# Welcome!

Welcome to Secuna's user guide and our FAQs list! Be sure to check on this page for any questions or concerns. If you have any more questions that aren't here, you can hit us up at support\@secuna.io.


# What is Secuna Pentest?

Vulnerability Assessment and Penetration Testing

Secuna's Pentest service is faster than the normal or traditional Vulnerability Assessment and Penetration Testing (VAPT). We leverage the effectiveness of our Secuna platform to lessen the time to receive reports and properly handle the vulnerability management.

In Secuna's Pentest, once we discover a vulnerability in your website or applications, your team will be notified real time to start validating or fixing those discovered vulnerabilities. There's no need to wait for a month or two before you receive the whole VAPT report and start working for a fix.

With Secuna's Pentest, our experienced and trained in-house penetration testing team combines the effectivity of automated tools with the creativity and thoroughness of our manual penetration testing methods to get your apps ready for the next major launch.

Learn more: <https://www.secuna.io/product/pentest>


# What is Secuna Discover?

Bug Bounty Program

Secuna Discover is a continuous and agile cybersecurity program. It is designed to discover security vulnerabilities that traditional Penetration Testing can't find.

In Discover, trusted cybersecurity professionals on Secuna platform are incentivized to continuously look and test for potential security vulnerabilities.

Like Response, Discover is also compliant to [ISO/IEC 29147:2018](https://www.iso.org/standard/72311.html) (Vulnerability Disclosure), [ISO/IEC 30111:2019](https://www.iso.org/standard/69725.html) (Vulnerability Handling Processes), and welcomes a "See Something, Say Something" process that helps ensure that potential security vulnerabilities reports end up with your team instead of being disclosed over social media.

You can choose between 3 types of plans in Discover:

**Standard**

This plan is the best for early-stage funded startups with few assets which enables them to run and manage their own program.

**Professional**

This plan is the best for large and growing companies with many assets which enables their team to run and manage their own program.

**Enterprise**

This plan is the best for organizations without security teams. In Enterprise, Secuna's own cybersecurity team will help you managing your bug bounty program from setting the policy, validating the submitted vulnerability reports up to collaborating with cybersecurity professionals.<br>

Learn more: <https://www.secuna.io/product/discover>


# What is Secuna Response?

Vulnerability Disclosure Program

Secuna Response is a cost effective way to keep your websites and apps secure.

With Response, you can safely receive reports and act on security vulnerabilities found in your product and collaborate with cybersecurity professionals to quickly respond with an effective fix.\
\
This process is compliant to [ISO/IEC 29147:2018](https://www.iso.org/standard/72311.html) (Vulnerability Disclosure), [ISO/IEC 30111:2019](https://www.iso.org/standard/69725.html) (Vulnerability Handling Processes), and welcomes a "See Something, Say Something" process that helps ensure that potential security vulnerabilities reports end up with your team instead of being disclosed over social media.

Learn more: <https://www.secuna.io/product/response>


# General

## What is Secuna?

Secuna is a community-powered cybersecurity testing platform that connects organizations to vetted cybersecurity professionals around the world.

It is the only company in the Philippines to embrace and utilize crowdsourced security and cybersecurity researchers.

How do I get in touch with Secuna?

Choose your own adventure!

<support@secuna.io>\
<https://www.facebook.com/secuna.io/>\
<https://twitter.com/secunasecurity>

## Why would an organization invite hackers to break into their assets/products

The Vulnerability Disclosure Program (VDP) and Bug Bounty Program (BBP) have been proven to deliver excellent results in finding security vulnerabilities.\
\
Granting permission for security researcher to test software and systems is a great way to receive more vulnerability findings, giving your organization more knowledge and control, and ultimately reducing risk.

In fact, the Pentagon, US Army, and US Air Force are already doing it. They collaborated to security researchers from all over the world and they found it effective.

Photos shown below are the results from their programs. Photos credit to HackerOne.

![](https://downloads.intercomcdn.com/i/o/174661431/6ba8325c807ae461d76a3461/PENTAGON.jpg)![](https://downloads.intercomcdn.com/i/o/174661694/13f783d8361f541476c5eda0/ARMY.jpg)

## Does Secuna comply with ISO standards?

Yes. Secuna adheres to [ISO 29147](https://www.iso.org/standard/72311.html) and [ISO 30111](https://www.iso.org/standard/69725.html). In accordance with ISO 29147, Secuna has an established process through which disclosed security vulnerabilities by a security researcher are reviewed and triaged by the customer with the appropriate resolution information. With regards to ISO 30111, Secuna provides remediation advice on your team with the information necessary to begin resolving vulnerabilities that have been both triaged and validated.

## What is the relationship between the customer and security researchers?

The security researchers, hackers, bug bounty hunters are non-employee independent contractors of Secuna and have no contractual relationship with a customer. The terms that govern Secuna's relationship with security researchers is the Disclosure Policy.

## How do you screen security researchers?

At Secuna, we want to make sure that every security researcher on our platform is trusted and professional. To do so, we are performing the following steps:

1. Background Checking
2. Identity Verification
3. Video Interview

Soon, we will implement a Technical Assessment to ensure that they are skilled enough to test the assets of our clients.

Security Researchers around the world may participate, except for security researchers from countries the US has issued export sanctions or other trade restrictions against (e.g., North Korea, Iran, Iraq, etc.)

## Are the bugs found by security researchers kept confidential?

All Security Programs' default provision is that all security vulnerabilities discovered must be kept confidential. Customers may permit security researchers in publicly disclosing security vulnerabilities for general interest. Secuna urges all customers to consider this option, but is not necessary to do so.

## What happens if a security researcher “goes rogue” and discloses a security vulnerability publicly?

In reality, incidents of full public disclosure are extremely rare, and we actively work to prevent them.&#x20;

Our diclosure policy describes conduct that is acceptable and unacceptable. We monitor closely the correspondence and behavior of Secuna security researchers, and security researchers are penalized for failing to comply with this policy.

In the case of an incident involving public disclosure, our team will contact the security researcher to ask them to delete the vulnerability details they have posted and to warn them of the potential consequences of unauthorized disclosure.

Secuna reserves the right to issue a warning to a security researcher and/or temporarily or permanently revoke access to the Secuna platform, depending on the severity of the breach.

## I do not want security tests to be run on my production environment. How can I avoid this?

In reality, security testing in production is recommended as it typically has the best data quality, and it is always accessible by cybercriminals.&#x20;

Security Testing does not usually have any negative impact on the systems. But the best way to avoid security testing in a production environment is to set up a testing environment with sample data for security testing.

## What types of things can your security researchers test?

Security Researchers on Secuna platform can assess and test anything programmed with code. Security researchers love testing mobile apps, website apps, hardware, IoT devices, and everything in between!

They are more active and will find severe security vulnerabilities if security programs offer bug bounties.

## Which payment options are available?

PayPal is our primary method of payment, but occasionally we use Bitcoin to handle bounties. If we are unable to process the bug bounty through PayPal for some reason, please contact our support team at <support@secuna.io>, and we will find another way to pay the bug bounty to security researchers.<br>


# Programs

## Can the researchers access private program?

No. The program must manually invite the security researcher if they want the researcher to participate in it their program.

## How do I rename my security program?

The program rename feature is already on our pipeline, but for now, kindly send us an email at <support@secuna.io>, and we'll help you out.

## How much is the payment processing fee?

We charge bug bounty programs a 20% fee per transaction (awarded security vulnerability) to help cover payment processing (PayPal), tax administration, and platform maintenance.

## What happens when my bug bounty pool is running low?

Every programs running a Secuna Managed service has a designated Customer Success Manager (CSM) and they will work with you to evaluate and adjust bug bounty pool as needed.

## Can I get a sample VAPT report for Secuna Pentest?

Yes, drop an email to <support@secuna.io> then we will provide you a sample VAPT report.

## For Secuna Pentest, What kind of deliverables can I expect from Secuna?

In Secuna Pentest service, you will receive a detailed Vulnerability Assessment and Penetration Testing (VAPT) report which includes detailed content for each discovered security vulnerabilities with Proof of Concept (PoC) and steps to reproduce. The report also comes with Executive Summary and Recommendations perfect for sharing with stakeholders.

After the service, we will also issue a Certificate of Cybersecurity Assessment powered by Credential.net.

## For Community-Powered VAPT, How is Secuna different from traditional VAPT models?

There are three main characteristics that set us apart from Traditional VAPT models:&#x20;

1. We source our penetration testers from a large global talent pool of vetted cybersecurity professionals, which means we can be agile without compromising quality or increasing price;&#x20;
2. We deliver all the reporting and communication through a modern online platform, making it easier for you to collaborate continuously with the penetration testers and integrate seamlessly with your SDLC.; and
3. We provide a max of 10 penetration testers to assess the security of your assets rather than the traditional 2-3 penetration testers. Because we believe in the following:\
   \- More eyes, More results\
   \- More testers, More skills and experiences\
   \- Much more faster because of the number of testers


# Security Researchers

## I'm under 13 years of age and what is this?

We allow bug bounty payments to any age. However, the [Children's Online Privacy Protection Act](http://www.ftc.gov/ogc/coppa1.htm) limits our ability to collect personal identifiable information (PII) from children under 13 years of age, so you will need to claim your bug bounties through your parent or legal guardian.

