1. Introduction
These Terms of Service ("Terms") govern your access to and use of the OpenHunt ("Platform"), a software-as-a-service product operated by OliveX Security LLC ("0xHunter," "we," "us," or "our").
The Platform provides technology infrastructure that enables organizations ("Program Owners") to host and manage vulnerability disclosure programs (VDP) and bug bounty programs (BBP), and enables security researchers ("Researchers") to discover and submit vulnerability reports to those programs.
By accessing or using the Platform, you agree to be bound by these Terms. If you do not agree, do not use the Platform.
2. Nature of the Platform
2.1 Platform as Infrastructure Provider
OpenHunt operates exclusively as a technology infrastructure provider. The Platform provides tools for Program Owners to publish program policies, receive vulnerability reports, manage triage workflows, and communicate with Researchers. The Platform does not operate, manage, or control any vulnerability disclosure or bug bounty program hosted on it.
2.2 No Party to Program Relationships
0xHunter is not a party to any agreement, arrangement, or relationship between Program Owners and Researchers. Each Program Owner independently defines, operates, and is solely responsible for its own program, including but not limited to: program scope, disclosure policies, rules of engagement, safe harbor commitments, reward structures, bounty payments, and all communications with Researchers.
2.3 No Agency or Employment
Nothing in these Terms creates an agency, partnership, joint venture, or employment relationship between 0xHunter and any Program Owner or Researcher. Researchers are independent individuals and are not employees, contractors, or agents of 0xHunter or any Program Owner by virtue of using the Platform.
3. Eligibility
3.1 General Eligibility
You must be at least 18 years old to use the Platform. By creating an account, you represent and warrant that: (a) you meet this age requirement; (b) the information you provide is accurate, current, and complete; (c) you are not prohibited by applicable laws from using the Platform; and (d) you will not use the Platform in violation of any applicable sanctions or export control regulations.
3.2 Program Owner Eligibility
Only legally constituted entities (corporations, limited liability companies, partnerships, or equivalent legal structures under applicable law) may register as Program Owners. Individuals acting in their personal capacity may not host programs on the Platform. By registering as a Program Owner, you represent and warrant that: (a) you are a duly organized and validly existing legal entity; (b) the person accepting these Terms has the authority to bind the entity; and (c) you can provide documentation evidencing your legal status upon request by 0xHunter.
4. Accounts
You are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account. You must notify us immediately at security@0xhunter.io if you suspect unauthorized access. We reserve the right to suspend or terminate accounts that violate these Terms.
5. Program Owner Responsibilities
As a Program Owner, you acknowledge and agree that:
- You are solely responsible for your program. This includes program scope, policies, rules of engagement, safe harbor provisions, bounty reward structures, and all interactions with Researchers. 0xHunter has no obligation to review, approve, or monitor the content or operation of your program.
- You are solely responsible for bounty payments. If you operate a Bug Bounty Program, you are solely and exclusively responsible for determining bounty amounts and making timely payments to Researchers. 0xHunter does not process, guarantee, or assume any liability for bounty payments.
- You are solely responsible for Safe Harbor. Any safe harbor commitments you make in your program policy are between you and the Researchers who participate. 0xHunter does not enforce, guarantee, or assume liability for your safe harbor commitments.
- You are solely responsible for legal compliance. You must ensure that your program complies with all applicable laws and regulations in your jurisdiction, including but not limited to data protection, computer fraud, and employment laws.
- You must respond to reports in good faith. You agree to evaluate and respond to vulnerability reports in a timely and professional manner consistent with your published program policy.
- You grant 0xHunter a limited license. You grant us a non-exclusive, worldwide license to display your program information (name, logo, policy, scope) on the Platform for the purpose of operating the service.
- You consent to appear in the public directory. By creating a program on the Platform, you agree that your organization name, industry, country, program type (VDP or BBP), program description, and aggregate statistics (such as number of vulnerabilities resolved and average response time) will be listed in the 0xHunter public programs directory at 0xhunter.io/programs and may appear in search engine results. If your plan includes a custom logo, your logo will also be displayed. You may opt out of the public directory at any time by setting your program to private in your program settings, but this may limit the visibility of your program to Researchers.
