Inspectiv Researcher Start-Up Guide: Essential Steps
Welcome to Inspectiv!
Inspectiv connects independent security researchers with companies (“Customers”) who want their applications & networks tested for vulnerabilities. As a researcher, you access bug bounty Programs, test within the rules each Program defines, submit vulnerability reports, and get paid for valid, reproducible and in-scope findings. Inspectiv's Bug Bounty & Triage Services (BBTS) team manages every program, triages every report, and handles payouts, so you never have to deal with the customer directly.
This guide walks through everything you need to do in order to begin: setting up your account, understanding how programs and payouts work, the rules of engagement you must follow while testing, and how to write reports that get accepted quickly.
Step 1: Create Your Account and Get Verified
Sign up: Create your researcher account at https://app.inspectiv.com . You may only hold one active account - operating more than one account can result in a platform ban.
Accept the legal agreements: Using the platform means you agree to the Researcher Terms & Conditions and the Researcher Agreement. Read them once up front and refer to them often - they cover ownership of your reports, confidentiality, and your independent-contractor relationship with Inspectiv.
Identity verification (KYC): Inspectiv may ask you to verify your identity (to prevent fraud) via PayPal or Payoneer, our two supported payment processors. This is a requirement before any bounty can be paid out.
Keep your account secure: You're responsible for all activity under your account. Report any unauthorized use immediately. Read all program pages thoroughly before conducting any security research.
Step 2: Understand the Program Model
Once your account is set up, you'll be granted access to public programs - open to the broader Inspectiv research community and the best way to start contributing and building a track record.
Unlocking private programs
Private programs offer higher-value targets and more testing opportunities with less competition, but they're invite-only. To qualify, you generally need to meet the following criteria:
Submit at least two accepted findings rated Low severity or higher .
Stay within each program's defined scope.
Do not engage directly with customers for fully managed bug bounty programs.
Follow Inspectiv's Rules of Engagement and Code of Conduct (see Step 3).
Being responsive, professional, respectful and consistently high-quality in your reporting is the single biggest factor in getting invited to exclusive private programs. We are here to support researchers that provide value and are easy to work with - they always get more opportunities to earn bounties.
Assigned credentials
Many programs issue you dedicated test credentials - most access is granted by assigning email routes that point to your registered https://app.inspectiv.com email address , for which you perform a a password reset to gain access. You can turn in your assigned credentials at any time to request another program's credentials instead - you can have up to 3 credential sets at a time.
Step 3: Know the Rules of Engagement Before You Test
Every program has its own Program Description with a defined Scope and Out-of-Scope list - read it in full before testing and never break the rules. On top of program-specific scope, the following rules apply platform-wide:
Tag every request: all testing traffic must include the customer HTTP header “X-Inspectiv-Tester: {your-username}”. Testing without this header can make an otherwise valid report ineligible for a bounty.
Don't create, delete, or mass-modify records. If your testing requires bulk changes, do it against your own records in a secondary/sandbox organization when one is available. Do not delete or modify any production data that does not belong to you.
Stop immediately if you access another account. If a vulnerability exposes someone else's account or data, stop testing and report it right away - do not continue exploring or escalating.
Respect rate limits. When testing for rate limiting, do not exceed 10 requests/second and do not sustain bursts longer than 10 seconds. Never send high-volume traffic or attempt fraudulent monetary transactions.
No social engineering. Phishing, vishing, spear-phishing, or any social-engineering attack against employees or customers is never acceptable.
Keep findings confidential. Don't publish, disclose, or share a vulnerability outside of the Inspectiv platform. This is strictly prohibited and it violates our non-disclosure policies.
Be courteous. Our triage team is here to help you - respect, professionalism and kindness go a long way to building a fruitful relationship working together.
Step 4: Write a Report That Gets Accepted
Report quality is the single biggest lever on both acceptance speed and payout size. The traits shared by every high-scoring report are listed below:
A clear POC (proof-of-concept). Include a concise video, screenshots, and exploit code - all are required. Our triage team will not accept a report without one - it's required, not optional.
Demonstrated, not just described, negative security impact. Don't just claim risk - show it safely. For example, for a Local File Inclusion, safely demonstrate partial file content exposure rather than just stating the risk exists.