## Can I donate my bug bounty to a charity?

Of course! Some companies on our platform, or even us at Secuna, may also increase the donation value in the event you decide to donate.&#x20;

Just let us know if you'd like to donate the bug bounty to a charity and we'll be the one to contact and process the donation for you.

## Why did I not receive the full bounty awarded to me?

Bug bounties are currently disbursed through PayPal and depending on his/her location, the recipient is responsible for any fees incurred.

You can review PayPal's transaction fee table and policy [here](https://www.paypal.com/en/webapps/mpp/paypal-fees).

## Why can’t I receive payments in my currency?

Our 2 main payout providers are PayPal and Bitcoin. You can only receive payments in the currencies these 2 options provide. If they don’t support your specified currency, then you unfortunately can’t receive payments in that currency. A work around for this is to receive your payment in US dollars and then have the funds converted to the currency you desire.

## When and how do I get my bug bounties?

Valid and accepted security vulnerability submitted to a bug bounty program on Secuna will result in a bug bounty payment to your account. After your submission is accepted by the program owner or Secuna Infosec Team, your reward will be paid out the following Friday. Note that for us to pay you on time, the program owner will need to send us the bug bounty payment before 12:00am GMT+8 Friday morning.

Secuna offers these 2 payout methods for monetary awards:

**PayPal** - As soon as the payment is initiated, you'll receive your award instantly, given that your PayPal account is set up to properly receive the amount of money Secuna is trying to send.

**Bitcoin through Paylance** - As soon as the payment is processed, you'll receive your award instantly.

Have more questions about getting paid? Reach out to <hackers@secuna.io> team for more information.

## What rewards can I get?

There are three main rewards that you could possibly get:

**Points** – The Secuna platform awards you points when you submit a valid security vulnerability depending on the severity level. Using these points, you have a better chance to get invited to our private security programs.

**Bug Bounty** – It is a financial compensation that you receive from a security program when you submit a valid security vulnerability to their bug bounty program.

**Swag** - You can also earn Swag from different security programs by reporting a valid security vulnerability.

## Is it okay or allowed to use automated vulnerability scanners while performing security research?

We do not recommend security researchers in running automated vulnerability scanners against the companies that use our platform.

We highly recommend reading the vulnerability disclosure policy of each security program because some of them allow you to use scanners against their assets.

## How long will it be after the bug I submitted is validated?

Response time can vary by the security program, security programs that are managed by Secuna typically have a faster response time. Please give at least a week before you request a follow-up.

## What is the KYC process?

We require security researchers to complete the KYC process before we let them browse in our platform and report to any open security programs.

KYC Process

1. Creation and verification of your Secuna account.
2. Background Research and Identity Verification.
3. Video Interview

In the following months, we will implement Technical Assessment.

## What are the rules?

Before you get started, we extremely recommend you to read our [Terms and Conditions](https://secuna.io/terms), [Privacy Policy](https://secuna.io/policy), and [Disclosure Policy](https://secuna.io/disclosure-policy) to learn what is expected from you. We want to make sure that we're all on the same page before you join Secuna and participate in our security programs.

## I found a security vulnerability in an organization that is not listed on your platform. What should I do?

If you are unable to find a published vulnerability disclosure policy for the organization, you can email us at [support@secuna.io](https://app.intercom.io/support@secuna.io), and we'll try to help.

You may also report it via Coordinated Vulnerability Disclosure Assistance: <https://app.secuna.io/coordinated-vulnerability-disclosure-assistance>


# Adding and Removing Program Team Members

**Adding program team members**

* Go to [Program Settings](https://app.secuna.io/program-settings/) then select [Team Members](https://app.secuna.io/program-settings/team-settings).

![](https://downloads.intercomcdn.com/i/o/271040540/ac07ef2f581c841747deb331/image.png)

* Click the **Add** button

![](https://downloads.intercomcdn.com/i/o/271041167/cfdd57c7716b63a05a84946d/image.png)

* Enter the email address of your team member and choose a role.

| **Role**   | **Description**                                              | **Permissions**                                                                                                                              |
| ---------- | ------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Owner      | The user who created the program.                            | <ul><li>Modify Program Settings</li><li>Invite Team Members</li><li>Access and View Submissions</li><li>Access Billing Information</li></ul> |
| Admin      | The user who can invite team members and access submissions. | <ul><li>Invite Team Member</li><li>Access and View Submissions</li></ul>                                                                     |
| Triager    | The user who can access submissions.                         | <ul><li>Access and View Submissions</li></ul>                                                                                                |
| Accounting | The user who can access the billing information.             | <ul><li>Access Billing Information</li></ul>                                                                                                 |

* Then click "**Invite to team**" to invite the user to your program.
*

**Removing program team members**

* Go to [Program Settings](https://app.secuna.io/program-settings/) then select [Team Members](https://app.secuna.io/program-settings/team-settings).
* Choose the team member and click **Delete** button.
* A pop-up will appear on your screen, click **Proceed** button to remove the program team member.


# Communicating with Researchers and Co-Admins as Program Admin

### Commenting on a report to Researchers <a href="#commenting-on-a-report-to-researchers" id="commenting-on-a-report-to-researchers"></a>

To comment on a report, select the **Post comment** tab and choose **Post to all participants**.

![](https://downloads.intercomcdn.com/i/o/270785016/26f0030fa9a44e9ba39673fa/image.png)

Then you may now enter your comment/message and press **Post comment** to submit.

![](https://downloads.intercomcdn.com/i/o/270785366/546296a5d152e03dcfd8f4c5/image.png)

### Commenting on a report to Co-Admins <a href="#commenting-on-a-report-to-co-admins" id="commenting-on-a-report-to-co-admins"></a>

To comment on a report internally, select the **Post comment** tab and choose **Post to team only**.

![](https://downloads.intercomcdn.com/i/o/270786527/33607d494ab845d599e04b6c/image.png)

Then you may now enter your comment/message and press **Post comment** to submit.

![](https://downloads.intercomcdn.com/i/o/270786801/615367179b4ff2b870d24cca/image.png)


# Paying bounties

Secuna makes it easy to pay rewarded bug reports. You can choose from these 2 options to pay a hacker:

| **Option**  | **Details**                                                                                                                                                                                                                                                                                                                     |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Credit Card | <p>If you saved your card during the payment of your program subscription in onboarding steps, you may use it to pay for bounties.<br><br>If not, when you click the pay button on <a href="https://app.secuna.io/billing/bounty-payouts">Bounty Payouts</a> page, a modal will pop up to set your card and pay the bounty.</p> |
| PayPal      | If you prefer using PayPal, clicking the pay button will redirect you to PayPal's website to pay the bounty.                                                                                                                                                                                                                    |

We highly recommend paying the bug reports 2 days after you rewarded it or within a week.

If you encounter a technical problem, please reach out to <support@secuna.io> or Secuna Technical Program Manager.


# Awarding bounties on bug reports

Once you have acknowledged the report as a valid finding, you can now award it a bug bounty. Other programs wait until the bug report is resolved but most of the programs prefer to award a bug bounty once the finding has been confirmed as valid.

To award a bounty, kindly follow the guide below:

* Go to [submissions](https://app.secuna.io/submissions) page and find a bug report.
* Then select the "**Change status**" tab and pick the **Accepted** status.\
  (Please note that changing the status to Accepted is required to award a bounty to a bug report)

![](https://downloads.intercomcdn.com/i/o/270773448/e431a4d4dd990ca32b6570de/image.png)

* Press the **Change status** button to display the message and to show the **Set award** tab.

![](https://downloads.intercomcdn.com/i/o/270768962/8419fb4a143854648ef2c717/image.png)

* Next step is to select the "**Set award**" tab above the comment box and choose an action on the left side.

![](https://downloads.intercomcdn.com/i/o/270770928/f353401b3df85de27c609406/image.png)

* Press the **Set award** button to award the bounty to researcher.

![](https://downloads.intercomcdn.com/i/o/270775462/1acf5647a4cfe95f828e104f/image.png)

For technical questions, kindly reach out to <support@secuna.io> or Secuna Technical Program Manager.


# Create an account as Security Researcher

Congratulations on deciding to use Secuna as your platform in submitting potential security vulnerabilities!

Below are the steps to create an account as Security Researcher.

* Go to <https://www.secuna.io/> and click the **Sign up** button. You should see the same page shown in the picture below.

![](https://downloads.intercomcdn.com/i/o/268920749/3bb3693bed3f04d7936f3759/image.png)

* Click **Security Researcher** - the sign up as security researcher page displays.

![](https://downloads.intercomcdn.com/i/o/268935099/554b4568c3ceac78684ad5d3/image.png)

* Enter the required details in the corresponding fields, then click the **Sign Up** button.

![](https://downloads.intercomcdn.com/i/o/268935218/06e548f501f837e802775832/image.png)

* Go to the Inbox of your email account and find an email with the subject **\[Secuna] Confirm your Email Address**, then click **Confirm Email Address**. Your browser will automatically redirect you back to Secuna with a success message Email Verified!

![](https://downloads.intercomcdn.com/i/o/268935358/9f0f85b2f61054c14ca69277/image.png)

* Click the **Continue to sign in** button to display the login form.

