
Overview
A bug bounty program can complement responsible disclosure by rewarding high-quality, verified reports. OXVO can operate a structured bounty program with clear scope, rules of engagement, and severity-based rewards.
Controls & Practices
- Program scope and reward tiers defined in policy - Prefer coordinated disclosure to protect customers - Recommended: start with private bounty then expand - Use triage SLAs to keep researchers informed

More trust controls
Browse related security, privacy, and reliability controls across OXVO.
