root@hckrt: ~#
Terms & Conditions
Website Terms of Use
Last updated: 13 July 2026
Please read these Website Terms of Use carefully before using https://www.hckrt.com/, https://hckrt.com/, https://blog.hckrt.com/ or any other public webpage operated by HACKRATE Kft. that links to these terms (together, the Website).
By accessing or using the Website, you agree to these Website Terms of Use. If you do not agree, please do not access or use the Website.
1. Subject of the Terms of Use
1.1 These Website Terms of Use apply to every visitor and user of the Website (User or you). The Website is operated by HACKRATE Kft., a company incorporated under Hungarian law, with its registered office at 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary, company registration number Cg. 11-09-028368, tax number 28961200-2-11, EU VAT number HU28961200, telephone +36 20 310 8651 and email address [email protected] (HACKRATE, Company, we, us or our).
1.2 You may use the Website only in accordance with applicable law, these Website Terms of Use and the rights of HACKRATE and third parties. You must not misuse, disrupt, damage, probe without authorisation, or attempt to gain unauthorised access to the Website or its underlying systems.
1.3 Separate terms apply to registered accounts, Bug Bounty Programs, Managed Vulnerability Disclosure Programs and other Hackrate services. If there is a conflict, the service-specific terms govern the relevant service, while these Website Terms of Use continue to govern general use of the public Website.
2. Intellectual Property Rights
2.1 The Website and its visual, textual, audiovisual, software and other content, including its layout, design, databases, trademarks, logos, trade names and domain names, are protected by copyright, trademark and other intellectual property laws. Unless stated otherwise, those rights belong to HACKRATE or its licensors.
2.2 You may view and make temporary copies of Website content for your own lawful, non-commercial use. Any other reproduction, modification, distribution, republication, public display, commercial exploitation or creation of derivative works requires HACKRATE's prior written permission, unless the use is expressly permitted by mandatory law, including Act LXXVI of 1999 on Copyright.
2.3 Where you lawfully quote or reuse Website content, you must identify HACKRATE and the Website as the source, preserve the meaning and integrity of the original material, and include an accurate and prominent link to the relevant page where reasonably practicable.
2.4 Nothing on the Website grants any licence or right to use a HACKRATE trademark, logo or other brand element except with HACKRATE's prior written permission or as expressly permitted by law.
3. User Accounts
3.1 Certain areas or services may require a registered account. Account registration and use are governed by the applicable service-specific terms, including the Bounty Hunter Terms of Use or the relevant business agreement.
3.2 Personal data collected through the Website or an account is processed as described in the Hackrate Privacy Notice.
4. Disclaimers and Liability
4.1 HACKRATE uses reasonable care to keep the Website available and its general information accurate and up to date. However, the Website and its public content are provided on an as is and as available basis. Public Website content is general information and is not legal, regulatory, financial or professional advice.
4.2 To the fullest extent permitted by applicable law, HACKRATE does not warrant that the Website will be uninterrupted, error-free, secure at all times, or free from harmful components, or that all information will always be complete, accurate, current or suitable for a particular purpose.
4.3 To the fullest extent permitted by applicable law, HACKRATE is not liable for loss arising solely from reliance on general public Website content, temporary unavailability of the Website, or the downloading of material from the Website. You are responsible for using appropriate security controls and backups when accessing or downloading online material.
4.4 HACKRATE may restrict, suspend or discontinue all or part of the Website where reasonably necessary for maintenance, security, legal compliance or business reasons.
4.5 Nothing in these Website Terms of Use excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud, fraudulent misrepresentation, wilful misconduct, or death or personal injury caused by negligence where applicable.
5. Links to Third-Party Websites
5.1 The Website may contain links to third-party websites or services. Those links are provided for convenience and do not constitute HACKRATE's endorsement of the third party, its content or its services.
5.2 HACKRATE does not control third-party websites and, to the fullest extent permitted by law, is not responsible for their availability, security, accuracy, privacy practices or content. You access third-party websites at your own risk and should review their applicable terms and privacy notices.
5.3 If HACKRATE becomes aware that a link on the Website directs Users to unlawful content, HACKRATE may remove or disable the link as appropriate.
6. Modifications
6.1 HACKRATE may update these Website Terms of Use where reasonably necessary, including to reflect changes to the Website, applicable law, security requirements or business practices.
6.2 The updated version will be published on this page with a revised “Last updated” date. Material changes will apply prospectively. Where required by law, HACKRATE will provide additional notice before a material change takes effect.
7. Contact
Questions about the Website may be submitted through the Contact page or by email to [email protected].
Program Sponsor Terms of Use
Last updated: 13 July 2026
These Program Sponsor Terms of Use (Terms) govern a Program Sponsor's access to and use of the Hackrate Ethical Hacking Platform for Bug Bounty Programs and the related services provided by HACKRATE (Platform and Services).
The Platform is owned and operated by HACKRATE Kft., with registered office at 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary, company registration number Cg. 11-09-028368, tax number 28961200-2-11, EU VAT number HU28961200, telephone +36 20 310 8651 and email [email protected] (HACKRATE).
The Program Sponsor and HACKRATE are each a Party and together the Parties.
THE PROGRAM SPONSOR'S ATTENTION IS PARTICULARLY DRAWN TO CLAUSES 8, 13, 14 AND 24 (WARRANTIES AND DISCLAIMERS; LIMITS ON LIABILITY; PAYMENTS AND INVOICING; AND LAW, DISPUTE RESOLUTION AND LANGUAGE).
1. Definitions
In these Terms:
Active Period means the period during which a Program Sponsor accepts Findings and makes the relevant Environment available for authorised testing. A period of suspension is not part of the Active Period, and cancellation ends the Active Period.
Affiliate means, in relation to a Party, any entity that directly or indirectly Controls, is Controlled by, or is under common Control with that Party.
Aggregate Data means information derived from use of the Platform or Services that has been aggregated and de-identified so that it does not identify, and cannot reasonably be used to identify, the Program Sponsor, a Bounty Hunter or another natural or legal person.
Agreement means these Terms, the applicable Order Form, any data processing agreement and any other document expressly incorporated into the Order Form or signed by authorised representatives of both Parties. If documents conflict, the Order Form prevails, followed by any data processing agreement for data-protection matters, then these Terms.
Authorisations has the meaning given in Clause 8.2(b).
Bounty Hunter means a registered and, where required, identity-verified natural person who is authorised to participate in a Bug Bounty Program under the Bounty Hunter Terms of Use and the applicable Program rules.
Bug Bounty Agreement means the agreement formed between the Program Sponsor and a Bounty Hunter under the applicable Bug Bounty Program rules when the Bounty Hunter is authorised to participate.
Bug Bounty Program or Program means the program rules made available through the Platform that define the Environment, scope, testing methods, restrictions, authorisation, reporting process, eligibility and, where applicable, Rewards.
Bug Bounty Report means a report submitted through the Platform concerning a Finding, including any Finding Materials, status information, triage notes and validation information made available to the Program Sponsor.
Confidential Information means information described in Clause 11 or otherwise identified as confidential or which a reasonable recipient should understand to be confidential given its nature and the circumstances of disclosure.
Control means direct or indirect ownership of more than 50% of the voting rights or equivalent power to direct the management of an entity.
Data Protection Legislation means Regulation (EU) 2016/679 (GDPR), Act CXII of 2011 on Informational Self-Determination and Freedom of Information, applicable electronic-communications and privacy laws, and any other data-protection law applicable to a Party, in each case as amended or replaced.
DPA means a data processing agreement meeting the requirements of Article 28 GDPR or other applicable Data Protection Legislation.
Environment means the systems, applications, interfaces, domains, accounts, data and other assets that the Program Sponsor is authorised to include and expressly includes within the scope of a Program. It excludes all Third-Party Systems unless the Program Sponsor has documented authority from their owner and expressly includes them.
Export Control Laws means applicable export-control, sanctions and trade-restriction laws and regulations.
Finding means a potential Vulnerability identified and reported within the authorised scope and Active Period of a Program.
Finding Materials means the Finding description, evidence, reproduction steps, screenshots, logs, Proof-of-Concept Code, Proof-of-Concept Documentation and related communications submitted for the purpose of reporting, validating or remediating a Finding.
Force Majeure means an event beyond a Party's reasonable control that prevents or materially delays performance, including natural disasters, war, civil unrest, epidemic, widespread telecommunications or utility failure, governmental action, or failure of a critical third-party infrastructure provider, excluding lack of funds.
HACKRATE Fees means Subscription Fees and any onboarding, management, validation, consulting or other fees specified in the Order Form, excluding the Program Budget.
Intellectual Property Rights means patents, utility models, rights in inventions, copyright and related rights, trademarks, service marks, trade names, domain names, design rights, database rights, trade secrets, know-how and all analogous rights, registered or unregistered, including applications and renewals.
Mandatory Policies means lawful security, compliance and business policies identified in the Program rules and made available to Bounty Hunters before they participate.
Order Form means an order, proposal, statement of work or other ordering document accepted by authorised representatives of both Parties and incorporating these Terms.
Platform Data means technical, operational and usage data generated by the Platform, excluding Program Sponsor Materials, Finding Materials and personal data except to the extent lawfully transformed into Aggregate Data.
Program Budget means funds provided by the Program Sponsor for approved monetary Rewards and any related payment charges expressly identified in the Order Form.
Program Sponsor means the business customer identified in an Order Form that defines and authorises a Program, controls or is duly authorised to test the Environment, determines Program scope and rules, evaluates Findings and approves Rewards.
Program Sponsor Materials means materials, data, credentials, instructions, policies and other content supplied by or on behalf of the Program Sponsor, including the Program rules and information about the Environment.
Proof-of-Concept Code means controlled code or another technical artefact reasonably necessary to demonstrate or validate a Finding.
Proof-of-Concept Documentation means information reasonably necessary to understand, reproduce, validate or remediate a Finding.
Reward means a monetary payment approved by the Program Sponsor for an eligible Finding under the Program rules.
Services means the Platform and the services specified in the Order Form.
Subscription Fees means recurring fees specified in the Order Form.
Term means the period described in Clause 3.
Third Party means a person other than HACKRATE, the Program Sponsor or their Affiliates.
Third-Party Systems means systems, data or services not solely controlled by the Program Sponsor and for which the Program Sponsor does not have documented authority to permit security testing.
Virus means malware or other code intended or reasonably likely to disrupt, damage, impair, alter or obtain unauthorised access to systems or data, excluding controlled Proof-of-Concept Code expressly permitted by the Program rules.
Vulnerability means a weakness in software, hardware, configuration, process or logic that may adversely affect confidentiality, integrity or availability.
2. Basis of Contract
2.1 An Order Form submitted or accepted by the Program Sponsor constitutes an offer to purchase the Services on these Terms.
2.2 The Agreement is formed when the Order Form is signed or otherwise expressly accepted by authorised representatives of both Parties. Each Order Form forms a separate Agreement. If more than one Program Sponsor signs an Order Form, they are jointly and severally responsible unless the Order Form states otherwise.
2.3 The Agreement applies to the exclusion of terms the Program Sponsor seeks to impose through a purchase order or similar document, unless HACKRATE expressly accepts those terms in writing.
2.4 HACKRATE may make non-material operational or legal updates to these Terms by giving reasonable notice. A change that materially reduces the Program Sponsor's contractual rights or materially expands its obligations will not apply to an existing Order Form before renewal unless required by law, security or a regulator, or agreed in writing.
3. Term
3.1 The Agreement begins on the effective date stated in the Order Form, or otherwise when the Order Form is accepted by both Parties, and continues for the subscription or Program period stated in the Order Form unless terminated under Clause 15.
3.2 A Program may have its own Active Period. Closure or suspension of one Program does not by itself terminate another Program or the Agreement unless the Order Form states otherwise.
4. Services
4.1 Subject to payment and compliance with the Agreement, the Program Sponsor may access and use the Platform for its own and its authorised Affiliates' internal business purposes to create, administer and monitor Programs, communicate with Bounty Hunters, receive and manage Findings, and use the Services stated in the Order Form.
