). Exordium operates under a UAE mainland trade licence. To the extent permitted by Applicable Law, each party waives any right to bring or participate in a class or representative action.
23. Changes & Contact
We may update these Terms. We will give at least 15 days’ notice of material changes by email or a Platform notice; continued use after changes take effect is acceptance. We keep dated, versioned archives of prior Terms.
Contact. Exordium Data Management Cyber Security Services L.L.C, Al Hadi 3 St, Al MZEER’AH, Abu Dhabi, UAE. Email [email protected]. General inquiries: [email protected].