![](https://downloads.intercomcdn.com/i/o/268923486/365fc3e5537d332a3d246550/image.png)

* Enter the registered email address and password in the corresponding fields. The **Let's set-up your Two-Factor Authentication** page displays.

![](https://downloads.intercomcdn.com/i/o/268923632/d2e7990ec877de0061f78a39/image.png)

* Download an **Authenticator** application if not yet installed in your smart phone; otherwise, click the **Continue** button. The page with QR code displays.

![](https://downloads.intercomcdn.com/i/o/268924030/448776fc070449885818c390/image.png)

* Access the **Authenticator** in the mobile phone where the application is installed then scan the QR code. Enter the current 6-digit authenticator code in the corresponding field, then click the **Continue** button.

![](https://downloads.intercomcdn.com/i/o/268924799/2a4360e34c60c6d4a563d667/image.png)

* Save the displayed recovery code in your hidden notes or copy-paste to a notepad and tick the checkbox, then click the **Continue** button. The Welcome to Secuna! page displays.

![](https://downloads.intercomcdn.com/i/o/268936129/c918a5b80e74c9f64f24acb2/image.png)

* Click the **Start Account Verification** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268936235/0c0eaaea3199edcc1e880ac5/image.png)

* Provide the necessary personal details then click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268936504/c23c2229c9c142989afddb9f/image.png)

* Provide your address details then click the **Continue** to proceed.

![](https://downloads.intercomcdn.com/i/o/268936712/d4299e877f55caf6db47ca40/image.png)

* Upload the back and front of your valid ID, and upload a selfied with the ID. Once done, click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/270546695/2ca9a9d550d262dc89c66d61/image.png)

* Last step is to schedule a date for your virtual interview with Secuna. Once done, click the **Submit for verification** button. A page with message Account Verification In Progress displays.

![](https://downloads.intercomcdn.com/i/o/270550293/b118f56c6d823e709f135cc3/image.png)

Once Secuna verifies your account, you may now login to access your account and start helping programs.


# Create an account as Organization

Congratulations on deciding to set up your security program on Secuna!

\
Below are the steps that will help you in creating your account:

* Go to <https://www.secuna.io/> and click the **Sign up** button. You should see the same page shown in the picture below.

![](https://downloads.intercomcdn.com/i/o/268920749/3bb3693bed3f04d7936f3759/image.png)

* Click **Organization** - the sign up as organization page displays.

![](https://downloads.intercomcdn.com/i/o/268921896/c389430708c78df370a1a1d6/image.png)

* Enter the required details in the corresponding fields, then click the **Sign Up** button.

![](https://downloads.intercomcdn.com/i/o/268922280/f21abf9877b593fd86ac729a/image.png)

* Go to the Inbox of your email account and find an email with the subject **\[Secuna] Confirm your Email Address**, then click **Confirm Email Address**. Your browser will automatically redirect you back to Secuna with a success message Email Verified!

![](https://downloads.intercomcdn.com/i/o/268922869/e2f138b6edc323802945511a/image.png)

* Click the **Continue to sign in** button to display the login form.

![](https://downloads.intercomcdn.com/i/o/268923486/365fc3e5537d332a3d246550/image.png)

* Enter the registered email address and password in the corresponding fields. The **Let's set-up your Two-Factor Authentication** page displays.

![](https://downloads.intercomcdn.com/i/o/268923632/d2e7990ec877de0061f78a39/image.png)

* Download an **Authenticator** application if not yet installed in your smart phone; otherwise, click the **Continue** button. The page with QR code displays.

![](https://downloads.intercomcdn.com/i/o/268924030/448776fc070449885818c390/image.png)

* Access the **Authenticator** in the mobile phone where the application is installed then scan the QR code. Enter the current 6-digit authenticator code in the corresponding field, then click the **Continue** button.

![](https://downloads.intercomcdn.com/i/o/268924799/2a4360e34c60c6d4a563d667/image.png)

* Save the displayed recovery code in your hidden notes or copy-paste to a notepad and tick the checkbox, then click the **Continue** button. The Welcome to Secuna! page displays.

![](https://downloads.intercomcdn.com/i/o/268925148/02322bde8be18296055ebdec/image.png)

* Click the **Verify your company** button - the Company Verification page displays.

![](https://downloads.intercomcdn.com/i/o/268925357/5dda370f666ddc2d945c9123/image.png)

* Provide details about you and your organization. You are also required to upload necessary documents about you and your organization. Once done filling out the form, click the **Submit for verification** button. A page with message Your company is being verified displays.

![](https://downloads.intercomcdn.com/i/o/268926371/9edad71057ee7e103e88b1b9/image.png)

Once Secuna verifies your account, next step would be choosing the program you're interested in. Please see guides below for specific program.

How to setup Secuna Response program?How to setup Secuna Discover program?


# Setup Secuna Response program

Congratulations! Your account has been verified by Secuna and you can now continue setting up your program.

\
Below are the steps that will get you up and running:

![](https://downloads.intercomcdn.com/i/o/268927578/4319668abb373f5295820232/image.png)

* Select **Response** by clicking the **Select & Continue** button - the **Let's build your security program page** displays.

![](https://downloads.intercomcdn.com/i/o/268928252/9e768497dc093b9d928caec9/image.png)

* Select the Cluster of your organization and click the **Continue** button.

![](https://downloads.intercomcdn.com/i/o/268928735/0eb717720cd69dac7c92dfd5/image.png)

* Next step is setting up the profile of your program. Enter the details for each corresponding fields, then click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268929051/6f391d299b6413309d1f3bf1/image.png)

* Next step is to review and modify the Policy for your program. Once done, click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268929314/0e43f32ef551c234e69a59d7/image.png)

* Next step is setting your in-scope and out-of-scope assets. Click the **Add Asset** button to select the type of your asset and provide the necessary details of your asset. Once done, click the **Continue** button to proceed.
* Review your program subscription and provide the necessary details for the payment method. The payment method will be used for your program's recurring plan subscription. Once paid, click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/270539667/b2c5ee404d5666688e263b02/image.png)

* This is the last step of onboarding. Review your program to check if everything is right then click the **Launch my program** button to run your program.


# Setup Secuna Discover program

Congratulations! Your account has been verified by Secuna and you can now continue setting up your program.

\
Below are the steps that will get you up and running:

![](https://downloads.intercomcdn.com/i/o/268927578/4319668abb373f5295820232/image.png)

* Select **Discover** by clicking the **Select & Continue** button - the **Let's build your security program page** displays.

![](https://downloads.intercomcdn.com/i/o/268931566/fbd936969e9785c07f832d66/image.png)

* Select the plan for your program, then click the **Continue** button.

![](https://downloads.intercomcdn.com/i/o/268931834/23619a0dfc339f0d3e782cb0/image.png)

* Next step is setting up the profile of your program. Enter the details for each corresponding fields, then click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268931973/aefa7552f372c220201af584/image.png)

* Next step is to review and modify the Policy for your program. Once done, click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268932037/b77c6f5815fc30cc666f3dfd/image.png)

* Next step is setting your in-scope and out-of-scope assets. Click the **Add Asset** button to select the type of your asset and provide the necessary details of your asset. Once done, click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268932162/bd2d545e1f21d3259ce1585b/image.png)

* You have the option to choose from ready-made bounty rates or provide your preferred bounty rates. Once done, click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268932518/b9ec6da1345c9f111e2fe3a8/image.png)

* Review your program subscription and provide the necessary details for the payment method. The payment method will be used for your program's recurring plan subscription and bounty payment for every rewarded report. Once paid, click the **Continue** button to proceed.

![](https://downloads.intercomcdn.com/i/o/268933457/3386d5e86110f52275c3bd65/image.png)

* This is the last step of onboarding. Review your program to check if everything is right then click the **Launch my program** button to run your program.


# Markdown Syntax

Secuna supports markdown syntax on reports and program policy pages.

## Headers <a href="#headers" id="headers"></a>

Markdown Input

```
# Header 1

## Header 2

### Header 3
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177906111/09bfe45f22a9c919bc77a485/Screen+Shot+2020-01-18+at+7.42.54+PM.png)

## Blockquotes <a href="#blockquotes" id="blockquotes"></a>

Markdown Input

```
> One line in blockquote
> How about two?
> How about more lines in blockquote
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177906476/fe3d1805d271d45e46c1350c/Screen+Shot+2020-01-18+at+7.47.17+PM.png)

## Text Emphasis <a href="#text-emphasis" id="text-emphasis"></a>

Markdown Input

```
*This text is italicized*
**This text is bold**
~~This text is deleted~~
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177906701/6ba051ce5002565d2ff2226e/Screen+Shot+2020-01-18+at+7.49.46+PM.png)

## Lists <a href="#lists" id="lists"></a>

### Unordered Lists <a href="#unordered-lists" id="unordered-lists"></a>

Markdown Input

```
* Quezon City
* Makati City
* Taguig City

or

+ Quezon City
+ Makati City
+ Taguig City

or 

- Quezon City
- Makati City
- Taguig City
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177906979/116aca208e78e60d78d2d4f4/Screen+Shot+2020-01-18+at+7.53.02+PM.png)