The Program Sponsor may create Programs using the templates and configuration options available on the Platform. Each Program must clearly identify its Environment, scope, exclusions, authorised methods, prohibited methods, rate limits or testing windows where applicable, reporting requirements, confidentiality rules, safe-harbour conditions, eligibility criteria and Reward rules.
4.2 Services may include third-party services if stated in the Order Form. Third-party services are provided under the third party's terms and privacy notice. Unless the Order Form expressly states that HACKRATE assumes responsibility for a third-party service, HACKRATE is not responsible for acts, omissions or availability of that third party.
4.3 A Program may be public or private. For a private Program, the Program Sponsor may define selection criteria and approve invited Bounty Hunters. HACKRATE will make a private Program available only to selected or eligible Bounty Hunters, subject to Platform functionality and the Order Form.
4.4 HACKRATE may provide triage, validation, program management, consulting or other managed services only to the extent specified in the Order Form. The Platform does not by itself guarantee discovery of Vulnerabilities, complete coverage, remediation, regulatory compliance or prevention of cyber incidents.
5. HACKRATE's Obligations
5.1 HACKRATE shall:
(a) grant the Program Sponsor a non-exclusive, non-transferable right during the Term to use the Platform for the purposes permitted by the Agreement;
(b) provide the Services with reasonable skill and care and materially in accordance with the Order Form;
(c) cooperate reasonably with the Program Sponsor in relation to the Services;
(d) apply reasonable technical and organisational measures designed to protect the Platform and personal data processed by HACKRATE; and
(e) use reasonable efforts to notify the Program Sponsor of a material security or availability incident affecting the Services, subject to legal and security restrictions.
5.2 HACKRATE may suspend a feature or access where reasonably necessary to address a security threat, prevent abuse, comply with law or protect the Platform, the Program Sponsor, Bounty Hunters or third parties. HACKRATE will, where reasonably practicable, provide notice and restore access after the relevant issue is resolved.
6. Program Sponsor's Obligations
6.1 The Program Sponsor shall:
(a) provide accurate, complete and timely information reasonably requested by HACKRATE, including evidence of the identity and authority of its representatives and evidence that it controls or is authorised to test the Environment;
(b) comply with reasonable Platform, security and access instructions provided by HACKRATE;
(c) meet the technical and operational prerequisites stated in the Order Form;
(d) comply with the Agreement, the Program rules and its payment obligations;
(e) obtain and maintain all licences, consents, approvals and authorisations required to run the Program and permit the testing activities described in the Program rules;
(f) ensure that no Third-Party System is included unless its owner has provided documented authority for the testing and the Program Sponsor may lawfully grant that authority to Bounty Hunters and HACKRATE;
(g) define a clear, accurate and current Program scope and promptly notify HACKRATE and participating Bounty Hunters of material scope changes;
(h) identify prohibited testing methods, operational restrictions, emergency contacts and procedures for accidental access to personal, confidential or regulated data;
(i) make timely decisions on Findings, severity, duplication, eligibility and Rewards, and provide meaningful status updates;
(j) maintain appropriate backups, monitoring, incident response and defensive security controls for the Environment; and
(k) remain solely responsible for remediation decisions and for implementing, testing and deploying fixes.
6.2 In relation to Bounty Hunters, the Program Sponsor shall:
(a) ensure that the Program rules and resulting Bug Bounty Agreement accurately describe the authorised research;
(b) provide a secure reporting channel through the Platform or as otherwise agreed;
(c) not threaten or initiate legal action against a Bounty Hunter solely for good-faith research that materially complies with the Program rules, while preserving the Program Sponsor's rights in cases of intentional harm, fraud, extortion, unlawful data use, out-of-scope activity or other material breach;
(d) treat Finding Materials as confidential and limit access to persons who need them for validation, remediation, compliance or legal purposes; and
(e) approve Rewards in accordance with the published Program rules and avoid discriminatory or arbitrary treatment.
6.3 If HACKRATE's performance is prevented or delayed by an act, omission or breach of the Program Sponsor (Program Sponsor Default), HACKRATE may, to the extent reasonably necessary:
(a) suspend the affected Services until the default is remedied;
(b) adjust delivery dates;
(c) be relieved from affected obligations for the duration and extent of the default; and
(d) recover reasonable, documented additional costs directly caused by the default.
HACKRATE shall use reasonable efforts to notify the Program Sponsor and mitigate avoidable impact.
7. Rewards
7.1 The Program Sponsor may offer Rewards under the Program rules. HACKRATE will process an approved monetary Reward only after receiving sufficient cleared funds in the Program Budget and the information and approvals required for payment.
7.2 HACKRATE may refuse, suspend or delay receipt or payment of funds where reasonably required by applicable sanctions, export-control, anti-money-laundering, anti-fraud, tax, banking or payment-provider rules, or where the payment information cannot be verified. References to FATF lists do not create a blanket payment prohibition beyond applicable law and HACKRATE's documented risk controls.
7.3 HACKRATE may require a Bounty Hunter to provide tax-residence, identity, bank-account or other compliance documentation reasonably necessary for a particular payment. HACKRATE may withhold or deduct taxes only where required by applicable law and will provide available payment documentation.
7.4 The Program Sponsor remains responsible for the accuracy of Reward criteria and approval decisions. HACKRATE is not required to fund a Reward from its own assets unless expressly agreed in the Order Form.
8. Warranties and Disclaimers
8.1 HACKRATE warrants that, during the Term:
(a) it has authority to enter into the Agreement;
(b) it has the rights necessary to provide the Platform and grant the rights stated in the Agreement; and
(c) to HACKRATE's knowledge, the Program Sponsor's authorised use of the unmodified Platform does not infringe a Third Party's Intellectual Property Rights.
8.2 The Program Sponsor warrants that:
(a) it has authority to enter into and perform the Agreement;
(b) it has obtained and will maintain all licences, permissions, consents and other authorisations required for the Program, the Environment and HACKRATE's performance (Authorisations), and will provide reasonable evidence on request;
(c) Program Sponsor Materials and instructions, and HACKRATE's authorised use of them, do not infringe third-party rights;
(d) the Program and its instructions comply with applicable law and do not authorise unlawful access, interception, monitoring, disruption, data use or testing of Third-Party Systems; and
(e) it will not represent that the Platform or Services guarantee discovery of every Vulnerability, prevention of incidents, or compliance with a law or standard.
8.3 Findings and Bug Bounty Reports are based on security research, information supplied by the Program Sponsor and Bounty Hunters, and technical conditions at the time of testing. HACKRATE will use reasonable skill and care for any triage or validation included in the Order Form, but does not warrant that every report is complete, reproducible, free from error, or suitable as the sole basis for a business, legal, compliance or remediation decision.
8.4 The Program Sponsor acknowledges that:
(a) except for the express warranties in the Agreement, the Platform is provided on an as is and as available basis and may be affected by maintenance, internet limitations and third-party infrastructure;
(b) selection, engagement and use of a Bounty Hunter remains the Program Sponsor's decision. Bounty Hunters are independent users, not employees, agents or subcontractors of HACKRATE, unless expressly stated otherwise in an Order Form;
(c) a ranking, badge, profile or identity-verification status is an operational signal and not a guarantee of competence, conduct, trustworthiness or suitability;
(d) the Bug Bounty Agreement is between the Program Sponsor and the Bounty Hunter. HACKRATE facilitates the Platform and may provide Services, but is not a party to that agreement unless expressly stated in writing; and
(e) HACKRATE may provide similar services to third parties and develop competing or similar products, provided that it complies with its confidentiality obligations.
8.5 No testing program can eliminate cybersecurity risk. The Services do not replace secure development, vulnerability management, penetration testing where required, monitoring, access control, incident response, backups or other appropriate security controls.
8.6 The Program Sponsor is responsible for evaluating, prioritising, remediating and testing reported Vulnerabilities. HACKRATE is not responsible for loss caused by the Program Sponsor's failure or delay in remediation, except to the extent directly caused by HACKRATE's breach and subject to Clause 13.
9. Indemnity
9.1 The Program Sponsor shall indemnify HACKRATE and its officers, employees and agents against a third-party claim, and reasonable directly related costs, to the extent the claim arises from:
(a) Program Sponsor Materials, the Environment, Program rules or instructions infringing a third party's rights;
(b) the Program Sponsor lacking authority to permit the testing; or
(c) the Program Sponsor's unlawful or material breach of the Agreement.
9.2 HACKRATE shall indemnify the Program Sponsor against a third-party claim that the unmodified Platform, when used as permitted by the Agreement, infringes that third party's Intellectual Property Rights, except to the extent the claim arises from Program Sponsor Materials, Finding Materials, unauthorised modifications, combinations not supplied or approved by HACKRATE, or continued use after HACKRATE provides a non-infringing alternative.
9.3 An indemnity under this Clause is conditional on the indemnified Party:
(a) promptly notifying the indemnifying Party of the claim, provided that delay relieves the indemnifying Party only to the extent materially prejudiced;
(b) not admitting liability or settling without prior written consent, not to be unreasonably withheld or delayed;
(c) giving the indemnifying Party reasonable control of the defence and settlement; and
(d) providing reasonable cooperation at the indemnifying Party's cost.
9.4 No settlement may impose an admission, payment or non-monetary obligation on the indemnified Party without its prior written consent.
10. Compliance
10.1 Each Party shall comply with laws applicable to its performance of the Agreement, including Data Protection Legislation, anti-bribery, anti-corruption, sanctions and Export Control Laws.
10.2 Neither Party shall use the Services to facilitate unlawful activity, evade sanctions, obtain unauthorised access or interfere with third-party systems or communications.
10.3 HACKRATE may perform reasonable customer, representative and payment verification and may suspend or refuse Services where necessary to meet legal or risk-management obligations.
11. Confidentiality
11.1 Each receiving Party shall:
(a) keep the disclosing Party's Confidential Information confidential;
(b) protect it using at least reasonable care and no less care than it uses for its own similar information;
(c) use it only to perform or exercise rights under the Agreement; and
(d) disclose it only as permitted by this Clause.
11.2 Confidential Information may be disclosed to employees, Affiliates, auditors, professional advisers, insurers, financing sources, agents and subcontractors who need it for the Agreement and are bound by confidentiality obligations, and to authorities or courts where legally required.
11.3 Where legally permitted, a Party required to disclose Confidential Information shall give reasonable advance notice and cooperate with lawful efforts to limit the disclosure.
11.4 Confidential Information does not include information that the recipient can demonstrate:
(a) is lawfully public without breach;
(b) was lawfully known without restriction before disclosure;
(c) is lawfully received from a third party without confidentiality duty; or
(d) was independently developed without use of the Confidential Information.
11.5 The confidentiality obligations continue for five years after termination, except that trade secrets, credentials, personal data, non-public Findings and security-sensitive information remain protected for as long as they remain confidential or as required by law.
12. Intellectual Property Rights
12.1 HACKRATE and its licensors retain all Intellectual Property Rights in the Platform, Services, documentation, templates, methods, software and improvements. No rights are transferred except the limited right to use the Services under the Agreement.
12.2 The Program Sponsor and its licensors retain all Intellectual Property Rights in the Program Sponsor Materials and Environment.
12.3 The Program Sponsor grants HACKRATE a non-exclusive, worldwide, royalty-free licence during the Term, and afterwards only as needed for legal retention, backup and dispute handling, to host, copy, transmit, display, modify and otherwise use Program Sponsor Materials solely to provide, secure and support the Services and comply with law.
12.4 Ownership of Finding Materials created by a Bounty Hunter is governed by the Bounty Hunter Terms of Use and the applicable Program rules. Unless a Program expressly states and the Bounty Hunter separately accepts an assignment, the Bounty Hunter retains ownership and grants HACKRATE and the Program Sponsor a broad licence to use the Finding Materials for validation, remediation, security, compliance, evidence, internal training and related purposes. The Program Sponsor shall not use Finding Materials to create or distribute an exploit product or publicly identify the Bounty Hunter without authorisation.
