AI-Generated Bug Bounty Submissions

AI-Generated Bug Bounty Submissions

We have been receiving a significant and growing volume of AI-generated, low-quality bug bounty reports across our programs. In response, we have scaled both our technology and our triage resources to keep pace and we are introducing new enforcement policies to protect the integrity of our programs for researchers and clients alike.

 

New Policies:

  • Researchers whose submissions are repeatedly identified as AI-generated, low quality reports, may be banned from individual programs or the Inspectiv platform.

  • Submissions identified as AI-generated, low-quality will be highly de-prioritized in our triage process.

  • Submissions lacking demonstrable, negative security impact will be de-prioritized or rejected.

  • Submissions that do not include a thorough video proof-of-concept (POC) will be de-prioritized or rejected.

  • Researchers may not operate more than one account on our platform. Attempts to do so can result in a ban from the platform.

 

We are taking these steps to ensure a fair and timely experience for all of our valued security researchers, and to continue delivering highly impactful vulnerability reports to our customers.

 

Together, let’s keep raising the bar — and keep doing what we do best: #SecureTheInternet.

 

Thank you for your continued support in making this happen.

 

— The Inspectiv Team