Chained vulnerabilities where possible. Combining issues (e.g., IDOR + XSS, or Broken Access Control + SQL injection) proves greater real-world risk and typically earns a higher severity and payout than either issue alone.
Concise, well-structured writing. Long reports that bury the key details slow down triage substantially. We look for signal rather than noise when triaging reports.
Confirmed scope. Re-check the Program's Scope / Out-of-Scope sections before you submit any report - this single step avoids the most common rejection reason.
Fast, professional follow-up. Respond promptly to triage questions in the report comments - you will be emailed every time we need a response . Slow responses delay your own payout, and substantial unresponsiveness can get a report closed as Invalid or downgraded to Informational.
Common Mistakes That Get Reports Rejected
AI-generated reports with no real proof-of-concept or demonstrable negative security impact.
Describing theoretical risk instead of demonstrating actual impact (usually rejected).
Missing a working screenshot , video or exploit code PoC.
Out-of-scope findings — e.g. Denial of Service, social engineering, functional UI/UX bugs, or unvalidated automated-scanner spam.
Duplicate submissions of an already-reported issue on the same endpoint, or caused by the same root cause resulting in a duplicate status.
Overly long reports with unclear, buried details that are missing key details or steps to reproduce.
Going unresponsive to a triage analyst's request for more information.
How Severity and Payouts Are Determined
Inspectiv rates every accepted report using the Inspectiv Severity Rating Methodology (ISRM), which centers on demonstrated negative impact: the more severe and well-proven the impact, the higher the severity and payout. The full ISRM reference chart is maintained on the KB page linked at the end of this guide.
AI-generated submissions policy
Inspectiv has scaled its triage process specifically to detect low-quality, AI-generated reports. Current policies are listed below:
Submissions identified as AI-generated / low-quality are heavily de-prioritized in triage, or rejected outright.
Reports lacking demonstrable negative impact, or lacking a thorough video or exploit code PoC, are de-prioritized or rejected altogether.
Researchers with repeated low-quality/AI-generated submissions may be banned from individual programs or the entire platform if the behavior continues.
Operating more than one researcher account is not allowed and will result in a platform ban.
Getting Paid
Payment methods: PayPal or Payoneer. Both are also used to run required KYC & identity checks before a payout is released.
Timing: bounty awards are typically made available on the Friday following the report's acceptance. If it gets accepted on friday, then it will be paid the following Friday.
What locks in your payout tier: the amount and tier are determined by the submission's creation date, not its acceptance date. If you submit during an active double/extra-bounty campaign, that bonus is honored even if the report isn't accepted until after the campaign ends, to be fair.
Taxes: you are solely responsible for any taxes owed on your bounty awards as an individual.
Restricted persons: Inspectiv cannot pay anyone on U.S. Commerce/Treasury/State Department denied or restricted-party lists, or the OFAC lists - per U.S. export control law.
Delays: Inspectiv isn't liable for payout delays caused by factors outside its reasonable control (e.g. payment processor issues or holidays).
If You Disagree With a Severity Rating
The best practice is to fully demonstrate impact in your original report and to answer any and all questions. If you still disagree with an accepted report's final severity, here's how a dispute works:
Raise it in the report's commentary first — the triage analyst will direct you to file a formal dispute, or you can email programs[at]inspectiv(dot)com directly.
File the dispute by email; the original triage analyst confirms receipt and the report goes back under review.
The golden rule: a dispute can only be evaluated on the impact and evidence already present in your original report. You cannot introduce new evidence or a new exploit path to argue for a higher severity when you file a dispute.
The original analyst documents their reasoning and and additional member of Bug Bounty team discusses and votes to either keep the severity as-is or raise it (with an additional payout).
Eligibility: disputes are only available to established researchers with at least 3 accepted reports rated Low severity or higher. Other researchers are not eligible for disputes.
Where to Get Help and Learn More
The full Inspectiv Researcher Knowledge Base contains further reading materials and details:
For Questions: Email our Bug Bounty team at programs[at]inspectiv(dot)com.
Welcome aboard - happy hunting, and thank you for helping #SecureTheInternet.
-Inspectiv team