12.5 HACKRATE may generate and use Aggregate Data for operating, securing, analysing, benchmarking and improving the Platform and Services; producing non-identifying statistics and security research; and demonstrating general service performance. HACKRATE shall not sell Program Sponsor Materials, Finding Materials or personal data. A public case study, testimonial or use of the Program Sponsor's name or logo requires the Program Sponsor's prior written approval.
12.6 If the Program Sponsor provides suggestions or feedback, it grants HACKRATE a worldwide, perpetual, irrevocable, royalty-free right to use that feedback without identifying the Program Sponsor or disclosing Confidential Information.
13. Limits on Liability
13.1 Subject to Clause 13.8, HACKRATE's liability for damage to or loss of tangible property directly caused by its breach or negligence, excluding loss or corruption of data, is limited to the Program Budget specified in the affected Order Form.
13.2 Subject to Clauses 13.4 and 13.8, HACKRATE's total aggregate liability arising out of or in connection with an Agreement, whether in contract, tort, negligence, breach of statutory duty, indemnity or otherwise, is limited to the HACKRATE Fees paid or payable under that Agreement for the six months immediately preceding the first event giving rise to the claim.
13.3 The Program Sponsor shall notify HACKRATE promptly after becoming aware of a potential claim and take reasonable steps to mitigate avoidable loss.
13.4 The cap in Clause 13.2 does not apply to HACKRATE's indemnity under Clause 9.2, but the exclusions in Clause 13.7 apply to the extent permitted by law.
13.5 Neither Party is liable to the extent a claim is caused by a product or service supplied directly to the claiming Party by a third party, or by the other Party's breach, instructions or failure to mitigate.
13.6 HACKRATE is not liable to the extent a claim results from unauthorised modification of the Platform, use contrary to documentation or the Agreement, or combination with unapproved systems, code or materials.
13.7 Subject to Clause 13.8, neither Party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business, goodwill, opportunity or data, whether direct or indirect. This exclusion does not prevent recovery of amounts properly payable to a third party under an indemnity or reasonable costs of restoring data from available backups where directly caused by a Party's breach.
13.8 Nothing in the Agreement excludes or limits liability for:
(a) death or personal injury caused by negligence;
(b) fraud, fraudulent misrepresentation or wilful misconduct;
(c) breach of confidentiality or unlawful processing of personal data to the extent liability cannot lawfully be limited;
(d) amounts owed under the payment obligations; or
(e) any liability that cannot lawfully be excluded or limited.
14. Payments and Invoicing
14.1 The Program Sponsor shall pay HACKRATE Fees and fund the Program Budget in accordance with the Order Form. Unless the Order Form states otherwise, fees are payable in advance and invoices are due within the period stated on the invoice.
14.2 Subscription renewal, notice periods and any price changes are governed by the Order Form. An automatic renewal applies only if expressly stated there. HACKRATE shall give any contractually required renewal or price-change notice.
14.3 Fees are non-refundable except as expressly stated in the Order Form, where HACKRATE terminates without cause before providing prepaid Services, or where required by applicable law. Termination does not affect accrued fees or approved Rewards.
14.4 Fees exclude VAT and similar taxes, which shall be added where applicable. Each Party is responsible for taxes imposed on its income, personnel or operations.
14.5 If an undisputed amount is overdue, HACKRATE may charge lawful default interest and, after reasonable notice, suspend affected Services until payment. The Program Sponsor shall raise a good-faith invoice dispute promptly and pay undisputed amounts on time.
15. Termination
15.1 Either Party may terminate an Agreement immediately by written notice if the other Party:
(a) commits a material breach that cannot be remedied; or
(b) fails to remedy a remediable material breach within 30 days after receiving written notice describing the breach and required remedy.
15.2 HACKRATE may suspend or terminate a Program immediately where continued testing creates a material security, safety or legal risk, or where the Program Sponsor lacks authority over the Environment. HACKRATE will notify the Program Sponsor as soon as reasonably practicable.
15.3 Termination does not affect accrued rights, liabilities, approved Reward obligations or clauses intended to survive, including confidentiality, intellectual property, data protection, liability, payment and dispute resolution.
15.4 On termination, the Program Sponsor's access will end, subject to a reasonable export period if stated in the Order Form. HACKRATE may retain data as required by the Agreement, the Privacy Notice, the DPA, backup cycles and applicable law.
16. Data Protection
16.1 Each Party shall comply with Data Protection Legislation for its processing under the Agreement.
16.2 Security testing may incidentally expose personal data. The Program Sponsor shall design the Program to minimise that risk, identify prohibited data-handling practices and provide instructions for accidental access. Bounty Hunters must stop unnecessary access, avoid exfiltration and promptly report the exposure through the authorised channel.
16.3 Each Party acts as an independent controller where it determines its own purposes and means of processing, including the Program Sponsor's decisions about the Program and Environment and HACKRATE's account administration, platform security, fraud prevention, legal compliance and service improvement.
16.4 To the extent HACKRATE processes personal data solely on the Program Sponsor's documented instructions, HACKRATE acts as processor and the Parties shall enter into or apply a DPA before that processing. If a specific processing activity makes the Parties joint controllers, they shall put an Article 26 GDPR arrangement in place before commencing that activity.
16.5 HACKRATE may disclose a Bounty Hunter's verified identity or contact information to the Program Sponsor only where reasonably necessary for Program administration, access authorisation, payment, compliance, safety, investigation or legal claims, and only on an applicable lawful basis and in accordance with the Privacy Notice. HACKRATE shall disclose only the data reasonably necessary for the stated purpose. Where consent is legally required, HACKRATE will request it.
16.6 Each Party shall implement appropriate technical and organisational measures, restrict access on a need-to-know basis, and notify and cooperate with the other Party without undue delay regarding a personal data breach materially affecting shared processing.
16.7 International transfers shall use a lawful transfer mechanism, including an adequacy decision, the European Commission's then-current standard contractual clauses or another safeguard permitted by Data Protection Legislation.
16.8 HACKRATE's processing of Platform users' personal data is described in the Hackrate Privacy Notice.
17. Variations
17.1 Except for updates permitted by Clause 2.4, a variation is effective only if recorded in writing and accepted by authorised representatives of both Parties. A valid electronic signature or clear electronic acceptance satisfies the writing requirement.
18. Force Majeure
18.1 A Party is not liable for delay or failure caused by Force Majeure, provided that it promptly notifies the other Party, uses reasonable efforts to mitigate the impact and resumes performance when reasonably possible.
18.2 If Force Majeure materially prevents the affected Services for 30 consecutive days, either Party may terminate those affected Services by written notice without penalty, except for amounts accrued before termination.
19. Assignment
19.1 Neither Party may assign the Agreement without the other Party's prior written consent, not to be unreasonably withheld or delayed, except that either Party may assign it to an Affiliate or in connection with a merger, reorganisation or sale of substantially all relevant assets, provided the assignee assumes the obligations and is not a direct competitor that creates a material confidentiality risk.
19.2 HACKRATE may use subcontractors to provide the Services and remains responsible for their performance to the same extent as for its own obligations, subject to the DPA for subprocessors.
20. Waiver
20.1 A delay or failure to exercise a right is not a waiver. A waiver is effective only if in writing and applies only to the specific circumstance for which it is given.
21. Severance
21.1 If a provision is invalid, unlawful or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable or, if that is not possible, treated as deleted. The remaining provisions continue in effect.
21.2 The Parties shall in good faith seek a lawful replacement that most closely reflects the original commercial purpose.
22. No Partnership
22.1 Nothing in the Agreement creates a partnership, joint venture, employment, fiduciary or agency relationship between the Parties, or authorises either Party to bind the other.
23. Notices
23.1 Formal notices under the Agreement must be in writing and sent by personal delivery, tracked post or email to the addresses stated in the Order Form or later notified under this Clause. Routine operational communications may be sent through the Platform.
23.2 A notice is deemed received:
(a) on delivery, if delivered personally;
(b) two business days after dispatch, if sent by tracked domestic post, or five business days if sent internationally; and
(c) when transmitted, if sent by email during the recipient's normal business hours and no delivery-failure message is received, otherwise at the start of the next business day.
23.3 A change of notice details is effective on the date specified in the change notice or, if later, two business days after receipt. This Clause 23.3 refers to the details in Clause 23.1.
24. Law, Dispute Resolution and Language
24.1 The Agreement and any non-contractual obligations arising from it are governed by the substantive laws of Hungary, excluding its conflict-of-laws rules.
24.2 In the event of any dispute arising from or in connection with the Agreement, including its breach, termination, validity or interpretation, the Parties exclude state-court proceedings and submit the dispute to the exclusive and final decision of the Permanent Arbitration Court attached to the Hungarian Chamber of Commerce and Industry (Commercial Arbitration Court Budapest). The Arbitration Court shall proceed under its Rules of Proceedings in force when the arbitration begins, excluding the Sub-Rules of Expedited Proceedings unless the Parties agree otherwise. The number of arbitrators shall be three, the seat of arbitration shall be Budapest, Hungary, and the language shall be English.
This does not prevent either Party from seeking urgent interim or protective relief from a competent court, or from enforcing an arbitral award.
24.3 If the Agreement is made available in more than one language, the English version prevails to the extent of any inconsistency, unless mandatory law requires otherwise.
Bounty Hunter Terms of Use
Last updated: 13 July 2026
1. About Us
1.1 Hackrate operates an ethical hacking platform through which organisations may publish or operate Bug Bounty Programs and invite independent security researchers to identify and responsibly report Vulnerabilities (the Platform).
1.2 The Platform enables eligible Bounty Hunters to apply for or join authorised Programs, receive the applicable Program rules and scope, submit Findings, communicate about reports and, where offered and approved, receive Rewards. A separate Bug Bounty Agreement is formed between the Bounty Hunter and the relevant Program Sponsor as described in Clause 7.
1.3 The Platform is operated by HACKRATE Kft., with registered office at 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary, company registration number Cg. 11-09-028368, tax number 28961200-2-11, EU VAT number HU28961200, telephone +36 20 310 8651 and email [email protected] (HACKRATE, we, us or our).
2. Our Contract with You
2.1 These Bounty Hunter Terms of Use (Terms, ToU or Agreement) govern your registration, account, use of the Platform and Services, and participation in Programs. By creating an account or otherwise accepting these Terms, you enter into an Agreement with HACKRATE.
If these Terms are made available in more than one language, the English version prevails to the extent of any inconsistency, unless mandatory law requires otherwise.
2.2 YOUR ATTENTION IS PARTICULARLY DRAWN TO CLAUSES 4, 6, 7, 8, 9, 12, 14, 15, 16, 17, 27 AND 28 (ACCOUNT AND IDENTITY VERIFICATION; THIRD-PARTY SYSTEMS; PROGRAM AUTHORISATION; REPORTING; REWARDS; YOUR OBLIGATIONS; INTELLECTUAL PROPERTY; CONFIDENTIALITY; EXPORT CONTROLS AND SANCTIONS; LIABILITY; GOVERNING LAW; AND DISPUTE RESOLUTION).
2.3 A Program may contain additional rules, including scope, testing restrictions, disclosure rules, eligibility and Reward criteria. Those Program rules form part of the Bug Bounty Agreement between you and the Program Sponsor. If Program rules conflict with these Terms, these Terms govern your relationship with HACKRATE; the Program rules govern your authorised testing and relationship with the Program Sponsor, except that no Program rule authorises you to breach applicable law or HACKRATE's Platform rules.
3. Definitions
In these Terms:
Active Period means the period during which a Program Sponsor accepts Findings and makes the relevant Environment available for authorised testing. A period of suspension is not part of the Active Period, and cancellation ends the Active Period.
Bounty Hunter means an individual aged 18 or over, with full legal capacity, who has a registered Platform account, has completed any verification required by HACKRATE or the relevant Program, and is authorised by a Program Sponsor to participate in a Program.