### Ordered Lists <a href="#ordered-lists" id="ordered-lists"></a>

Markdown Input

```
1. Red
2. Green
3. Blue
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177907205/c2f1b21c94e790ffd7c19231/Screen+Shot+2020-01-18+at+7.55.57+PM.png)

## Links <a href="#links" id="links"></a>

### Inline-style links <a href="#inline-style-links" id="inline-style-links"></a>

Markdown Input

```
Kindly check out this [example link](http://example.com/).
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177907431/396be851e63688a593925b79/Screen+Shot+2020-01-18+at+7.58.50+PM.png)

### Reference-style links <a href="#reference-style-links" id="reference-style-links"></a>

Markdown Input

```
Aside from [OSCP][1], most of the cybersecurity professionals are also recommending [OSWE][2] and [OSCE][3] certifications.

[1]: https://www.offensive-security.com/pwk-oscp/
[2]: https://www.offensive-security.com/awae-oswe/
[3]: https://www.offensive-security.com/ctp-osce/
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177908061/0a2b83941d759226b943bb75/Screen+Shot+2020-01-18+at+8.06.43+PM.png)

## Code <a href="#code" id="code"></a>

### One-line / In-line code <a href="#one-line--in-line-code" id="one-line--in-line-code"></a>

Markdown Input

```
The following payload `javascript:alert(document.domain)` executes an XSS alert on your website.
```

Markdown Output

![](https://downloads.intercomcdn.com/i/o/177908428/cdfc8ff88b398dd9f27744d5/Screen+Shot+2020-01-18+at+8.10.20+PM.png)

### Multi-line code <a href="#multi-line-code" id="multi-line-code"></a>

Markdown Input

````
An XML External Entity attack is a type of attack against an application that parses XML input and allows XML entities. XML entities can be used to tell the XML parser to fetch specific content on the server.

```
<?xml version="1.0"?>
<!DOCTYPE data [
<!ELEMENT data (#ANY)>
<!ENTITY file SYSTEM "file:///etc/passwd">
]>
<data>&file;</data>
```
````

\
Markdown Output

![](https://downloads.intercomcdn.com/i/o/177908961/12734aefa9f0daf255cbfb53/Screen+Shot+2020-01-18+at+8.15.51+PM.png)

### Table <a href="#table" id="table"></a>

Markdown Input

```
| ID   | Names |
| --------- | ------- |
| 1    | Ameer |
| 2 | Nathu |
| 3      | Atom |
```

\
Markdown Output<br>

![](https://downloads.intercomcdn.com/i/o/177909122/5dbc09d156d1d83585b15539/Screen+Shot+2020-01-18+at+8.18.49+PM.png)


# Bug Bounty Program (BBP)

Bug Bounty Program (BBP) is a program that offers cash rewards (bug bounties) in exchange for their security vulnerability findings. The advantage of this program is all kind of skilled security researchers will test your assets to find possible security vulnerabilities.

**Note**: To offer a bug bounty on Secuna, you'll be required to set up credit card details.

Check Secuna Discover: <https://www.secuna.io/product/discover><br>


# Vulnerability Disclosure Program (VDP)

Vulnerability Disclosure Program (VDP) helps organizations to receive, coordinate, and act on security vulnerability submissions from our vetted security researchers. Our platform will automatically award reputation points to researchers who have reported a valid vulnerability.

Check Secuna Response: <https://www.secuna.io/product/response><br>


# Difference between an Open and a Private program

**Open Programs**

Open programs are open to all approved and KYC-verified security researches on Secuna platform. It gives the program better coverage and exposure to researchers. But same with private program, vulnerability reports can remain private and confidential unless they granted the researcher with to fully disclose it or publicly disclose it.

**Private Programs**

Private programs are known only to those security researchers invited to the program. All vulnerability reports for these programs remain private and confidential unless they granted the researcher with to fully disclose it or publicly disclose it.

As private programs limit the number of security researchers invited to the security program, the number of report submissions is also limited to enable the security program to get the hang of receiving and triaging vulnerability reports. All security programs begin as private, but as they become more proficient in handling reports, they can choose to go public if desired.


# Program Roles

All security programs on Secuna start with **Owner** role and they can invite new team member and assign specific role.

### Roles  <a href="#roles" id="roles"></a>

```
Owner
|- Modify Program Settings
|- Invite Team Member
|- Access and View Submissions
|- Access Billing Information
|- Invite Security Researchers (Private Program)

Admin
|- Modify Program Setting
|- Invite Team Member
|- Access and View Submissions
|- Invite Security Researchers (Private Program)

