Frequently Asked Questions
Answers to program launch, payouts, and responsible disclosure questions we hear most.
Frequently Asked Questions
Answers to the most common questions from researchers and program owners across the NidFul community.
Researchers
How fast do programs respond?
Most programs commit to acknowledging submissions within one business day and triaging within five. You can view SLAs per program on the policy page.
Can I test from outside the program’s country?
Yes, unless the policy explicitly restricts geographic locations. Always respect export controls and check for sanctions restrictions.
Are chained vulnerabilities rewarded?
Absolutely. Provide clear explanation linking each step; bounty multipliers apply when chains demonstrate higher impact.
Program Owners
How do we limit scope creep?
Use NidFul’s scope versioning. Communicate adjustments through announcement posts and update safe-harbor language when removing assets.
Can we require NDAs for private programs?
Yes. Upload NDA templates and NidFul will manage acceptance tracking before granting access.
How do we handle duplicate reports?
Triage can merge duplicates. When multiple researchers contribute unique insights, share partial bounties to maintain good relationships.
Payments & Compliance
Which currencies can we pay in?
Programs can pay in local currency (NGN, KES, ZAR, GHS) or USD/EUR. NidFul handles conversions automatically.
What tax documents do researchers receive?
Year-end summaries include total payouts in both local currency and USD, along with transaction references for tax filings.
How long are reports retained?
By default, 24 months. Adjust retention to meet internal policy or regulatory requirements (minimum 12 months for auditability).
Support
Where can we get real-time status updates?
Check the platform status page for uptime and incident history.
How do we escalate urgent issues?
- Use the Critical Escalation toggle when submitting reports.
- Email
security@nidful.comwith your program ID. - For government programmes, follow the shared incident hotline documented in your onboarding kit.
Need more? Explore Common Issues & Fixes or reach the support team via the channels listed in Additional Links & Support.