Bug Bounty Agreement means the agreement formed between a Bounty Hunter and a Program Sponsor under Clause 7 and the applicable Program rules.
Bug Bounty Program or Program means the rules made available through the Platform that identify the Program Sponsor, Environment, scope, exclusions, authorised and prohibited testing methods, Active Period, disclosure requirements, eligibility criteria and, where applicable, Reward criteria.
Bug Bounty Report means a report concerning one or more Findings submitted through the Platform, including Finding Materials and status, validation or triage information.
Confidential Information means information described in Clause 15 or otherwise identified as confidential, or which a reasonable person should understand to be confidential given its nature and the circumstances of disclosure.
Data Protection Legislation means Regulation (EU) 2016/679 (GDPR), Act CXII of 2011 on Informational Self-Determination and Freedom of Information, and other data-protection or privacy laws applicable to the relevant processing.
Environment means the systems, applications, networks, services and related data that the Program Sponsor controls or is authorised to include and that are expressly identified as in scope in the Program.
Export Control Laws means applicable export-control, trade-control, sanctions and embargo laws and regulations.
Finding means a Vulnerability identified in the Environment and submitted in accordance with the Program rules.
Finding Materials means the Finding, Bug Bounty Report, Proof-of-Concept Code, Proof-of-Concept Documentation, screenshots, logs, technical data and other materials submitted or created by you for a Program.
Heightened Cybersecurity Requirements means additional security, incident-reporting, confidentiality, screening, access or operational requirements that a Program Sponsor lawfully applies because of its regulatory, contractual or risk obligations, including, where applicable, requirements arising from Directive (EU) 2022/2555 (NIS2) as transposed into national law, Regulation (EU) 2022/2554 (DORA), or equivalent sector-specific rules.
Intellectual Property Rights means copyright and related rights, database rights, patents, utility models, rights in inventions, trademarks, service marks, trade names, domain names, design rights, trade secrets, know-how and analogous rights, registered or unregistered, including applications and renewals.
Mandatory Policies means lawful policies or codes identified in the Program rules and made available before participation.
Platform means the online applications, interfaces and websites provided by HACKRATE for the Services.
Program Sponsor means the organisation that defines and authorises a Program and controls, or is duly authorised to permit testing of, the Environment.
Proof-of-Concept Code means controlled code or another technical artefact reasonably necessary to demonstrate or validate a Finding and permitted by the Program rules.
Proof-of-Concept Documentation means information reasonably necessary to understand, reproduce, validate or remediate a Finding.
Reward means a monetary payment that a Program Sponsor may approve for an eligible Finding under the Program rules.
Services means the Platform and related services HACKRATE provides to you under these Terms.
Third Party means a person other than you, HACKRATE, the relevant Program Sponsor or their authorised representatives.
Third-Party Systems means systems, data or services outside the Environment or not expressly included in Program scope, including systems that the Program Sponsor does not solely control and has not documented authority to permit you to test.
Virus means malware or other code intended or reasonably likely to disrupt, damage, impair, alter or obtain unauthorised access to systems or data, excluding controlled Proof-of-Concept Code expressly permitted by the Program rules.
Vulnerability means a weakness in software, hardware, configuration, process or logic that may adversely affect confidentiality, integrity or availability.
4. Account Registration on the Platform
4.1 You must be a natural person aged 18 or over and have full legal capacity to register. You must provide accurate, complete and current account, contact, tax and payment information reasonably required by HACKRATE. You may not register using a false identity or on behalf of another person without documented authority.
4.2 You warrant that information and documents you submit are authentic, accurate and not misleading. You must promptly update information that changes.
4.3 You are responsible for keeping your password, authentication factors, recovery codes and account access confidential. You must use a unique, strong password and promptly notify HACKRATE at [email protected] or through the available support channel if you suspect unauthorised access. You are responsible for activity performed through your account to the extent caused by your failure to protect access credentials, subject to mandatory law.
4.4 HACKRATE may verify your email address, telephone number, payment details, tax information, professional details and identity before or during use of the Platform. Identity verification may be required for Platform access, private Programs, access to sensitive Environments, sanctions and fraud screening, or Reward payments.
4.5 HACKRATE uses ComplyCube, operated by TEEMO TECHNOLOGY LTD, as a service provider for identity verification. Depending on the verification workflow, you may be asked to provide identity and contact details, images or electronic data from an official identity document, and a selfie or short video. Facial matching or liveness checks may involve biometric processing. The verification interface and the Hackrate Privacy Notice provide further information, including legal bases, recipients, international transfers and retention criteria. Where explicit consent is legally required for biometric processing, it will be requested separately.
4.6 HACKRATE may approve, reject, limit, suspend or request additional review of a registration or verification result where reasonably necessary for security, fraud prevention, sanctions compliance, payment processing, Program eligibility or protection of users and clients. HACKRATE does not guarantee that automated verification signals are error-free. You may request human review of a verification or account decision by contacting [email protected] or the support channel identified in the decision.
4.7 Your account is personal and non-transferable. You must not sell, lend, share or permit another person to use it, and you must not operate multiple accounts to evade restrictions, ranking rules or sanctions.
4.8 HACKRATE may monitor account and Platform activity for security, integrity, misuse prevention, support and compliance. Monitoring is performed in accordance with the Privacy Notice and applicable law.
5. Acceptable Use of the Platform
5.1 When using the Platform, Services or participating in a Program, you must not upload, transmit, publish or engage in content or conduct that:
(a) is unlawful, fraudulent, threatening, harassing, defamatory, discriminatory, obscene or infringes another person's rights;
(b) facilitates crime or unlawful access;
(c) contains unlawful sexual content or exploitation material;
(d) promotes unlawful violence or intentional harm;
(e) distributes malware, uncontrolled exploit code or harmful payloads outside expressly authorised testing; or
(f) damages persons, property, systems or data beyond the minimum effect expressly authorised and necessary to validate a Finding.
5.2 HACKRATE may remove content, disable access, suspend activity or preserve evidence where it reasonably believes Clause 5 has been breached, or where necessary to protect the Platform, a Program Sponsor, users or third parties.
5.3 Unless expressly authorised by the applicable Program, you must not:
(a) perform activity outside Program scope, outside the Active Period, after authorisation has been withdrawn, or against systems or accounts not designated for testing;
(b) conduct denial-of-service, destructive, persistence, ransomware, social-engineering, phishing, physical-security, supply-chain or high-volume automated testing;
(c) copy, modify, download, disclose or distribute Environment or Platform data except for the minimum controlled evidence necessary to report a Finding;
(d) use the Environment or Platform to build or provide an unauthorised competing or third-party service;
(e) use a third-party scanning, exploitation, collaboration or data-sharing service in a way not permitted by the Program;
(f) access, monitor, intercept or record private or business communications, personal accounts, credentials or Third-Party Systems;
(g) sell, rent, transfer, sublicense or commercially exploit access to the Environment, Platform or Finding Materials;
(h) help another person gain unauthorised access; or
(i) introduce an uncontrolled attack, Virus, backdoor, persistent access mechanism or Vulnerability into HACKRATE's or a Program Sponsor's systems.
5.4 HACKRATE uses reasonable measures designed to prevent unauthorised access to the Platform but does not warrant that the Platform will be uninterrupted or immune from every security event.
6. Third-Party Systems
6.1 You must not test, access or use a Third-Party System unless it is expressly identified as in scope and the Program Sponsor has authority to permit that testing. A link, dependency, embedded service, shared cloud resource, IP address or technical relationship with the Environment does not by itself place a Third-Party System in scope.
6.2 If you discover that testing is affecting or may affect a Third-Party System, stop the affected activity and notify HACKRATE through the Platform. HACKRATE and the Program Sponsor cannot grant rights belonging to an unaffiliated third party.
6.3 The Platform may link to third-party websites or services. HACKRATE does not control or endorse them and is not a party to transactions you enter into with them. Review their terms and privacy notices before use.
7. Participation in a Bug Bounty Program
7.1 A Program may be public or private. Public availability does not mean unrestricted authorisation; only the express Program scope and rules define permitted testing.
7.2 You may browse and apply for eligible public Programs during their Active Period. For a private Program, HACKRATE or the Program Sponsor may invite or approve Bounty Hunters based on disclosed or internal eligibility criteria, including experience, location, verification status, legal restrictions or prior performance. You may decline an invitation.
7.3 Before testing, you must read and accept the current Program rules. You are responsible for checking scope, exclusions, prohibited methods, rate limits, testing windows, accounts, credentials, data-handling rules, disclosure terms, emergency contacts and Reward criteria. Material Program changes apply prospectively from notice unless required immediately for safety or law.
7.4 A Program Sponsor may impose Heightened Cybersecurity Requirements or Mandatory Policies. Those requirements must be made available to you before they bind your participation. HACKRATE may assist with publication but does not warrant that a Program Sponsor's requirements are complete, lawful or suitable for every jurisdiction.
7.5 HACKRATE may disclose your verified identity, contact information, professional details or payment-related status to a Program Sponsor only where reasonably necessary for Program access, administration, payment, compliance, safety, investigation or legal claims, on an applicable lawful basis and in accordance with the Privacy Notice. HACKRATE will limit disclosure to information reasonably necessary for the stated purpose. Where consent is legally required, it will be requested. If required information cannot lawfully be provided, HACKRATE or the Program Sponsor may restrict your participation in the affected Program.
7.6 By being approved for and participating in a Program, you enter into a separate Bug Bounty Agreement with the Program Sponsor on the applicable Program rules. HACKRATE facilitates the Platform and may provide triage or managed services but is not a party to that Bug Bounty Agreement unless expressly stated in writing.
7.7 The Program Sponsor, not HACKRATE, grants the legal and technical authorisation to test the Environment. HACKRATE cannot authorise testing of assets that the Program Sponsor does not control or have authority to include.
7.8 The Bug Bounty Agreement takes effect when the Program Sponsor approves your participation or, for a public Program that does not require individual approval, when you validly accept the Program rules and begin authorised activity. Rejection of an application means no testing authorisation is granted. You may ask HACKRATE to facilitate a review, but the Program Sponsor retains the final participation decision unless the Order Form states otherwise.
7.9 HACKRATE may notify you through the Platform or by email when access is approved and may make necessary technical details available. Access details are confidential and may be changed or withdrawn. HACKRATE does not warrant availability of the Environment.
7.10 HACKRATE may suspend your participation at the Program Sponsor's request or on its own reasonable assessment where activity appears out of scope, unsafe, unlawful or inconsistent with Program rules. Where appropriate and safe, HACKRATE will provide the reason and an opportunity to respond.
7.11 The Bug Bounty Agreement and authorisation end when the Program or Active Period ends, when you are removed, or when the Program Sponsor withdraws authorisation. You must immediately stop testing and using access credentials after notice or expiry.
7.12 Safe harbour. Under the Program Sponsor Terms of Use, the Program Sponsor is required not to threaten or initiate legal action solely for good-faith security research that materially complies with the Program rules. This safe-harbour commitment does not cover intentional harm, extortion, unlawful data use, concealment, out-of-scope activity, testing after withdrawal, third-party claims or material breach, and it cannot bind law-enforcement authorities or unaffiliated third parties.
8. Submitting Findings and the Bug Bounty Report
8.1 Submit a Finding through the authorised Platform channel promptly and during the Active Period, using the required format. Do not use public repositories, personal cloud drives, unapproved messaging services or public disclosure channels for confidential Finding Materials.
8.2 You may request reasonable clarification of Program rules or HACKRATE's assistance with triage. Such assistance does not expand scope or authorise further testing.
8.3 Include sufficient, accurate and proportionate evidence to permit reproduction and validation. Proof-of-Concept Code or Documentation is required only to the extent reasonably necessary and permitted by the Program. Remove or redact unnecessary personal, confidential, authentication and production data.