Triager
|- Access and View Submissions

Accounting
|- Access Billing Information
```


# Report statuses on Secuna

All reports are either Open or Closed and can be changed to a variety of different statuses.

### Open Report Statuses <a href="#open-report-statuses" id="open-report-statuses"></a>

![](https://downloads.intercomcdn.com/i/o/270730259/70fcb5a0bf383b84de9b9e66/Screen+Shot+2020-11-26+at+10.40.34+PM.png)

**Closed Report Statuses**

![](https://downloads.intercomcdn.com/i/o/270730619/01510b1edac7e8ad3638a86a/Screen+Shot+2020-11-26+at+10.41.28+PM.png)


# Bug Bounty Table

Suggested Bug Bounty per Severity Level

At Secuna, every bug has a severity level assigned based on the security impact. To help you decide which security vulnerabilities should be resolved first, Secuna has the following types of severities:

* **Critical Severity** - A vulnerability whose exploitation could allow remote code execution without user interaction. Exploitation likely results in a root-level compromise of servers or infrastructure devices.
* **High Severity** - A vulnerability whose exploitation could allow access to user’s information without authorization. Exploitation could result in elevated privileges, significant data loss, or downtime.
* **Medium Severity** - A vulnerability requiring user privileges to be exploited successfully. Exploitation would involve the attacker to manipulate individual victims by using social engineering tactics, live on the same local network as the victim, or set up denial of service assaults. Often only very restricted access is available.
* **Low Severity** - Low-range vulnerabilities typically have minimal effect on an organization’s business.

For companies running a Bug Bounty Program on Secuna, we created these bug bounty rates that you may follow to reward the valid submissions of security researchers based on the severity of their reports.

For startup companies (referred to as “Startups”), we recommend a minimum of $100 USD for low severity vulnerabilities.<br>

![](https://downloads.intercomcdn.com/i/o/202352185/52f919e8aa32ca58096fbcf7/Screen+Shot+2020-04-21+at+3.44.58+PM.png)


# Disclosure Types

Report disclosure enables organizations to be transparent about discovered security vulnerabilities in their security program.

Programs can choose from 4 disclosure types when a security researcher requested for disclosure:

* **Public Disclosure**\
  Public disclosure will make the report accessible to anyone online without logging in to Secuna platform. The full contents of the report are visible including the:\
  \- Security Vulnerability Information\
  \- Attachments\
  \- Comments<br>
* **Full Disclosure**\
  Full disclosure is visible only to all approved security researchers and programs on Secuna platform. The full contents of the report are visible including the:\
  \- Security Vulnerability Information\
  \- Attachments\
  \- Comments<br>
* **Partial Disclosure**\
  Only the title of the report is visible. All security vulnerability information, attachments and comments are hidden.<br>
* **Non-disclosure**\
  Disclosure of the report is not allowed.<br>


# Privacy Policy

Updated: 9th of February 2020

At Secuna ("we", "our", or "us"), our utmost commitment is to protect and respect the data privacy of the users of our website ("site" or "platform") and customers ("clients") of our products and services (collectively, "services"). We take responsibility for complying with the [National Privacy Commission](https://www.privacy.gov.ph/)’s [Data Privacy Act of 2012](https://www.privacy.gov.ph/data-privacy-act/) (DPA). The Privacy Policy ("Policy") explains our online and offline information practices and provides what personal information ("Personal Information") we may collect from and about you, how we intend to use that Personal Information, and how we will ensure to protect it. For any questions and concerns regarding this Policy, you can contact us at any time by emailing <privacy@secuna.io> or writing to the Secuna Privacy Team at Level 10-01, One Global Place, 5th Avenue cor. 25th Street Bonifacio Global City, Taguig City, Philippines. Please note our platform can contain links to third-party websites, apps, and services. Their privacy practices will govern information collected by these third parties. We encourage you to learn about the privacy practices of these third parties before beginning any engagement with these third parties.

### ACCEPTANCE OF PRIVACY POLICY <a href="#acceptance-of-privacy-policy" id="acceptance-of-privacy-policy"></a>

By using our platform, you accept our Privacy Policy, including our [Terms and Conditions](https://secuna.io/terms); and acknowledge our collection, use, disclosure, and retention of your personal information as described in our Privacy Policy. If you do not agree with our Privacy Policy or our Terms and Conditions, you should not proceed in accessing our platform.

### INFORMATION WHICH SECUNA COLLECTS <a href="#information-which-secuna-collects" id="information-which-secuna-collects"></a>

You provide us with information in the following circumstances:

* **When you contact us.**\
  You provide personal information when contacting us through our sites or platform. For example, we will collect your full name, username, company name, job position, email address, home or company address, and phone number when you register or subscribe to email lists.
* **When you create a customer account on our platform.**\
  You are required to provide us your identity and contact data, such as first and last name, email address, company name, job position, mobile number, company-issued ID, and company registration documents. Customer account holders can provide or update us with additional information in the course of their use of our platform.
* **When you create a hacker account on our platform.**\
  You are required to provide us your identity and contact data, such as first name, middle name, last name, username, email address, country, valid government-issued IDs, and video interview. Hacker account holders can provide or update us with additional information in the course of their use of our platform.
* **When you apply for an open job position.**\
  Our recruiting service provider will collect your resume, curriculum vitae, and any additional information you choose to provide to us, including but not limited to employment history and education, when you apply for jobs through our sites.
* **When you participate in our events and social media.**\
  We also obtain information about you when you participate or engage in an activity, event, interact with or otherwise communicate with our social media accounts.
* **When you participate in our surveys.**\
  If you decide to participate and engage in our online surveys, you may be asked to provide your complete name and email address. You voluntarily provide all information gathered from your participation in our surveys. We may use this data to enhance our platform and/or services in any way that is compatible with the policies set out herein.
* **Automatically collected information.**\
  When you visit our sites, certain information will be automatically collected from your computer, mobile phone, or other access devices. This information can include your location, computer operating system, Internet Protocol (IP) address, access times, browsing history and web log information, browser type and language, and "clickstream" data, such as domain names and page views.

### HOW SECUNA USES INFORMATION <a href="#how-secuna-uses-information" id="how-secuna-uses-information"></a>

We process your personal information to manage your account and provide the services outlined in our Terms and Conditions in order to fulfil our agreement with you. Furthermore, as we are interested in being responsive to you and in ensuring that our products and Services function properly, we will use the information that we collect from you to:

* To personalize our websites in order to provide you with the content from our websites and to show it to you and your device in the most efficient way;
* To allow us to support, sign in and verify access by registered user;
* To monitor and analyze trends, usage, and activity related to our sites and services in order to contribute to the enhancement of our system;
* To establish and administer commercial relationships and transactions under our Terms and Conditions;
* To keep our sites safe and secure, which includes enforcing our Terms and Conditions;
* To communicate and interact with you so that we can keep you up-to-date on the latest developments, announcements, and other information about our services and sites (including events, newsletters, and additional information);
* To send you marketing communications that we believe may be of interest to you, including via email and SMS in accordance with applicable law and in accordance with your preferences;
* To contact you about your account, answer your questions, or reply to any communications you send us;
* To troubleshoot any problems with your account or the Services, in our legitimate interest;
* To provide statistical information about our users to third parties (but only limited information is provided to third parties so that they are unable to distinguish any individual user from that information);
* To review and enforce compliance with our Terms and Conditions, guidelines, and policies; and
* To exercise or defend our legal rights, or to comply with judicial orders.

### HOW SECUNA SHARES AND DISCLOSES YOUR INFORMATION <a href="#how-secuna-shares-and-discloses-your-information" id="how-secuna-shares-and-discloses-your-information"></a>

We may share your information as outlined in this Policy (e.g. with our third-party service providers; to comply with legal responsibilities, protect and defend our rights and property) even or without your consent.

* We share your personal information with service providers that help with parts of our business operations, such as cloud storage providers, IT service providers, and search engine and analytics providers that help us improve and optimize our sites.
* We share your personal information with third-parties in order to comply with regulations and respond to lawful requests and legal process, enforce our Terms and Conditions, including investigation of potential violations thereof, detect and prevent, or otherwise address fraud, security or technical issues, or protect against harm to the rights, property, or safety of Secuna, its users or the public as required or permitted by law.
* We will only transfer, share, or disclose your personal information to a third party if the purpose is to sell, transfer, divest, or disclose all or a portion of our business and/or assets to other companies in connection with or during negotiation of any merger, financing, acquisition, bankruptcy, dissolution, transaction, or proceeding.
* We will otherwise share your information as directed by you or subject to your consent.
* With respect to those users who have a username (and personal photo or avatar, if any, associated with your account), such information will only be displayed and made available on our sites.
* When you enter into a financial transaction (to pay us or pay us) associated to our Services, we may, directly or via/through a third-party payment service provider, obtain the financial information about you for the purposes of this Privacy Policy. We will only use this data in association with the financial transaction and will not share it with third parties except to the extent needed to finish the financial transaction or comply with applicable law.
* Information you provide through your participation in research projects, community discussions, chats, events, and any correspondence will be shared with other users, our customers, or otherwise displayed on our Sites.

### WHERE SECUNA STORES YOUR PERSONAL INFORMATION <a href="#where-secuna-stores-your-personal-information" id="where-secuna-stores-your-personal-information"></a>

Our sites and servers are hosted in a location in the United States of America or Singapore. The personal information we obtain from you will be transferred and stored to a server located in the Singapore. We will take all reasonable steps to ensure that your personal information is handled and processed securely and in accordance with our policy.

### SECURITY AND RETENTION <a href="#security-and-retention" id="security-and-retention"></a>

To protect the personal information submitted to us, we follow generally accepted industry standards, from during transmission until we receive it in our system. However, we cannot guarantee nor ensure the security of any personal information you transmit over the Internet or through our websites will be 100% secure. We will retain your Personal Information only for the period necessary to fulfill the purposes for which we collected it, such as for satisfying any legal, accounting, or reporting requirements and where we are required to assert or defend against claims, until the end of the relevant retention period or until the claims in question have been settled. To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized use or disclosure of your Personal Information, the purposes for which we process your Personal Information, and whether we can achieve those purposes through other means and the applicable legal requirements. Following the applicable retention period, we will promptly and securely destroy your Personal Information under applicable laws and regulations.