6. Program Types and Rewards
6.1 Vulnerability Disclosure Programs (VDP)
Programs classified as Vulnerability Disclosure Programs (VDP) are intended for coordinated vulnerability disclosure without monetary compensation. VDP Program Owners may not offer, promise, or advertise monetary rewards, bounties, or any form of financial compensation to Researchers through the Platform. VDP Program Owners may offer non-monetary recognition such as public acknowledgment, Hall of Fame listings, certificates of recognition, or promotional merchandise ("swag"). Any Program Owner that wishes to offer monetary rewards to Researchers must reclassify their program as a Bug Bounty Program (BBP).
6.2 Bug Bounty Programs (BBP)
Programs classified as Bug Bounty Programs (BBP) may offer monetary rewards to Researchers in accordance with the reward structure published in their program policy. The Program Owner is solely and exclusively responsible for: (a) defining reward amounts and criteria; (b) evaluating whether a submission qualifies for a reward; (c) processing and completing all payments to Researchers; and (d) complying with all applicable tax, financial, and regulatory obligations arising from such payments, including but not limited to withholding taxes, foreign payment regulations, and anti-money laundering requirements.
6.3 0xHunter's Role in Rewards and Payments
OpenHunt serves exclusively as a SaaS infrastructure provider and does not participate in, facilitate, intermediate, process, escrow, or guarantee any reward, bounty payment, or financial transaction between Program Owners and Researchers. 0xHunter does not collect funds from Program Owners on behalf of Researchers, does not hold funds in escrow, and does not act as a payment processor, financial intermediary, or fiduciary in any capacity. All financial arrangements, negotiations, disputes, and obligations related to bounty payments are exclusively between the Program Owner and the Researcher. 0xHunter shall not be liable for any failure, delay, underpayment, non-payment, or dispute arising from bounty rewards or any other form of compensation offered by a Program Owner.
7. Program Acceptable Use and Suspension
7.1 Program Acceptable Use
Program Owners agree not to use the Platform to:
- Operate fraudulent programs designed to obtain free security testing without the intention of honoring stated rewards or commitments.
- Deploy honeypots, traps, or deceptive environments intended to entrap, identify, or take legal action against Researchers acting in good faith.
- Collect, harvest, or misuse personal information of Researchers for purposes unrelated to the vulnerability disclosure program.
- Publish programs with knowingly false, misleading, or deceptive scope definitions, policies, or reward structures.
- Use the Platform to facilitate any activity that violates applicable laws or the rights of third parties.
7.2 Program Suspension and Removal
0xHunter reserves the right, at its sole and absolute discretion, to suspend, restrict, or permanently remove any program hosted on the Platform, at any time, with or without prior notice, for any reason that 0xHunter considers valid. Reasons may include, but are not limited to:
- Violation of these Terms or the Acceptable Use provisions in Section 7.1.
- Complaints from Researchers regarding non-payment, bad faith conduct, or failure to honor program commitments.
- Programs that 0xHunter reasonably believes may expose the Platform, its users, or third parties to legal, reputational, or security risk.
- Inactivity or abandonment of the program.
- Any other reason that 0xHunter, in its sole judgment, deems sufficient.
Program suspension or removal does not release the Program Owner from any obligations already incurred toward Researchers or 0xHunter, including outstanding bounty payments and indemnification obligations under these Terms. 0xHunter shall not be liable to the Program Owner or any third party for any suspension or removal of a program.
8. Researcher Responsibilities
As a Researcher, you acknowledge and agree that:
- You interact directly with Program Owners. Your vulnerability research and submissions are governed by the specific program policy published by each Program Owner. 0xHunter is not responsible for the content, accuracy, or enforcement of those policies.
- You must comply with program policies. You agree to conduct testing only against assets explicitly listed as in-scope by the Program Owner and to follow their rules of engagement.
- You must act lawfully. You are solely responsible for ensuring that your security research activities comply with all applicable laws and regulations in your jurisdiction and in the jurisdiction of the Program Owner.
- You must not cause harm. You agree to avoid accessing, modifying, or deleting data belonging to other users; performing denial-of-service attacks; social engineering; or physical security testing unless explicitly authorized by the Program Owner.