8.4 If testing exposes personal data, credentials, financial information, health data, private communications, trade secrets or other protected information, you must:
(a) stop accessing or viewing it beyond the minimum necessary to establish the exposure;
(b) not download, copy, modify, delete, exfiltrate, retain or disclose it except for minimal redacted evidence expressly necessary for the report;
(c) not use the data to contact affected persons, access accounts or demonstrate impact; and
(d) immediately report the exposure through the authorised channel and follow lawful containment instructions.
8.5 HACKRATE may review, triage, validate, classify, request clarification, merge, reject or forward Findings according to the Program and Services. The Program Sponsor may perform or commission its own validation. Neither HACKRATE nor the Program Sponsor guarantees acceptance of your severity assessment or Reward recommendation.
8.6 HACKRATE may create a Bug Bounty Report from submitted materials and make it available to the Program Sponsor. Reports may identify or pseudonymise you according to Program requirements and the Privacy Notice. HACKRATE may retain reports and audit history for service delivery, security, legal claims, compliance and the retention periods described in the Privacy Notice.
8.7 You may view available status information and comment or request a good-faith re-evaluation through the Platform. Re-evaluation does not guarantee a different outcome. Program Sponsor decisions on scope, duplication, severity, eligibility and Rewards are final unless the Program rules provide an appeal process or HACKRATE has authority under the Order Form to decide.
8.8 You must not publicly disclose a Finding without the prior written authorisation required by the Program rules. Coordinated disclosure dates or approvals must be recorded through the Platform or another authorised written channel.
9. Reward Payment
9.1 A Reward is available only if expressly offered by the Program and approved under its rules. Participation, submission, acceptance, validation or remediation does not by itself create a right to payment. HACKRATE does not fund a Reward from its own assets unless expressly stated.
9.2 HACKRATE may process an approved Reward after it receives cleared funds and payment authorisation from the Program Sponsor and you complete required identity, tax, bank, sanctions, anti-fraud or payment-provider checks. HACKRATE may refuse, suspend or delay payment where reasonably required by applicable law, sanctions, export controls, anti-money-laundering or anti-fraud controls, tax rules, banking restrictions, incomplete information or payment-provider requirements.
9.3 You must provide accurate payment instructions and any tax-residence, identity, invoice or other documentation reasonably required for the payment. Available currencies, methods, minimum amounts, fees and payment schedules may be shown on the Platform or communicated before payment. HACKRATE is not responsible for delays caused by incorrect information, intermediary banks, payment providers or events outside its reasonable control.
9.4 Rewards may be taxable income. You are responsible for determining, reporting and paying taxes and social-security charges that apply to you. HACKRATE may withhold or report amounts where required by law and will provide available payment documentation. Nothing in these Terms is tax advice.
9.5 If a payment is reversed, rejected or reasonably suspected to result from fraud, error, duplicate payment or unlawful activity, HACKRATE may investigate, suspend further payment and recover an amount paid in error, subject to applicable law and fair notice.
10. Bounty Hunter Evaluation
10.1 HACKRATE may maintain records of Platform and Program activity and display rankings, statistics, reputation indicators or leaderboards. The Privacy Notice explains the personal data used and the applicable purposes and legal bases.
10.2 HACKRATE or a Program Sponsor may assign positive or negative evaluation signals based on report quality, validity, duplication, rule compliance, communication and other documented criteria. These signals may be used to support invitations, access decisions or Program administration but are not guarantees of ability, trustworthiness or future performance.
10.3 If an automated or rules-based evaluation materially affects your Platform or Program access, you may request human review and provide relevant information through the support channel. HACKRATE may correct demonstrably inaccurate records but is not required to disclose confidential anti-fraud logic or another user's data.
10.4 HACKRATE may award digital badges or recognitions and allow you to share them, subject to brand guidelines. You must not alter or use a badge to make misleading claims about certification, employment or endorsement.
11. HACKRATE's Obligations
11.1 HACKRATE will provide the Platform and Services with reasonable skill and care, subject to these Terms and the relevant Program.
11.2 HACKRATE does not warrant uninterrupted or error-free access, that every Finding will be accepted, that every Vulnerability will be discovered, or that participation will result in a Reward or invitation.
11.3 HACKRATE is not responsible for delay or failure caused by internet, telecommunications, payment, third-party infrastructure or Environment limitations outside its reasonable control.
11.4 HACKRATE may provide similar services to third parties and develop or license similar products, provided it complies with its confidentiality and data-protection obligations.
11.5 HACKRATE will maintain the rights, permissions and organisational authority reasonably necessary to operate the Platform and perform its obligations.
12. The Bounty Hunter's Obligations
12.1 You shall:
(a) cooperate reasonably with HACKRATE and provide information necessary for the Services, verification, Program administration and payment;
(b) comply with applicable law, these Terms, Program rules, Heightened Cybersecurity Requirements and Mandatory Policies;
(c) act in good faith, use proportionate testing methods and minimise operational, data-protection and safety impact;
(d) use only accounts, credentials, tools, rates, source addresses, time windows and methods authorised by the Program;
(e) immediately stop testing when scope is unclear, authorisation ends, protected data is encountered, instability occurs, or HACKRATE or the Program Sponsor instructs you to stop;
(f) keep access details and Finding Materials secure and not share them with collaborators unless the Program expressly permits team participation and each collaborator is authorised;
(g) ensure your devices, networks and tools are reasonably secured and do not introduce uncontrolled risk;
(h) report conflicts of interest, insider access, prior knowledge or employment relationships that may affect Program eligibility;
(i) not submit another person's work as your own, fabricate evidence, manipulate severity, create a Vulnerability to report it, or submit a report you know is false, duplicate or previously disclosed without identifying that fact; and
(j) preserve relevant evidence and cooperate with reasonable investigation of suspected misuse, without compromising unrelated personal data or legal privilege.
12.2 You are an independent Platform user, not an employee, worker, agent, representative or subcontractor of HACKRATE. You have no authority to bind HACKRATE or a Program Sponsor.
13. Data Protection
13.1 HACKRATE processes your personal data as described in the Hackrate Privacy Notice, including for account administration, identity verification, Program access, communications, security, fraud prevention, payments, rankings, legal compliance and claims.
13.2 You must comply with Data Protection Legislation when handling personal data encountered during research. Program authorisation does not automatically authorise collection, use or disclosure of personal data beyond what is strictly necessary to identify and report a Vulnerability.
13.3 Unless a Program expressly states otherwise, you must not act as a processor of production personal data for HACKRATE or the Program Sponsor. If a specific Program requires processing on documented instructions, the relevant parties must agree appropriate data-processing terms before that activity begins.
13.4 HACKRATE may share personal data with the relevant Program Sponsor and service providers as described in the Privacy Notice. You must not use personal data received through the Platform for marketing, profiling, harassment, unrelated contact or any purpose outside the Program.
13.5 Report any actual or suspected unauthorised disclosure, loss or access to personal data through the Platform without undue delay.
14. Intellectual Property Rights
14.1 You retain ownership of Intellectual Property Rights in original Finding Materials that you create, subject to third-party rights and the licences in this Clause. No ownership transfer is implied merely because you submit a Finding or receive a Reward.
14.2 To the extent you own or control the necessary rights, you grant HACKRATE and the relevant Program Sponsor a worldwide, non-exclusive, royalty-free, perpetual and irrevocable licence to host, copy, reproduce, use, execute, test, validate, analyse, adapt, translate, display internally, distribute internally and create derivative works from Finding Materials for:
(a) triage, reproduction, validation and remediation;
(b) securing, testing and improving the Environment and related systems;
(c) operating and improving the Platform and Services;
(d) internal security training, audit, compliance, insurance and legal evidence; and
(e) exercising rights and performing obligations under these Terms and the Program.
14.3 HACKRATE and the Program Sponsor may sublicense the rights in Clause 14.2 to Affiliates, professional advisers, insurers, auditors, hosting or security providers, remediation vendors and other contractors who need the materials for those purposes and are bound by appropriate confidentiality and use restrictions. They may transfer the licence in connection with a merger, reorganisation or sale of the relevant business or Environment.
14.4 A Program may require assignment of specified Intellectual Property Rights only if the assignment is clearly disclosed before participation and you separately and expressly accept it. Any such assignment is governed by the Program rules and mandatory law; these general Terms do not themselves transfer ownership.
14.5 You warrant that, to your knowledge and after reasonable care, you created or lawfully control the rights in the Finding Materials and that their authorised use under this Clause does not knowingly infringe a third party's rights. Identify third-party or open-source materials and applicable licence terms in your report. You do not warrant ownership of the Program Sponsor's systems, data or code, or of facts and ideas that are not protected by Intellectual Property Rights.
14.6 You must not include code, data or content subject to terms that prevent HACKRATE or the Program Sponsor from using the report for validation and remediation. If you become aware of a rights issue, promptly notify HACKRATE and cooperate reasonably to replace or remove the affected material.
14.7 To the extent permitted by applicable law, you consent to reasonable technical modification, redaction, translation and integration of Finding Materials for the purposes above. Nothing authorises public attribution to you or public disclosure of your Finding without the approvals required by the Program and Privacy Notice.
15. Confidentiality
15.1 Confidential Information includes non-public details of the Platform, Program, Environment, credentials, source code, security controls, Finding Materials, Bug Bounty Reports, personal data, business information and the results of testing.
15.2 Each recipient shall protect Confidential Information using at least reasonable care, use it only for the Program or Agreement, and disclose it only to authorised persons who need it and are bound by confidentiality obligations.
15.3 You must not publicly disclose a Finding, exploit, screenshot, affected asset, Program detail or communication without the prior written approval required by the Program. A Program Sponsor's remediation or public acknowledgement does not by itself authorise disclosure of all Finding Materials.
15.4 Confidential Information does not include information that the recipient can demonstrate:
(a) became lawfully public without breach;
(b) was lawfully known without restriction before disclosure;
(c) was lawfully received from a third party without confidentiality duty; or
(d) was independently developed without use of the Confidential Information.
15.5 A recipient may disclose Confidential Information where legally required, provided that, where lawful and reasonably practicable, it gives advance notice and cooperates with efforts to limit the disclosure.
15.6 Confidentiality obligations continue after termination for as long as information remains confidential. Trade secrets, credentials, personal data, non-public Vulnerabilities and security-sensitive information remain protected for as long as required by law or their nature.
16. Export Compliance and Sanctions
16.1 You and HACKRATE must comply with Export Control Laws applicable to technical data, software, payments and services. You must not use the Platform or Finding Materials to evade sanctions, export restrictions or trade controls.
16.2 You must not provide access to controlled technical data or services to a prohibited person, entity, territory or end use. HACKRATE may restrict Programs, downloads, access or payments where reasonably required for compliance and may request information needed to assess applicable restrictions.
16.3 Nothing in these Terms requires either party to act in violation of applicable law. A restriction based on sanctions or export-control screening is not a representation that you have committed wrongdoing.
17. Limitation of Liability
17.1 The Platform, Programs, Environments and Services are provided on an as is and as available basis, subject to the express obligations in these Terms and any rights that cannot be excluded. HACKRATE does not warrant uninterrupted access, Program availability, acceptance of a Finding, payment of a Reward, accuracy of third-party information, or that testing will be free from technical or legal risk.
17.2 To the fullest extent permitted by applicable law:
(a) where HACKRATE breaches a material contractual obligation through slight negligence, HACKRATE's liability is limited to the foreseeable loss typical for this type of agreement;
(b) HACKRATE is not liable for a slightly negligent breach of a non-material contractual obligation or other duty of care; and
(c) HACKRATE is not liable for special, indirect or consequential loss, or for loss of opportunity, anticipated Reward, reputation, profit, revenue, business, data, savings or goodwill, including third-party claims, except to the extent such exclusion is not permitted by law.
17.3 HACKRATE is not liable to the extent loss results from acts or omissions of a Program Sponsor, another Bounty Hunter, payment provider or other Third Party; testing outside scope; use of unauthorised tools or data; failure to follow Program rules; or your device, network or credentials. HACKRATE remains responsible for its own obligations to the extent required by applicable law.