### HOW SECUNA USES COOKIES <a href="#how-secuna-uses-cookies" id="how-secuna-uses-cookies"></a>

We use cookies to collect information over time about our users' website browsing activities. Cookies enable us to determine and count the number of users on our websites to see how these users progress. Using cookies enables us enhance our services and improve the way our websites operate.

The types of cookies we use includes:

* **Cookies that are strictly essential**\
  When you log in to our platform, Secuna will use the required cookies for the operation of our websites. They include, e.g., cookies that enable users to log into secure areas of our websites and enables us to know when you’re logged in or not. Please note that we use these encrypted cookies as user identifier.
* **Cookies for analytics and performance**\
  When you visit and use our platform, Secuna will use the cookies to assess the performance of our websites. These cookies help us to understand how our websites are used and interacted by our visitors and users and to determine whether they have viewed a specific security program, profile, links, or website pages.\
  \
  We also use Google Analytics to gather aggregated statistics about the user of our services. These cookies help us measure traffic and improve the performance of our website and services. This information may be transmitted and stored on Google's servers. By downloading and installing an add-on by Google (located at [https:/tools.google.com/dlpage/gaoptout](https://tools.google.com/dlpage/gaoptout?hl=en)), you can opt-out from this collection of information.&#x20;
* **Cookies for functionality**\
  When our users return to our websites, Secuna will use the cookies to recognize them. Also, these cookies enable us to personalize their content, such as greeting users by their name, remembering the preferences of a user (for example, choosing the language or region of a user), and tailoring our marketing outreach to our users based on their profile and involvement with our websites.
* **Cookies for advertising and targeting**\
  To be specific, these cookies record the visit of a user to our sites, the pages that a user has visited and the links that a user has followed. We use this data to make the website more relevant to users and enhance the experience. We may also use third-party services such as Google’s AdWords and DoubleClick to deliver content, including ads or online marketing relevant to your interests.

### AGE LIMITATIONS <a href="#age-limitations" id="age-limitations"></a>

At Secuna, we welcome children to submit security vulnerability information. However, some laws may restrict our ability to collect personal information from children under 18. If you are under 18, kindly ask your parent or guardian to submit your findings for you. If you, as a parent or guardian, learned that your child had provided us with personal information without your consent, you may alert us at [support@secuna.io.](mailto:support@secuna.io) If we, at Secuna, discover that we have collected and received the personal information from children under 18, we will take steps to remove the information as soon as possible.

Please note that any bug bounty payments that may apply are only issued to an adult (including the parent or guardian of the children).

### YOUR DATA PRIVACY RIGHTS <a href="#your-data-privacy-rights" id="your-data-privacy-rights"></a>

You have several rights under relevant data privacy laws, including the National Privacy Commission's Data Privacy Act of 2012. Depending on where you are based, those rights can include the right to:

* request access or copies of your personal information;
* modify incorrect personal information;
* delete or remove your personal information;
* restrict the processing of your personal information;
* request a commonly structured, machine-readable copy of your personal information and that it is transferred to another data controller;
* lodge complaints with competent authorities in your country; and&#x20;
* request a list containing the names and addresses of any potential recipients of your personal information.

To exercise one or more of these rights, or you may ask questions or relay concerns by sending us an email at <privacy@secuna.io> or by visiting us at Secuna Software Technologies, Inc.’s office, Attn: Secuna, Level 10-01, One Global Place, 5th Avenue cor 25th Street Bonifacio Global City, Taguig City, Philippines.

### OBJECTION TO MARKETING <a href="#objection-to-marketing" id="objection-to-marketing"></a>

As a data subject, you have the right to opt-out of receiving promotional emails from Secuna by following the instructions provided in those emails. If you opt-out, we could still send you non-promotional emails related to your account and our current business relations. You can also send requests about your contact preferences or changes to your information, including invitations to opt-out of sharing your personal information with third parties, through our contact information provided.

### AMENDMENTS <a href="#amendments" id="amendments"></a>

We update our Privacy Policy from time to time. When we update our Privacy Policy, we will revise the "Updated" date above, inform you via email, and post the new Privacy Policy to our sites.

### SECUNA INFORMATION <a href="#secuna-information" id="secuna-information"></a>

For questions about accessing, changing, or deleting your personal information, please visit [www.secuna.io](http://www.secuna.io/) or via email at <privacy@secuna.io>.


# Terms and Conditions

Updated: 23rd of September 2019

### AGREEMENT TO TERMS <a href="#agreement-to-terms" id="agreement-to-terms"></a>

By signing up and using Secuna, you agree to be bound by the Terms and Conditions.&#x20;

### DEFINITION OF TERMS <a href="#definition-of-terms" id="definition-of-terms"></a>

As used in these Terms and Conditions, the following capitalized terms shall have the following meanings.

* “**Bug Bounties**” means a cash reward awarded to security researchers after reporting a valid security vulnerability.
* "**Customer**" means a Secuna customer with security program running in the platform to receive security vulnerability information.
* “**Secuna Platform**" means the crowdsourced cybersecurity testing platform offered and operated by Secuna.
* “**Security Program**" means the security page of a customer to receive security vulnerability information from different security researcher.
* “**Security Program Policy**" is a policy prepared by a customer that contains the rules and scopes governing the security program to which the security researchers must agree, and the bug bounty rates, if any, that a customer will award to security researchers who participate in the security program.
* “**Security Researcher**" are commonly known as hackers, white hat hackers, or bug bounty hunters who uses the Secuna platform to submit security vulnerability information to different security programs.
* "**Security Vulnerability Information**" means bug reports or other security vulnerability information, in text, graphics, image, audio,  video, software, hardware, works of authorship of any kind, and information or other material that security researchers provide or otherwise made available through the Secuna platform to a Customer resulting from participation in a security program.
* “**Services**" means the Secuna platform and any related service made available by or through Secuna Platform.
* “**Third Party Services**" means an individual or entity that provides a service to a Customer through Secuna.

### SERVICES OFFERED BY SECUNA <a href="#services-offered-by-secuna" id="services-offered-by-secuna"></a>

* **Secuna Platform**\
  For Customers, Secuna allows them to access and use the Secuna Platform exclusively for their business purposes to enable them to communicate and collaborate with different Security Researchers by launching a security program and offer bug bounties to discover and receive Security Vulnerability Information. This is subject to Customer’s compliance with the Terms.
* **Security Program Management Service**\
  If agreed by the Secuna and Customer, Secuna will provide the security program management service and allow Secuna to access the Security Vulnerability Information to provide the security program management service. To the deliver the service, Secuna will conduct a set of activities associated with the security program management service, including the reproducing and verifying of Security Vulnerability Information submitted by Security Researchers, communicating to Security Researchers, and awarding bug bounties. The Customer authorizes Secuna to decide on awarding bug bounties which will be based on the bug bounty rates set by the Customer on their security program. Secuna makes no representation or warranty regarding the security program management service and agrees to provide the security program management service on an as-is basis.
* **Third Party Services**\
  If agreed by the Secuna and Customer, the Services may include certain Third-Party Services. Notwithstanding anything to the contrary in the terms and conditions, the Third-Party Services will be provided by the third party to Customer; therefore, Secuna is not responsible for the Third-Party Services. Also, Secuna makes no warranty or representation concerning the Third-Party Services. The Customer agrees to be responsible for all payment obligations related to the Third-Party Services and to accept to and be bound by any terms and conditions presented to the Customer by the Third-Party Services provider governing the use of the applicable Third-Party Services, and unless otherwise agreed, the Customer will remit payment for the Third-Party Services directly to Secuna within twenty-two (22) business days of invoice, and Secuna will pay the Third-Party Services provider.
* **Other Services Offered By Secuna**\
  If agreed by the Secuna and Customer, the Services may include additional services to be provided by Secuna upon special arrangement.

### PROHIBITION ON USE <a href="#prohibition-on-use" id="prohibition-on-use"></a>

The Customer and Security Researcher shall not use the Services provided by Secuna, or any portion thereof, for the benefit of any third-party or in any manner prohibited by the Terms and Conditions.

### SECURITY VULNERABILITY INFORMATIONS <a href="#security-vulnerability-informations" id="security-vulnerability-informations"></a>

By submitting any Security Vulnerability Information available to a Customer, the Security Researcher agrees to the Security Program Policy of the Customer. Individual Security Program Policies supersede Secuna's Security Vulnerability Disclosure Policy in the event of a conflict. The Security Researcher confirms that neither the Security Vulnerability Information nor any use of Security Vulnerability Information by the Customer will infringe, misappropriate, or violate a third-party's intellectual property rights, or rights of publicity or privacy, or result in the violation of any applicable law or regulation.

### SECURITY VULNERABILITY DISCLOSURE TERMS <a href="#security-vulnerability-disclosure-terms" id="security-vulnerability-disclosure-terms"></a>

Secuna's Security Vulnerability Disclosure Terms (located in the following link: [https://secuna.io/disclosure-policy](http://help.secuna.io/en/articles/3627790-disclosure-terms)), which describes the default policy concerning the submission and disclosing of security vulnerability. In the event of a conflict, Secuna’s Security Vulnerability Disclosure Terms are superseded by Customer’s Security Program Policy.

### SECURITY PROGRAMS <a href="#security-programs" id="security-programs"></a>

If agreed by the Secuna and Customer, the Customer is solely responsible for the administration and management of the their Security Programs through the Secuna Platform. Secuna reserves the right in its sole discretion to reject or dismiss a Security Program for any reason. While Secuna may assist the Customer in preparing their Security Program, the Customer is solely responsible for the their Security Program Policy. The Customer represents and warrants that they own all of the Security Program Policy or that the Customer has all rights necessary to grant Secuna the license rights in the their Security Program Policy under the Terms and Conditions. The Customer also represents and warrants that neither the Security Program Policy, nor the Customer's use and provision of the Security Program Policy to be made available through the Services, nor any use of the Security Program Policy by Secuna or a Security Researcher on or through the Services, will infringe, misappropriate or violate any third-party's intellectual property rights, or rights of publicity or privacy, or result in the violation of any applicable law or regulation, including export control laws.

