Security reports.
Handled responsibly.
Run a credible vulnerability disclosure programme without another disconnected platform. Publish scope, triage reports, reward researchers, and keep every decision inside Ticaga.
Make the rules clear.
Before testing begins.
Give researchers one branded place to understand scope, rewards, disclosure terms, and the correct way to submit a finding.
Web Platform Security
Help us protect our customers by reporting vulnerabilities responsibly. Eligible findings are rewarded after validation.
Programme scope
Disclosure policy
Allow our security team 90 days to investigate and resolve an accepted report before public disclosure.
From first report
to final reward.
A structured process keeps researchers informed and gives your team a complete activity trail.
Collect
Capture impact, affected component, vulnerability type, reproduction steps, and reporter details.
Triage
Assign an owner, set severity, update status, add internal context, and create a linked ticket.
Resolve
Track remediation and optionally create a private RoadMap security task until disclosure.
Reward
Award the finding, collect encrypted payout details, and recognise the researcher publicly.
Know what needs attention now.
See programme health, incoming volume, triage pressure, accepted findings, and rewards without building a security spreadsheet.
- Filter reports by programme, severity, status, or assignee
- Public tokens let guest researchers track progress safely
- Automatic email updates at every important status change
- Optional AI-assisted severity detection for the first pass
Reward good research without losing the paper trail.
Set programme ranges, award individual findings, and follow every payout from claim to completion.
Credits, PayPal, or manual payout.
Registered researchers can build a credit balance and request withdrawal. Guest researchers can securely claim a direct reward with encrypted payout details.
Public, private,
or invitation-only.
Match the programme to your security maturity and the researchers you want to work with.
Open programme
Publish the programme in your public directory and accept reports from guests or registered researchers.
Direct-link intake
Keep a programme out of the directory while sharing a controlled submission link with selected people.
Invitation-only
Invite approved researchers, expire or revoke access, and maintain a participant record for every programme.
One programme system.
One monthly price.
Add Bug Bounty to an active Ticaga installation with a 14-day trial.
Keep security operations beside customer support.
Bug Bounty is an optional paid extension for Ticaga. Your core helpdesk licence remains separate, and the extension uses the same employees, departments, tickets, brands, and notifications.
Price shown in GBP, excluding VAT where applicable. Prices are subject to change before purchase.
Give security reports
a safer route in.
Publish clear rules, keep researchers updated, and reward the findings that make your product stronger.