17.4 Nothing in these Terms excludes or limits liability where HACKRATE has given a specific guarantee, or for fraud, fraudulent misrepresentation, wilful misconduct, death or personal injury caused by negligence where applicable, breach of mandatory public-order obligations, unlawful processing of personal data to the extent it cannot be limited, an approved Reward that HACKRATE has received from a Program Sponsor and is contractually obliged to pass on to you, or any liability that cannot lawfully be excluded or limited.
17.5 If you are a consumer, nothing in these Terms limits mandatory consumer rights or remedies. The exclusions and limitations apply only to the extent valid under the law applicable to you.
18. Term and Termination
18.1 This Agreement begins when you accept it and continues until terminated.
18.2 Either party may terminate for material breach or other good cause. You may terminate by closing your account through the available account process or by contacting support, subject to completion of pending payment, investigation or legal-retention steps.
18.3 HACKRATE may suspend or terminate your account or Program access immediately where reasonably necessary to address an urgent security, safety, fraud, sanctions or legal risk; an out-of-scope or harmful activity; a material or repeated breach; false identity or payment information; or misuse of another person's account. Where the issue is remediable and urgent suspension is not required, HACKRATE will normally provide notice and a reasonable opportunity to respond.
18.4 On termination:
(a) all testing authorisations end unless a Program Sponsor separately confirms otherwise in writing;
(b) you must stop using credentials and return or securely delete confidential materials as instructed, except for records you must retain by law;
(c) HACKRATE may retain or delete account, report and payment data in accordance with the Privacy Notice, applicable contracts, backup cycles and law; and
(d) accrued rights, approved payment obligations and clauses intended to survive remain in effect, including Clauses 9, 13, 14, 15, 16, 17, 27 and 28.
19. Force Majeure
19.1 HACKRATE is not liable for delay or failure caused by events outside its reasonable control, including widespread internet, cloud, telecommunications, utility, payment or transport failure; cyberattack not caused by failure to use reasonable care; epidemic; natural disaster; war; civil disorder; labour dispute; government action; or supplier failure. HACKRATE will use reasonable efforts to mitigate material impact and restore affected Services.
20. Waiver
20.1 A delay or failure to exercise a right is not a waiver. A waiver is effective only if clearly given in writing and applies only to the specific circumstance stated.
21. Rights and Remedies
21.1 Except where these Terms expressly provide otherwise, contractual rights and remedies are cumulative and do not exclude rights or remedies available under applicable law.
22. Severance
22.1 If a provision is invalid, unlawful or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable or, if that is not possible, treated as deleted. The remaining provisions continue in effect.
22.2 The parties shall seek a lawful replacement that most closely reflects the original purpose, subject to mandatory consumer law where applicable.
23. Entire Agreement
23.1 These Terms, the Privacy Notice, the applicable Program rules and any document expressly incorporated into them constitute the agreement between you and HACKRATE concerning the Platform and supersede earlier statements on the same subject.
23.2 Nothing in this Clause excludes liability for fraud or fraudulent misrepresentation or limits mandatory rights. You acknowledge that general marketing statements do not create a warranty unless expressly included in these Terms or the applicable Program.
24. Assignment
24.1 You may not assign or transfer your account or this Agreement without HACKRATE's prior written consent.
24.2 HACKRATE may assign this Agreement to an Affiliate or in connection with a merger, reorganisation or sale of the relevant business, provided that the assignee assumes HACKRATE's obligations. HACKRATE may use subcontractors and remains responsible for their performance to the extent required by law and contract.
25. No Partnership or Agency
25.1 Nothing in these Terms creates a partnership, joint venture, employment, worker, fiduciary or agency relationship between you and HACKRATE or a Program Sponsor, or authorises you to bind either of them.
26. Notices
26.1 HACKRATE may send contractual notices through the Platform, to the email address registered to your account, or by another durable electronic method. You are responsible for maintaining a current email address and reviewing Platform notices.
26.2 A notice is considered received when made available in your account or sent by email without a delivery-failure message, except where mandatory law requires a different method. Operational messages may be effective immediately; material amendments will take effect as stated in the notice and, where required by law, only after reasonable advance notice.
26.3 You may send formal notices to [email protected] or by tracked post to HACKRATE Kft., 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary. Privacy requests should be sent to [email protected].
27. Governing Law
27.1 This Agreement and non-contractual obligations arising from it are governed by the substantive laws of Hungary, excluding conflict-of-laws rules. If you are a consumer, this choice does not deprive you of mandatory protections of the country where you habitually reside.
28. Dispute Resolution
28.1 Before starting formal proceedings, you and HACKRATE should attempt in good faith to resolve the dispute through written notice describing the issue and requested remedy. This does not suspend mandatory limitation periods or prevent urgent relief.
28.2 Business or professional users. If you enter into this Agreement in the course of a trade, business, craft or profession, any dispute arising from or in connection with it, including its breach, termination, validity or interpretation, shall be submitted to the exclusive and final decision of the Permanent Arbitration Court attached to the Hungarian Chamber of Commerce and Industry (Commercial Arbitration Court Budapest). The Arbitration Court shall proceed under its Rules of Proceedings in force when the arbitration begins, excluding the Sub-Rules of Expedited Proceedings unless the parties agree otherwise. The number of arbitrators shall be three, the seat shall be Budapest, Hungary, and the language shall be English.
28.3 Consumers. If you are a consumer, Clause 28.2 applies only to the extent a pre-dispute arbitration agreement is valid and binding under mandatory law. You retain the right to bring proceedings before courts having mandatory jurisdiction, including courts available under applicable consumer law. Nothing prevents either party from seeking urgent interim or protective relief from a competent court.
mVDP - User's Terms of Use
Last updated: 13 July 2026
1. About Us
1.1 Hackrate provides cybersecurity services, including Managed Vulnerability Disclosure Programs (mVDPs), through which individuals may responsibly report suspected security Vulnerabilities to participating organisations.
1.2 The mVDP reporting form and related services are operated by HACKRATE Kft., with registered office at 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary, company registration number Cg. 11-09-028368, tax number 28961200-2-11, EU VAT number HU28961200, telephone +36 20 310 8651 and email [email protected] (HACKRATE, we, us or our).
2. Our Contract with You
2.1 These mVDP User Terms of Use (Terms, ToU or Agreement) apply to you as an individual who uses an mVDP reporting form or submits a Finding (User or you). By accepting these Terms or submitting a report, you enter into this Agreement with HACKRATE. The relevant mVDP Program rules displayed with the form also apply to your authorised activity and submission.
If a provision is invalid or unenforceable, it shall be modified to the minimum extent necessary or treated as deleted without affecting the remainder. The parties shall seek a lawful replacement that most closely reflects the original purpose.
If these Terms are made available in more than one language, the English version prevails to the extent of any inconsistency, unless mandatory law requires otherwise.
2.2 YOUR ATTENTION IS PARTICULARLY DRAWN TO CLAUSES 4, 5, 6, 7, 9, 10, 11, 12, 13, 16 AND 17 (AUTHORISED USE; THIRD-PARTY SYSTEMS; SUBMITTING FINDINGS; AWARDS; YOUR OBLIGATIONS; INTELLECTUAL PROPERTY; CONFIDENTIALITY; EXPORT CONTROLS; LIABILITY; GOVERNING LAW; AND DISPUTE RESOLUTION).
3. Definitions
In these Terms:
Active Period means the period during which HACKRATE accepts Findings on behalf of an mVDP Client and the relevant Environment is available for authorised reporting. Suspension is not part of the Active Period, and cancellation ends it.
Confidential Information means non-public information concerning HACKRATE, the mVDP Client, the Environment, Finding Materials, personal data, credentials, business information or security controls, and information identified as confidential or reasonably understood to be confidential.
Environment means systems, applications, networks and services that the mVDP Client controls or is authorised to include and that are expressly identified as in scope in the mVDP Program.
Export Control Laws means applicable export-control, trade-control, sanctions and embargo laws and regulations.
Finding means a suspected Vulnerability identified in the Environment and reported in accordance with the mVDP Program.
Finding Materials means the Finding, Proof-of-Concept Code, Proof-of-Concept Documentation, screenshots, logs, technical data and other materials you submit.
Intellectual Property Rights means copyright and related rights, database rights, patents, rights in inventions, trademarks, service marks, trade names, domain names, design rights, trade secrets, know-how and analogous rights, registered or unregistered.
mVDP Client or Client means the organisation that authorises the mVDP Program, controls or is authorised to include the Environment, and receives relevant Findings from HACKRATE.
mVDP Form means the reporting form made available by or for HACKRATE for the relevant mVDP Program.
mVDP Program or Program means the vulnerability disclosure rules shown with the mVDP Form, including the Client, Environment, scope, exclusions, authorised methods, prohibited conduct, disclosure rules and Active Period.
Proof-of-Concept Code means controlled code or another technical artefact reasonably necessary to demonstrate or validate a Finding and permitted by the Program.
Proof-of-Concept Documentation means information reasonably necessary to understand, reproduce, validate or remediate a Finding.
Third Party means a person other than you, HACKRATE, the relevant Client or their authorised representatives.
Third-Party Systems means systems, data or services outside the Environment or not expressly included in scope, including systems the Client does not solely control and has not documented authority to permit you to test.
User means an individual who acts in good faith and submits a Finding through the mVDP Form. Unless the Program expressly says otherwise, an mVDP User is not required to hold a Hackrate Platform account or complete identity verification.
Virus means malware or other code intended or reasonably likely to disrupt, damage, impair, alter or obtain unauthorised access, excluding controlled Proof-of-Concept Code expressly permitted by the Program.
Vulnerability means a weakness in software, hardware, configuration, process or logic that may adversely affect confidentiality, integrity or availability.
4. Acceptable Use Requirements
4.1 You must act lawfully, in good faith and only within the express scope and rules of the Program. You must not engage in conduct or submit content that is fraudulent, harmful, threatening, harassing, defamatory, discriminatory, obscene, infringing, unlawful or designed to facilitate crime or intentional harm.
4.2 Unless the Program expressly authorises it, you must not:
(a) perform testing outside scope, outside the Active Period or after authorisation has been withdrawn;
(b) conduct denial-of-service, destructive, persistence, ransomware, social-engineering, phishing, physical-security, supply-chain or high-volume automated testing;
(c) copy, modify, download, disclose or distribute Environment data beyond the minimum evidence strictly necessary to report a Finding;
(d) use the Environment or mVDP Form to provide an unauthorised third-party or competing service;
(e) use an unapproved third-party scanner, exploitation service, collaboration platform or data-sharing service;
(f) access, monitor, intercept or record private or business communications, personal accounts, credentials or Third-Party Systems;
(g) sell, rent, transfer, sublicense or commercially exploit access to the Environment, mVDP Form or Finding Materials;
(h) help another person gain unauthorised access; or
(i) introduce an uncontrolled attack, Virus, backdoor, persistent access mechanism or Vulnerability.
4.3 Test only to the minimum extent necessary to establish the existence and impact of a suspected Vulnerability. Do not establish persistence, pivot, alter or delete data, access unrelated records, interrupt services or demonstrate impact through avoidable harm.
4.4 If scope is unclear, stop and request clarification through the mVDP Form or contact channel. A technical ability to access an asset is not authorisation.
4.5 HACKRATE may reject a submission, disable access or preserve evidence where it reasonably believes the Program or these Terms have been breached, or where necessary to protect the Client, HACKRATE, users or third parties.
5. Third-Party Systems
5.1 You must not access or test a Third-Party System unless it is expressly identified as in scope and the Client has authority to permit that testing. Links, embedded components, shared hosting, cloud infrastructure, IP ranges or dependencies do not by themselves place a Third-Party System in scope.
5.2 If testing affects or may affect a Third-Party System, stop the affected activity and notify HACKRATE. Neither HACKRATE nor the Client can grant rights belonging to an unaffiliated third party.
6. Submitting Findings
6.1 Read and accept the Program rules displayed with the mVDP Form before testing or submitting information. The Program rules define the Client's authorisation; these Terms do not authorise activity outside that scope.