### BUG BOUNTIES AND SECUNA FEES <a href="#bug-bounties-and-secuna-fees" id="bug-bounties-and-secuna-fees"></a>

The Customer agrees under the Terms and Conditions to award Bug Bounties to those Security Researchers who submitted a valid Security Vulnerability Information to customers for a specific Security Program. Secuna will process Bug Bounties that are cash payments on behalf of the Customer and will remit the Bug Bounty payments to the relevant Security Researcher within ten (10) business days after Secuna receives the Bug Bounty payment from the Customer. Secuna is not responsible for processing any Bug Bounty award that is not in the form of monetary payment, or for delays in payment beyond the reasonable control of Secuna. The Customer agrees under the Terms and Conditions to pay Secuna a payment processing fee equal to twenty percent (20%) of each Bug Bounty awarded to a Security Researcher. The Customer also agrees to pay the Secuna Fees and the relevant Bug Bounty payments directly to Secuna within thirty (30) days of the invoice date, unless otherwise stated on the Order Form. The Secuna Fees and Bug Bounty payments are non-refundable, except as expressly provided in the Terms and Conditions. With the exception of any amounts disputed in good faith, all past due amounts payable under any applicable Order Form or Terms and Conditions will incur interest at a rate of 1.5% per month or the maximum rate allowed by law, whichever is lower. The Customer shall reimburse Secuna for all reasonable costs and expenses incurred in the collection of any overdue amounts, including reasonable attorneys' charges.

### SECURITY RESEARCHER’S BUG BOUNTY PAYMENTS <a href="#security-researchers-bug-bounty-payments" id="security-researchers-bug-bounty-payments"></a>

A Bug Bounty may be awarded to the Security Researcher for submitting a Security Vulnerability Information to a customer for a particular security program if the submitted Security Vulnerability Information meets the demands of the customer as defined in their Security Program Policy. Secuna will process Bug Bounties which are financial payments on behalf of the Customer and will send the Bug Bounty payments to the relevant Security Researcher within ten (10) business days after receiving the Bug Bounty payment from the Customer. Secuna is not responsible for any payment delays outside the reasonable control of Secuna. Using a pseudonym, the security researcher may stay anonymous. However, in order to be qualified and eligible to receive a bug bounty, the security researcher needs to provide accurate, complete and up-to-date information, including mailing addresses, government-issued IDs (if applicable), and any other data that Secuna would reasonably request to allow Secuna to legally send any bug bounty payments and file tax forms. If Secuna is not provided with this data by the Security Researcher, any Bug Bounty payments that would otherwise be paid to the Security Researcher will be given to Secuna's selected charity. Some security teams may offer bug bounties for the valid submission of security vulnerability. The decision to award bug bounties is entirely at the discretion of the security team, and it is essential to note that not all security programs offer bug bounties. The amount of each bug bounty payment will be determined by the Security Team and describe in their security program policy. Bug Bounty payments are subject to the following eligibility requirements:

* We are not able to pay bug bounties to residents or those who report security vulnerabilities from a country against which the Philippines and the United States of America has trade restrictions or export sanctions.
* Secuna welcomes minors to participate in our platform. However, the [Children's Online Privacy Protection Act](https://www.ftc.gov/ogc/coppa1.htm) also known as COPPA restricts our ability to collect personal information from children, so you will need to claim your bug bounties with the help of your parent or guardian.
* Some payments will be made in U.S. dollars (USD) or Bitcoins (BTC) and will comply with local laws and regulations, and rules of ethics. As determined by your country's laws, you are responsible for the tax consequences of any bug bounty you receive.
* It is your primary responsibility to comply with any policies your employer may have that may affect your eligibility to participate in our platform.

### NO ADVOCACY OF SECURITY RESEARCHERS <a href="#no-advocacy-of-security-researchers" id="no-advocacy-of-security-researchers"></a>

Secuna does not endorse any Security Researcher. Secuna is not responsible for any damage or harm resulting from the communications or interactions between the Customer and Security Researcher or other customers, either through the Services or otherwise. Secuna does not intend any ranking in the leaderboard or description of any Security Researcher in their profile accounts as an endorsement of any type. Any selection or use of any Security Researcher is at the Customer's own risk. Any use or reliance of Security Vulnerability Informations that the Customer receives is at the their own risk. Secuna does not endorse, represent or guarantee any Security Vulnerability Information that is complete, truthful, accurate or reliable. Under no conditions shall Secuna be responsible in any manner for any Security Vulnerability Information, including, but not limited to, any mistakes or omissions in any Security Vulnerability Information, or any loss or harm of any kind caused as a consequence of using any Security Vulnerability Information.

### NO EMPLOYMENT/AGENCY RELATIONSHIP <a href="#no-employmentagency-relationship" id="no-employmentagency-relationship"></a>

Security Researchers are not Secuna employees, contractors, nor agents, but are independent third parties who wish to participate in Security Programs and connect, communicate, or collaborate with the Customer. Nothing in the Terms is meant to make Secuna and Security Researcher as joint venturers, partners, or employer and employee. Under no circumstances shall Secuna be considered as a Security Researcher's employer, nor shall the Security Researcher have any right as Secuna's employee. Likewise, Customers are not employees, contractors, nor agents of Secuna, but are independent third parties who want to run their Security Programs and connect with Security Researchers through our Platform. Security Researchers agree that they will not attempt to impose liability on Secuna or seek any legal remedy from Secuna regarding Customer's actions or omissions.

### SEPARATE ARRANGEMENTS <a href="#separate-arrangements" id="separate-arrangements"></a>

Any contract or interaction, including concerns with any security program policy, between a Customer and a Security Researcher will be exclusive to the Customer and the Security Researcher. Secuna does not participate in such agreements and disclaims all liability resulting from such operations or transactions. The Customer agrees that any legal remedy that the Customer seeks to obtain for actions or omissions of the Security Researcher or other third parties regarding the Customer's Security Program, including Security Vulnerability Information, will be limited to claims against the particular the Security Researcher or other third parties who caused harm to Customer, and the Customer agrees not to impose liability on Secuna or seek any legal remedy from Secuna regarding such actions or omissions.

### TERMINATION AND SEVERANCE <a href="#termination-and-severance" id="termination-and-severance"></a>

Secuna may terminate the access and use of the Secuna Platform at any time and without notice to the Customer or Security Researcher at Secuna's sole discretion. A Customer or Security Researcher may, at any moment by sending an email to <support@secuna.io>, cancel the account of such Customer or Security Researcher. The following conditions of the Terms shall survive upon termination, discontinuation or cancelation of the Services, the Secuna Platform or the account of a Customer or Security Researcher: No Endorsement, Independent Parties, Ownership, Warranty Disclaimers, Liability Limitation, and Dispute Resolution.

### OWNERSHIP RIGHTS <a href="#ownership-rights" id="ownership-rights"></a>

Secuna does not claim any ownership rights in any Security Program Material or Security Vulnerability Information. Nothing in the Terms shall be considered to restrict any privileges that the Customer and Security Researcher may have to use and utilize the Security Program Material and Security Vulnerability Information. The Customer and Security Researcher acknowledges and agrees that Secuna may gather, collect, and use such information internally at Secuna, which will not identify particular Customers or Security Researchers. Subject to the rights of the Customer and Security Researcher in any Security Program Material or Security Vulnerability Information, Secuna and its licensors are the sole proprietors of all rights, titles and interests in the Services and content contained therein, including all associated intellectual property rights. The Customer and Security Researcher acknowledges that copyright, trademark, and other regulations of the Republic of the Philippines and overseas nations protect the Services and Secuna content.

### LICENSE <a href="#license" id="license"></a>

By making any security program material or security vulnerability information available through the Services, the Customer and Security Researcher hereby grants Secuna a perpetual, irrevocable, non-exclusive, non-transferable, non-sublicensable, global, royalty-free license to use, copy, reproduce, display, modify, adapt, transmit and distribute copies of the security program material of the Customer and the security vulnerability information of the security researcher for the sole purpose of providing the Services. Subject to compliance by the Customer and Security Researcher with the Terms, Secuna hereby grants the Customer and Security Researcher a non-exclusive, non-transferable, non-sublicensable, global, royalty-free license to access and view the content made available on the Services by Secuna exclusively in connection with the use of the Services authorized by the Customer and Security Researcher.

### RULES ON CONFIDENTIALITY <a href="#rules-on-confidentiality" id="rules-on-confidentiality"></a>

Secuna understands that it may receive Confidential Information from the Customer; likewise, Customer understands that it may receive Confidential Information from Secuna; and Security Researcher understands that it may receive Confidential Information of a Customer or Secuna. The receiving party agrees not to disclose any third party's Confidential Information and not to use any other party's Confidential Information for any purpose not specified in the Terms, provided Customer or Security Researcher agrees that Secuna may collect or gather data with respect to Services and Security Programs for reporting on the aggregate response rate, total Bug Bounties paid and other aggregate measures (labeled as "Secuna Aggregate Data") and the Secuna Aggregate Data is not Confidential Information.

### PRIVACY <a href="#privacy" id="privacy"></a>

The Privacy Policy of Secuna (located on the following link: <https://secuna.io/privacy>), explains how Secuna collects, uses, and discloses information from Secuna’s Customers and Security Researchers, and will apply to the Services.

### LINKS TO THIRD-PARTY WEBSITES <a href="#links-to-third-party-websites" id="links-to-third-party-websites"></a>

The Services provided by Secuna may contain links websites or resources of third-parties. Secuna provides these links as a convenience only and is not responsible for the content, products or services on or available from those websites or resources or links displayed on such websites. Customer or Security Researcher acknowledge sole responsibility and assumes all risk resulting from using any third-party websites or resources.

### AUTHORIZATION <a href="#authorization" id="authorization"></a>

If the Customer is using the Services on behalf of a company, organization, or other legal entity, Customer represents that they have the authority to bind that company or other legal entity to the Terms. If the Security Researcher is a minor (under the age of 18 in accordance with Philippine laws), the parents of Security Researcher must agree on their behalf to the Terms.

### INDEMNIFICATION AND LIABILITIES <a href="#indemnification-and-liabilities" id="indemnification-and-liabilities"></a>

Customer shall indemnify, defend and hold harmless Secuna, including its officers, directors, managers, employees, and agents, against any claims, disputes, claims, liabilities, damages, losses and costs and expenses, including, without limitation, reasonable legal and accounting fees arising from or in any way connected with Customer's Security Program Material, use of a Security Vulnerability Information, or Customer's violation of the Terms. Security Researcher shall indemnify, defend and hold harmless Secuna, including its officers, directors, managers, employees, and agents, against any claims, disputes, demands, liabilities, damages, losses, and costs and expenses, including, without limitation, reasonable legal and accounting fees arising from or in any way connected with Security Researcher's access to or use of the Services, Security Researcher's reliance of Security Program Material, Security Researcher's Vulnerability Information, or Security Researcher's violation of the Terms.