- You must submit reports in good faith. You agree to submit vulnerability reports that are accurate, original, and contain sufficient detail to reproduce the finding. Submitting fraudulent, fabricated, or plagiarized reports is strictly prohibited.
- Bounty payments are the Program Owner's responsibility. Any bounty rewards are determined and paid exclusively by the Program Owner. 0xHunter does not determine, process, guarantee, or assume liability for any bounty payments.
- You accept risk. You acknowledge that security research carries inherent risks, including the possibility of legal action by Program Owners or third parties. 0xHunter is not responsible for any legal consequences arising from your research activities, even if conducted through the Platform.
9. Disclaimer of Liability for Program Activities
9.1 Platform Limitation
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, 0xHUNTER SHALL NOT BE LIABLE FOR ANY ACTS, OMISSIONS, CONTENT, POLICIES, OR CONDUCT OF PROGRAM OWNERS OR RESEARCHERS, INCLUDING BUT NOT LIMITED TO:
- The accuracy, legality, or completeness of any program policy, scope definition, or safe harbor commitment published by a Program Owner.
- The accuracy, validity, or impact of any vulnerability report submitted by a Researcher.
- Any failure by a Program Owner to respond to reports, pay bounties, or honor safe harbor commitments.
- Any legal action taken by a Program Owner against a Researcher, or by a Researcher against a Program Owner.
- Any damages resulting from security research activities conducted through the Platform.
- Any unauthorized access to, or breach of, a Program Owner's systems resulting from Researcher activity.
9.2 No Mediation Obligation
0xHunter is not obligated to mediate, arbitrate, or resolve disputes between Program Owners and Researchers. We may, at our sole discretion, provide assistance in resolving disputes, but any such assistance does not create an obligation to do so in future cases and does not make 0xHunter a party to the dispute.
10. Intellectual Property
10.1 Platform Content
All content and materials comprising the Platform itself — including software, design, logos, text, and documentation — are the exclusive property of OliveX Security LLC or its licensors and are protected by applicable intellectual property laws.
10.2 User Content
You retain ownership of any content you submit to the Platform, including vulnerability reports. By submitting content, you grant 0xHunter a worldwide, non-exclusive, royalty-free license to store, display, and transmit such content as necessary to operate the Platform.
Vulnerability reports submitted to a Program Owner are subject to any intellectual property terms specified in that Program Owner's program policy. 0xHunter is not responsible for the intellectual property terms set by Program Owners. Disputes regarding duplicate reports, report validity, or intellectual property of submitted findings are exclusively between the Researcher and the Program Owner.
11. Prohibited Conduct
You agree not to:
- Use the Platform for any unlawful purpose.
- Submit fraudulent, fabricated, or plagiarized vulnerability reports.
- Attempt to gain unauthorized access to the Platform's own infrastructure.
- Harass, threaten, or intimidate other users.
- Circumvent security measures or access controls of the Platform itself.
- Use automated tools to scrape or collect data from the Platform without authorization.
- Create multiple accounts to abuse features or evade restrictions.
- Impersonate any person or entity, or misrepresent your affiliation.
- Interfere with or disrupt the Platform's operation or other users' experience.
12. Platform Availability
0xHunter does not guarantee uninterrupted, continuous, or error-free availability of the Platform. The Platform may be subject to scheduled or unscheduled downtime for maintenance, updates, security patches, or other operational reasons. 0xHunter shall not be liable for any loss, damage, or inconvenience caused by the Platform being temporarily unavailable, including but not limited to lost vulnerability reports, missed communications, or delayed triage workflows. Program Owners and Researchers acknowledge that they should not rely on the Platform as their sole means of communication for time-sensitive security matters.
13. Limitation of Liability
THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
0xHUNTER SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO YOUR USE OF THE PLATFORM, REGARDLESS OF THE THEORY OF LIABILITY.
OUR TOTAL AGGREGATE LIABILITY FOR ANY CLAIMS ARISING FROM OR RELATED TO THESE TERMS OR THE PLATFORM SHALL NOT EXCEED THE GREATER OF: (A) THE AMOUNT YOU HAVE PAID TO 0xHUNTER IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR (B) ONE HUNDRED US DOLLARS (USD $100).