6.2 Use only the authorised reporting channel and submit the Finding promptly during the Active Period. Do not disclose it publicly or through an unapproved repository, messaging service or cloud drive.
6.3 Include accurate, proportionate evidence sufficient to understand and, where reasonably possible, reproduce the Finding. Proof-of-Concept Code or Documentation is required only where reasonably necessary and permitted. Do not include unnecessary personal data, secrets, credentials, production records or harmful payloads.
6.4 If you encounter personal data, credentials, private communications, financial or health information, trade secrets or other protected information:
(a) stop accessing it beyond the minimum necessary to establish the exposure;
(b) do not download, copy, modify, delete, retain or disclose it except for minimal redacted evidence necessary for the report;
(c) do not use it to access accounts or contact affected persons; and
(d) immediately report the exposure and follow lawful containment instructions.
6.5 Do not submit high-volume, automated or low-quality reports that materially duplicate each other or lack a reasonable basis. You may submit separate Findings where they reflect materially different root causes or affected assets and the Program permits it.
6.6 You warrant that, to your knowledge, information you submit is accurate, not fabricated and not knowingly misleading. Identify uncertainty, assumptions, prior disclosure, duplicate status and any conflict of interest.
6.7 You may provide an email address or other contact information if you wish to receive questions or status information. The Privacy Notice explains how HACKRATE and the Client process that data. Anonymous or pseudonymous reporting may be available where the form permits it, but may limit follow-up or recognition.
6.8 HACKRATE may review, triage, validate, classify, request clarification, merge, reject or forward a Finding according to the Services agreed with the Client. HACKRATE will use reasonable skill and care for included triage but does not guarantee that every Finding is reproducible, accepted, remediated or answered.
6.9 Safe harbour. Under the mVDP Client Terms and Conditions, the Client is required to provide a good-faith authorisation and not to threaten or initiate legal action solely for activity that materially complies with the Program. This commitment does not cover intentional harm, extortion, unlawful data use, concealment, out-of-scope activity, testing after withdrawal, third-party claims or material breach, and cannot bind law-enforcement authorities or unaffiliated third parties.
7. Awards
7.1 An mVDP is a vulnerability disclosure channel, not a Bug Bounty Program. Unless the Program expressly states otherwise, HACKRATE does not offer or owe a Reward, payment, gift or other compensation for a submission.
7.2 A Client may choose, at its sole discretion, to recognise or reward a User outside HACKRATE's control. No submission, validation, acceptance or remediation creates a payment entitlement unless a written offer expressly states the criteria and is accepted.
8. HACKRATE's Obligations
8.1 HACKRATE will make the mVDP Form available and provide the agreed review, triage, validation, communication and reporting services with reasonable skill and care.
8.2 HACKRATE may contact you if you provide valid contact details and clarification is reasonably needed. HACKRATE is not required to disclose confidential Client information or provide continuous status updates.
8.3 HACKRATE does not warrant uninterrupted access, that every Finding will be validated or accepted, that the Client will remediate it, or that use of the mVDP Form will meet every User requirement.
8.4 HACKRATE is not responsible for internet, telecommunications, third-party infrastructure or Environment limitations outside its reasonable control.
8.5 HACKRATE may provide similar services to other organisations and develop or license similar products, subject to confidentiality and data-protection obligations.
9. The User's Obligations
9.1 You shall:
(a) cooperate reasonably with HACKRATE and provide information necessary to understand the Finding;
(b) comply with applicable law, these Terms and the Program rules;
(c) act in good faith and minimise operational, privacy and safety impact;
(d) stop activity when instructed, when authorisation ends, when scope is unclear, when instability occurs or when protected data is encountered;
(e) keep access information and Finding Materials secure;
(f) not submit another person's work as your own, fabricate evidence, create a Vulnerability to report it, or conceal prior knowledge or conflicts of interest;
(g) use reasonably secure devices, networks and tools; and
(h) promptly report an actual or suspected unauthorised disclosure or loss of personal or confidential data arising from your activity.
9.2 You are an independent reporter, not an employee, worker, agent, representative or subcontractor of HACKRATE or the Client, and have no authority to bind either of them.
10. Intellectual Property Rights
10.1 You retain ownership of Intellectual Property Rights in original Finding Materials that you create, subject to third-party rights and the licences in this Clause. No ownership transfer is implied by submission.
10.2 To the extent you own or control the necessary rights, you grant HACKRATE and the relevant Client a worldwide, non-exclusive, royalty-free, perpetual and irrevocable licence to host, copy, reproduce, use, execute, test, validate, analyse, adapt, translate, display internally, distribute internally and create derivative works from Finding Materials for:
(a) triage, reproduction, validation and remediation;
(b) securing, testing and improving the Environment and related systems;
(c) operating and improving the mVDP Form and Services;
(d) internal security training, audit, compliance, insurance and legal evidence; and
(e) performing obligations and exercising rights under these Terms and the Program.
10.3 HACKRATE and the Client may sublicense those rights to Affiliates, professional advisers, insurers, auditors, hosting or security providers, remediation vendors and contractors who need the materials for those purposes and are bound by appropriate confidentiality and use restrictions. They may transfer the licence in connection with a merger, reorganisation or sale of the relevant business or Environment.
10.4 You warrant that, to your knowledge and after reasonable care, you created or lawfully control the relevant rights and that authorised use does not knowingly infringe third-party rights. Identify third-party or open-source materials and their licence terms. You do not warrant ownership of the Client's systems, code, data, facts or unprotectable ideas.
10.5 To the extent permitted by law, you consent to reasonable technical modification, redaction and translation for the purposes above. Nothing authorises public attribution to you or public disclosure of the Finding without the approvals required by the Program and Privacy Notice.
11. Confidentiality
11.1 Non-public details of the Program, Environment, credentials, security controls, Finding Materials, personal data, Client business information and testing results are Confidential Information.
11.2 You must protect Confidential Information using at least reasonable care, use it only to report the Finding, and not disclose it to a Third Party without prior written authorisation from HACKRATE or the Client as required by the Program.
11.3 Confidential Information does not include information you can demonstrate became lawfully public without breach, was lawfully known without restriction, was lawfully received from a third party without confidentiality duty, or was independently developed without use of the Confidential Information.
11.4 A legally required disclosure is permitted only to the extent required. Where lawful and reasonably practicable, give advance notice and cooperate with efforts to limit the disclosure.
11.5 These obligations continue for as long as the information remains confidential. Trade secrets, credentials, personal data, non-public Vulnerabilities and security-sensitive information remain protected for as long as required by law or their nature.
12. Export Compliance
12.1 You and HACKRATE must comply with Export Control Laws applicable to technical data, software and services. You must not use the mVDP Form or Finding Materials to evade sanctions, export restrictions or trade controls.
12.2 HACKRATE may restrict access or disclosure where reasonably required for compliance and may request information needed to assess a restriction. Nothing requires either party to act unlawfully.
13. Limitation of Liability
13.1 The mVDP Form, Program and Environment are provided on an as is and as available basis, subject to express obligations and rights that cannot be excluded. HACKRATE does not warrant uninterrupted access, acceptance or remediation of a Finding, accuracy of third-party information, or that research will be free from technical or legal risk.
13.2 To the fullest extent permitted by applicable law:
(a) where HACKRATE breaches a material contractual obligation through slight negligence, HACKRATE's liability is limited to the foreseeable loss typical for this type of agreement;
(b) HACKRATE is not liable for a slightly negligent breach of a non-material contractual obligation or other duty of care; and
(c) HACKRATE is not liable for special, indirect or consequential loss, or for loss of use, data, profit, savings, opportunity, anticipated award, reputation or goodwill, including third-party claims, except to the extent such exclusion is not permitted by law.
13.3 HACKRATE is not liable to the extent loss results from acts or omissions of the Client or another Third Party, out-of-scope activity, failure to follow the Program, or your device, network or credentials. HACKRATE remains responsible for its own obligations to the extent required by applicable law.
13.4 Nothing excludes or limits liability where HACKRATE has given a specific guarantee, or for fraud, fraudulent misrepresentation, wilful misconduct, death or personal injury caused by negligence where applicable, breach of mandatory public-order obligations, unlawful processing of personal data to the extent it cannot be limited, or any liability that cannot lawfully be excluded or limited.
13.5 If you are a consumer, nothing in these Terms limits mandatory consumer rights or remedies, and the exclusions and limitations apply only to the extent valid under the law applicable to you.
14. Rights and Remedies
14.1 Except where these Terms expressly provide otherwise, contractual rights and remedies are cumulative and do not exclude rights or remedies available under applicable law.
15. Entire Agreement
15.1 These Terms, the Privacy Notice and the applicable Program rules constitute the agreement between you and HACKRATE concerning the mVDP Form and supersede earlier statements on the same subject.
15.2 Nothing in this Clause excludes liability for fraud or fraudulent misrepresentation or limits mandatory rights. General marketing statements do not create a warranty unless expressly included in these Terms or the Program.
16. Governing Law
16.1 This Agreement and non-contractual obligations arising from it are governed by the substantive laws of Hungary, excluding conflict-of-laws rules. If you are a consumer, this choice does not deprive you of mandatory protections of the country where you habitually reside.
17. Dispute Resolution
17.1 Before starting formal proceedings, you and HACKRATE should attempt in good faith to resolve the dispute through written notice describing the issue and requested remedy. This does not suspend mandatory limitation periods or prevent urgent relief.
17.2 Business or professional users. If you submit the report in the course of a trade, business, craft or profession, any dispute arising from or in connection with this Agreement, including its breach, termination, validity or interpretation, shall be submitted to the exclusive and final decision of the Permanent Arbitration Court attached to the Hungarian Chamber of Commerce and Industry (Commercial Arbitration Court Budapest). The Arbitration Court shall proceed under its Rules of Proceedings in force when the arbitration begins, excluding the Sub-Rules of Expedited Proceedings unless the parties agree otherwise. The number of arbitrators shall be three, the seat shall be Budapest, Hungary, and the language shall be English.
17.3 Consumers. If you are a consumer, Clause 17.2 applies only to the extent a pre-dispute arbitration agreement is valid and binding under mandatory law. You retain the right to bring proceedings before courts having mandatory jurisdiction, including courts available under applicable consumer law. Nothing prevents either party from seeking urgent interim or protective relief from a competent court.
mVDP - Terms and Conditions for Clients
Last updated: 13 July 2026
These Terms and Conditions (Terms) govern a Client's use of Hackrate's Managed Vulnerability Disclosure Program (mVDP) and related services, including the mVDP reporting form, triage and communication services specified in an Order Form (mVDP Form and Services).
The Services are provided by HACKRATE Kft., with registered office at 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary, company registration number Cg. 11-09-028368, tax number 28961200-2-11, EU VAT number HU28961200, telephone +36 20 310 8651 and email [email protected] (HACKRATE).
The Client and HACKRATE are each a Party and together the Parties.
THE CLIENT'S ATTENTION IS PARTICULARLY DRAWN TO CLAUSES 8, 13, 14, 16 AND 24 (WARRANTIES AND DISCLAIMERS; LIMITS ON LIABILITY; PAYMENTS AND INVOICING; DATA PROTECTION; AND LAW, DISPUTE RESOLUTION AND LANGUAGE).
1. Definitions
In these Terms:
Active Period means the period during which HACKRATE accepts Findings on behalf of the Client and the Client makes the Environment available for authorised reporting. A period of suspension is not part of the Active Period, and cancellation ends it.
Affiliate means, in relation to a Party, an entity that directly or indirectly Controls, is Controlled by, or is under common Control with that Party.
Aggregate Data means information derived from the mVDP Form or Services that has been aggregated and de-identified so that it does not identify, and cannot reasonably be used to identify, the Client, a User or another natural or legal person.
Agreement means these Terms, the applicable Order Form, any data processing agreement and any other document expressly incorporated into the Order Form or signed by authorised representatives of both Parties. If documents conflict, the Order Form prevails, followed by any data processing agreement for data-protection matters, then these Terms.