### DISCLAIMER <a href="#disclaimer" id="disclaimer"></a>

Secuna provides the Services "as is" without any warranty. Secuna makes no warranty that the Services will, as applicable, meet the requirements of the Customer or Security Researcher or be available on an uninterrupted, secure, or error-free basis. Without restricting the preceding, Secuna explicitly disclaims any warranties for a particular purpose and any warranties arising from dealing or usage of trade.

### LIMITS OF LIABILITY <a href="#limits-of-liability" id="limits-of-liability"></a>

Neither party shall be responsible for any loss of revenues, loss of information or goodwill, incidental, special, exemplary or consequential damages, disruption of service, computer damage or system failure, or costs of replacement services resulting out of or in association with the Terms or inability to use the Services, whether based on warranty, contract, tort (including negligence), or any other legal theory, and whether or not such party was notified of the potential for such damage. For consequential or incidental damages, some jurisdictions do not allow the exclusion or limitation of liability, so the above limitation may not apply. Except for obligations under Confidentiality and Indemnification sections, each party’s maximum liability under this terms will not exceed the amounts paid or payable by the Customer to Secuna for the use of the services during the twelve (2) month period before the date when the claim or liability first arose.

### PROMOTION <a href="#promotion" id="promotion"></a>

In any promotion or advertisement describing the connection between the parties, Secuna may use the name of the Customer and/or Security Researcher.

### CHANGES TO SECUNA PLATFORM OR SECUNA SITE <a href="#changes-to-secuna-platform-or-secuna-site" id="changes-to-secuna-platform-or-secuna-site"></a>

Secuna may change all or any portion of the Secuna Platform or Secuna Website, as it is in accordance with the terms contained herein. Furthermore, if any Security Program is inactive or unattended by a Customer, Secuna shall have the right to remove or disable access to any appropriate Security Program Material or Security Vulnerability Information if the Customer has not replied to Secuna's written notice via email within three (3) business days of such written notice.

### AMENDMENTS <a href="#amendments" id="amendments"></a>

Secuna may, upon notification to the Customer or Security Researcher, change the Terms at any moment. If Customer or Security Researcher continues to use the Services after Secuna has changed the terms and conditions, the Customer and Security Researcher will be considered to have agreed to be bound by the changed terms and conditions.

### NOTICE TO SECUNA <a href="#notice-to-secuna" id="notice-to-secuna"></a>

Anyone can submit feedback by sending an email to Secuna at <feedback@secuna.io>. By submitting any Feedback, sender grants Secuna a royalty-free, worldwide, irrevocable, perpetual, non-exclusive, sub-licensable, transferable, fully-paid license under any intellectual property rights owned or controlled by the sender to use, copy, modify, create derivative works based on and otherwise use the feedback for any purpose.

### SECUNA INFORMATION <a href="#secuna-information" id="secuna-information"></a>

If there are any questions about the Terms or the Services, please contact Secuna at <support@secuna.io>, or Secuna Software Technologies, Inc., Level 10-01, One Global Place, 5th Avenue corner 25th Street Bonifacio Global City, Taguig City.

### OTHER TERMS AND CONDITIONS <a href="#other-terms-and-conditions" id="other-terms-and-conditions"></a>

The Terms and any relevant executed order form that refers to the Terms represent the entire and exclusive agreement between Secuna and Customer or Security Researcher and supersede and replace any prior verbal or written contract or agreement between Secuna and Customer or Security Researcher on the Services. If any provision of the Terms is held by the legal authority of the competent jurisdiction to be invalid, forbidden, or otherwise unenforceable, the other provisions of the Terms shall remain enforceable and the invalid or unenforceable provision shall be deemed modified to the extent allowed by law to be valid and enforceable. Secuna will assign the Terms and bind and inure to the benefit of the parties, their successors and assigns. The Customer or Security Researcher may not assign the Terms to be unreasonably withheld without the prior written permission of Secuna. Any notices or other communications provided by Secuna under the Terms, including amendments to the Terms, will be provided by email or by posting to the Secuna Site. The failure of Secuna to enforce any right or provision of the Terms shall not be considered as a waiver of such right or provision. Any such waiver will only be effective if it is signed in writing by a duly authorized Secuna representative.


# Disclosure Terms

Updated: 9th of February 2020

### ACCEPTANCE TO DISCLOSURE TERMS <a href="#acceptance-to-disclosure-terms" id="acceptance-to-disclosure-terms"></a>

By using our platform, you accept our Disclosure Terms, including our [Terms and Conditions](https://help.secuna.io/en/articles/3627778-terms-and-conditions) and [Privacy Policy](https://help.secuna.io/en/articles/3627768-privacy-policy). If you do not agree, you should not proceed in accessing our platform and submitting a security vulnerability information.

### DEFINITIONS OF TERMS <a href="#definitions-of-terms" id="definitions-of-terms"></a>

* **Security Programs**: Security Teams may launch a Security Program and publish a policy designed to guide security researcher in finding security vulnerabilities into a particular service or product. If this security program is private, your participation is entirely optional and subject to non-disclosure by default.
* **Security Researcher**: They are commonly known as hackers, white hat hackers, or bug bounty hunters who use the Secuna platform to provide security vulnerability information to different security programs.
* **Security Team**: A team of individuals responsible for addressing a product or service's security issues. Depending on the circumstances, this could be an organization's formal security team, a group of volunteers of an open-source project, or an independent volunteer.
* **Security Vulnerability**: A software bug that would allow an attacker to perform penetration testing.&#x20;
* **Security Vulnerability Information**: A bug report or other security vulnerability information, in text, graphics, image, audio,  video, software, hardware, works of authorship of any kind, and information or other material that security researchers provide or otherwise made available through the Secuna platform to a Customer resulting from participation in a security program.

\
Security is core to our values, and we value the input of hackers acting in good faith to help us maintain a high standard for the security and privacy for our users. This includes encouraging responsible security vulnerability research and disclosure. This policy also sets out our definition of good faith in the context of using our platform, interacting with different users, finding and reporting security vulnerabilities, as well as what you can expect from us in return. To avoid any confusion, we ask you:

* To play by the rules. This includes following this policy, as well as any other relevant terms or agreements, including the standards set forth by the Security Teams. If there is any inconsistency between this policy and any other relevant terms, the terms of this policy will prevail;
* To be kind and cordial at all times. Any form of harassment, abusive language, profanity, or threats will not be tolerated in our platform nor tolerate any discrimination based on race, ethnicity, nationality, level of experience, personal and physical appearance, age, religion, gender identity and orientation, political beliefs, or others.
* To report any security vulnerability you’ve discovered;
* To make a reasonable faith effort to avoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience;
* To keep the details of any discovered security vulnerabilities confidential until they are resolved, according to the Disclosure Terms;
* To Maintain communication in our platform. Secuna is not liable for any damage caused by communicating or disclosing security vulnerability information outside the platform. So, please do not use emails, social media accounts, or other private ways to communicate a member of a security program in regards to security vulnerabilities or any  related issues, unless they instructed you to do so.
* To not engage in extortion. Any attempt to obtain bug bounties, money, or services by coercion is strictly prohibited. If you know or have information about a potential security vulnerability or inadvertently come into possession of private data, please promptly ethically initiate the disclosure process as described below.
* To be patient with the progress of resolving your reported security vulnerability;
* To not impersonate any users on Secuna. Social engineering attempts to another party trough impersonation of a Secuna employee, another security researcher, or a security team is unauthorized and will not be tolerated.
* To perform penetration testing only on in-scope targets, and respect systems and activities which are described on out-of-scope;
* To not farm points. Farming for points or bug bounties are prohibited.
* To limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information; and
* To interact only with test accounts you own or with explicit permission from the account holder.

### SECURITY VULNERABILITY PROCESSES <a href="#security-vulnerability-processes" id="security-vulnerability-processes"></a>

**Security Vulnerability Submission**

Before submitting any potential security vulnerability, always review the policy of the security program very carefully. Security Teams will publish their own policy to give more details and guide security research into a particular target, app, service, or product. These policies may superseded this disclosure policy. A report should be made and submitted to the appropriate security program under our platform if you believe you have found a potential security vulnerability. Your report should include a detailed description and explanation of the discovered security vulnerability with easy-to-follow reproducible steps or a working proof-of-concept (POC). The report will be continuously updated when the vulnerability has been investigated and validated, when more information is being requested from you, or when you have qualified for a bug bounty.

**Security Vulnerability Disclosure**

By default, the contents of the report will be made available to the Security Team once it is submitted on the Secuna platform and will initially remain private to allow the Security Team sufficient time to publish remediation. Once the report has been closed and resolved, Security Programs can disclose the security vulnerability information or Security Researcher may request for disclosure. The following events can happen in the Security Vulnerability Disclosure Process:

* When 90 days have elapsed with the Security Team being unresponsive, unable, or unwilling to respond to your report or provide a vulnerability disclosure timeline, the contents of the Report may be publicly disclosed by the Security Researcher. We do believe transparency is important in these extreme cases.
* When the Security Team of any security program has evidence of active exploitation or imminent public harm, they may immediately provide remediation details to the public so that users can take protective action to avoid getting hacked.
* When the Security Team needs more time to remediate the security vulnerability due to complexity and other factors, an extension can be made so that the report may remain private to ensure that the Security Team has an enough time to remediate the security vulnerability.

**Private Security Program**

Private security programs may send invitations to some security researchers, and participation in these private security programs is subject to strict non-disclosure. Before accepting an invitation, Security Researchers should carefully review any security program policies and non-disclosure agreements necessary for participation.

### POLICY ENFORCEMENT <a href="#policy-enforcement" id="policy-enforcement"></a>

* If you see a user violating this policy, please reach out to our team at <support@secuna.io>.
* If a user breach one of the rules listed above, we will issue a written warning. If the user continues with his/her negative behavior, We will suspend access to the platform for a reasonable period of time. If the user’s behavior remains after the first two measures are taken, we will issue a permanent platform ban.
* If a user breaks the rules in our platform in a particularly egregious manner, we reserve the right to issue a permanent ban on the platform immediately.

### AMENDMENTS <a href="#amendments" id="amendments"></a>

We may revise our Disclosure Terms from time to time. When we update our Disclosure Terms, we will revise the "Last Updated" date above, inform you via email, and post the new Privacy Policy to our sites.

### SECUNA INFORMATION <a href="#secuna-information" id="secuna-information"></a>

Secuna is always open to feedback, questions, and suggestions. If you would like to talk to us, please feel free to email us at <support@secuna.io> or follow us on Twitter [@SecunaSecurity.](https://twitter.com/SecunaSecurity)