0xHUNTER DOES NOT GUARANTEE THE AVAILABILITY, ACCURACY, COMPLETENESS, OR RELIABILITY OF THE PLATFORM OR ANY CONTENT HOSTED ON IT.
IN THE EVENT THAT APPLICABLE LAW DOES NOT PERMIT THE EXCLUSION OR LIMITATION OF CERTAIN WARRANTIES OR LIABILITY, THE ABOVE LIMITATIONS SHALL APPLY TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW.
14. Indemnification
14.1 By Program Owners
Program Owners agree to indemnify, defend, and hold harmless 0xHunter, its officers, directors, employees, and agents from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) the operation of their program; (b) their interactions with Researchers; (c) any failure to honor safe harbor commitments or pay bounties; (d) any violation of applicable laws in connection with their program; (e) any claim by a third party related to their program; or (f) the suspension or removal of their program pursuant to Section 7.2.
14.2 By Researchers
Researchers agree to indemnify, defend, and hold harmless 0xHunter, its officers, directors, employees, and agents from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) their security research activities; (b) any violation of a Program Owner's program policy; (c) any violation of applicable laws in connection with their research; or (d) any claim by a third party related to their research activities.
15. Force Majeure
0xHunter shall not be liable for any failure or delay in performing its obligations under these Terms to the extent that such failure or delay results from circumstances beyond its reasonable control, including but not limited to: acts of God, natural disasters, epidemics or pandemics, war, terrorism, civil unrest, government actions or regulations, embargoes, sanctions, power outages, internet or telecommunications failures, distributed denial-of-service attacks or other cyberattacks, failures of third-party infrastructure providers (including but not limited to AWS, Cloudflare, and Vercel), labor disputes, or any other event that could not have been reasonably foreseen or prevented. During a Force Majeure event, 0xHunter's obligations under these Terms are suspended for the duration of the event, and 0xHunter will use commercially reasonable efforts to resume performance as soon as practicable.
16. Termination
We may suspend or terminate your account at any time, with or without cause, and with or without notice. For Program Owners with active paid subscriptions, termination without cause will be subject to thirty (30) days' prior written notice. Termination for violation of these Terms may be immediate and without notice. Upon termination, your right to access the Platform ceases immediately. Sections 9 (Disclaimer of Liability for Program Activities), 13 (Limitation of Liability), 14 (Indemnification), 15 (Force Majeure), 18 (Governing Law), and 19 (Severability) survive termination.
17. Modifications
We may modify these Terms at any time. Material changes will be communicated via email to registered users or through a notice on the Platform at least fifteen (15) days before taking effect. Your continued use of the Platform after the effective date constitutes acceptance of the modified Terms. If you do not agree with the changes, you must discontinue use of the Platform.
18. Governing Law and Jurisdiction
These Terms are governed by and construed in accordance with the laws of the Argentine Republic. Any disputes arising from or related to these Terms shall be submitted to the exclusive jurisdiction of the competent courts of San Miguel de Tucumán, Province of Tucumán, Argentina, unless otherwise required by mandatory consumer protection laws of your jurisdiction.
19. Severability
If any provision of these Terms is held to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect. The invalid or unenforceable provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the original intent.
20. Acceptance Mechanism
By creating an account on the Platform, you are required to affirmatively accept these Terms and the Privacy Policy through an explicit action (such as checking a box or clicking an "I Accept" button) during the registration process. Browsing publicly available pages of the Platform does not constitute acceptance of these Terms, but continued use of the Platform after account creation does constitute ongoing acceptance.
21. Language
These Terms are drafted in English. A Spanish translation may be made available for convenience. In the event of a conflict between the English and Spanish versions, the English version shall prevail, except where mandatory consumer protection laws of the user's jurisdiction require the local language version to take precedence.
22. Entire Agreement
These Terms, together with the Privacy Policy and any applicable program-specific policies published by Program Owners, constitute the entire agreement between you and 0xHunter regarding the use of the Platform. These Terms supersede any prior agreements, understandings, or representations, whether written or oral, relating to the subject matter hereof.
23. Contact
For questions about these Terms:
- Email: legal@0xhunter.io
- Company: OliveX Security LLC