Authorisations has the meaning given in Clause 8.2(b).
Client means the business customer identified in the Order Form that controls, or is duly authorised to permit reporting or testing of, the Environment and defines the mVDP Program.
Client Materials means materials, data, credentials, instructions, policies, brand assets and other content supplied by or on behalf of the Client, including the mVDP Program rules and information about the Environment.
Confidential Information means information described in Clause 11 or otherwise identified as confidential, or which a reasonable recipient should understand to be confidential given its nature and the circumstances of disclosure.
Control means direct or indirect ownership of more than 50% of voting rights or equivalent power to direct the management of an entity.
Data Protection Legislation means Regulation (EU) 2016/679 (GDPR), Act CXII of 2011 on Informational Self-Determination and Freedom of Information, and other data-protection or privacy laws applicable to the relevant processing.
Environment means the systems, applications, networks, services and related data that the Client controls or is authorised to include and expressly identifies in the mVDP Program.
Export Control Laws means applicable export-control, trade-control, sanctions and embargo laws and regulations.
Finding means a suspected Vulnerability identified in the Environment and submitted through the mVDP Form in accordance with the mVDP Program.
Finding Materials means the Finding, Proof-of-Concept Code, Proof-of-Concept Documentation, screenshots, logs, technical data and other materials submitted by a User or created in connection with a Finding.
Force Majeure means an event outside a Party's reasonable control, including widespread internet, cloud, telecommunications, utility, payment or transport failure; cyberattack not caused by failure to use reasonable care; epidemic; natural disaster; war; civil disorder; labour dispute; government action; or material supplier failure.
HACKRATE Fees means subscription, implementation, triage, management, consulting and other fees specified in the Order Form.
Intellectual Property Rights means copyright and related rights, database rights, patents, utility models, rights in inventions, trademarks, service marks, trade names, domain names, design rights, trade secrets, know-how and analogous rights, registered or unregistered, including applications and renewals.
mVDP Data means technical, operational and usage data generated by the mVDP Form or Services, excluding Client Materials, Finding Materials and personal data except to the extent lawfully transformed into Aggregate Data.
mVDP Form means the reporting form or interface made available by HACKRATE for the Client's mVDP Program.
mVDP Program or Program means the rules made available with the mVDP Form that identify the Client, Environment, scope, exclusions, authorised and prohibited activity, reporting process, safe-harbour conditions, disclosure rules and Active Period.
mVDP Report means a report concerning a Finding made available to the Client through the Services, including Finding Materials and status, triage or validation information.
Order Form means an order, proposal, statement of work or other ordering document accepted by authorised representatives of both Parties and incorporating these Terms.
Proof-of-Concept Code means controlled code or another technical artefact reasonably necessary to demonstrate or validate a Finding and permitted by the Program.
Proof-of-Concept Documentation means information reasonably necessary to understand, reproduce, validate or remediate a Finding.
Services means the mVDP Form and services specified in the Order Form.
Subscription Fees means recurring fees specified in the Order Form.
Term means the period described in Clause 3.
Third Party means a person other than HACKRATE, the Client or their Affiliates.
Third-Party Systems means systems, data or services not solely controlled by the Client and for which the Client does not have documented authority to permit reporting or security testing.
User means an individual who uses the mVDP Form to submit a Finding under the mVDP User Terms of Use. Unless the Order Form expressly states otherwise, HACKRATE does not verify a User's identity.
Virus means malware or other code intended or reasonably likely to disrupt, damage, impair, alter or obtain unauthorised access, excluding controlled Proof-of-Concept Code expressly permitted by the Program.
Vulnerability means a weakness in software, hardware, configuration, process or logic that may adversely affect confidentiality, integrity or availability.
2. Basis of Contract
2.1 An Order Form submitted or accepted by the Client constitutes an offer to purchase the Services on these Terms.
2.2 The Agreement is formed when the Order Form is signed or otherwise expressly accepted by authorised representatives of both Parties. Each Order Form forms a separate Agreement. If more than one Client signs an Order Form, they are jointly and severally responsible unless the Order Form states otherwise.
2.3 The Agreement applies to the exclusion of terms the Client seeks to impose through a purchase order or similar document, unless HACKRATE expressly accepts those terms in writing.
2.4 HACKRATE may make non-material operational or legal updates to these Terms by giving reasonable notice. A change that materially reduces the Client's contractual rights or materially expands its obligations will not apply to an existing Order Form before renewal unless required by law, security or a regulator, or agreed in writing.
3. Term
3.1 The Agreement begins on the effective date stated in the Order Form, or otherwise when the Order Form is accepted by both Parties, and continues for the subscription period stated there unless terminated under Clause 15.
3.2 The mVDP Program may have its own Active Period. Suspension or closure of the Program does not by itself terminate the Agreement unless the Order Form states otherwise.
4. Services
4.1 Subject to payment and compliance with the Agreement, the Client may use and embed the mVDP Form on the domain, applications or other Environments identified in the Order Form for its own and its authorised Affiliates' internal business purposes. The number of domains, subdomains, applications or brands covered is determined by the Order Form, not by a fixed rule in these Terms.
4.2 The Client shall define and keep current the mVDP Program, including the Environment, scope, exclusions, authorised and prohibited methods, testing limits, emergency contacts, data-handling rules, disclosure terms and safe-harbour conditions. The mVDP Form is a reporting and workflow channel; it does not by itself authorise activity beyond the Program.
4.3 Services may include third-party services if stated in the Order Form. Third-party services are subject to their own terms and privacy notices. Unless HACKRATE expressly assumes responsibility in the Order Form, HACKRATE is not responsible for acts, omissions or availability of a third-party service.
4.4 HACKRATE may provide review, triage, validation, researcher communication, program management, consulting or other services only to the extent specified in the Order Form. An mVDP is not a Bug Bounty Program unless expressly agreed, and HACKRATE does not guarantee discovery of Vulnerabilities, complete technical validation, remediation, regulatory compliance or prevention of cyber incidents.
5. HACKRATE's Obligations
5.1 HACKRATE shall, to the extent included in the Order Form:
(a) make the mVDP Form available and grant the Client a non-exclusive, non-transferable right during the Term to use it for the agreed mVDP Program;
(b) receive Findings submitted through the mVDP Form;
(c) review, triage, classify and, where reasonably possible and authorised, validate Findings with reasonable skill and care;
(d) communicate with a User where contact details are provided and clarification is reasonably necessary;
(e) make relevant Findings and HACKRATE's available triage or validation information accessible to the Client;
(f) provide agreed assistance and consulting concerning the operation of the mVDP Program; and
(g) cooperate reasonably with the Client in relation to the Services.
5.2 HACKRATE may reject, merge, request clarification on, or classify a submission as out of scope, duplicate, informational, not reproducible or otherwise ineligible, based on the available evidence and Program rules. The Client remains responsible for remediation and may perform its own validation.
5.3 HACKRATE shall apply reasonable technical and organisational measures designed to protect the mVDP Form and personal data processed by HACKRATE, and shall use reasonable efforts to notify the Client of a material security or availability incident affecting the Services, subject to legal and security restrictions.
5.4 HACKRATE may suspend the mVDP Form or affected activity where reasonably necessary to address a security threat, prevent abuse, comply with law or protect the Client, Users, HACKRATE or third parties. Where reasonably practicable, HACKRATE will provide notice and restore the affected Services after the issue is resolved.
6. Client's Obligations
6.1 The Client shall:
(a) provide accurate, complete and timely information reasonably requested by HACKRATE, including evidence that the Client controls or is authorised to include the Environment;
(b) comply with reasonable Platform, security, integration and access instructions;
(c) meet technical and operational prerequisites stated in the Order Form;
(d) comply with the Agreement and its payment obligations;
(e) obtain and maintain all licences, consents, approvals and authorisations required for the Program, Environment and HACKRATE's performance;
(f) exclude Third-Party Systems unless their owner has provided documented authority and the Client may lawfully extend the relevant authorisation to Users and HACKRATE;
(g) define clear, accurate and current Program scope, prohibited methods, data-handling rules, emergency contacts and disclosure rules, and promptly notify HACKRATE of material changes;
(h) avoid changes that materially affect the Environment or validation process without reasonable advance notice where practicable; urgent security changes may be made immediately with prompt notice;
(i) provide HACKRATE personnel and subcontractors with the limited authorisation reasonably necessary to perform agreed validation or support activity in the Environment;
(j) provide a clear good-faith authorisation and safe-harbour statement for Users acting within the Program, and not threaten or initiate legal action solely for activity that materially complies with the Program, while preserving rights in cases of intentional harm, fraud, extortion, unlawful data use, out-of-scope activity or other material breach;
(k) maintain appropriate backups, monitoring, incident response, access control and defensive security controls for the Environment;
(l) review Findings promptly, provide meaningful status information where agreed, and make remediation decisions; and
(m) remain solely responsible for implementing, testing and deploying fixes and for legal, regulatory and incident-notification decisions.
6.2 The Client shall not instruct HACKRATE or Users to perform unlawful access, interception, monitoring, disruption, data collection or testing. The Client is responsible for ensuring that its Program rules and statements accurately describe the authority it can grant.
6.3 If HACKRATE's performance is prevented or delayed by an act, omission or breach of the Client (Client Default), HACKRATE may, to the extent reasonably necessary:
(a) suspend the affected Services until the default is remedied;
(b) adjust delivery dates;
(c) be relieved from affected obligations for the duration and extent of the default; and
(d) recover reasonable, documented additional costs directly caused by the default.
HACKRATE shall use reasonable efforts to notify the Client and mitigate avoidable impact.
7. Rewards
7.1 The Client acknowledges that an mVDP does not ordinarily include a Reward. If the Client chooses to recognise or reward a User, the Client is solely responsible for defining eligibility, making the offer, funding and providing the award, and complying with applicable tax, sanctions and payment rules, unless the Order Form expressly states that HACKRATE will administer the payment.
7.2 HACKRATE is not liable for a reward, payment or compensation offered directly by the Client and does not become a party to that arrangement merely by transmitting information.
8. Warranties and Disclaimers
8.1 HACKRATE warrants that, during the Term:
(a) it has authority to enter into the Agreement;
(b) it has the rights necessary to provide the mVDP Form and grant the rights stated in the Agreement; and
(c) to HACKRATE's knowledge, the Client's authorised use of the unmodified mVDP Form does not infringe a Third Party's Intellectual Property Rights.
8.2 The Client warrants that:
(a) it has authority to enter into and perform the Agreement for itself and any Affiliate using the Services;
(b) it has obtained and will maintain all licences, permissions, consents and other authorisations required for the Program, Environment and HACKRATE's performance (Authorisations), and will provide reasonable evidence on request;
(c) Client Materials and instructions, and HACKRATE's authorised use of them, do not infringe third-party rights;
(d) the Program and its instructions comply with applicable law and do not authorise unlawful access, interception, monitoring, disruption, data use or activity against Third-Party Systems; and
(e) it will not represent that the mVDP Form or Services guarantee discovery or remediation of every Vulnerability, prevention of incidents, or compliance with a law or standard.
8.3 Findings and mVDP Reports depend on information supplied by Users and the Client and on technical conditions at the time. HACKRATE will use reasonable skill and care for included triage and validation but does not warrant that every report is complete, accurate, reproducible, free from error, or suitable as the sole basis for a business, legal, compliance or remediation decision.
8.4 The Client acknowledges that:
(a) except for express warranties in the Agreement, the mVDP Form is provided on an as is and as available basis and may be affected by maintenance, internet limitations and third-party infrastructure;
(b) Users are independent reporters, not employees, agents or subcontractors of HACKRATE;
(c) unless identity verification is expressly included in the Order Form, HACKRATE does not verify or guarantee a User's identity, competence, motive, location or authority;
(d) HACKRATE may provide similar services to third parties and develop competing or similar products, subject to confidentiality obligations; and
(e) no vulnerability disclosure program can eliminate cybersecurity risk or replace secure development, vulnerability management, penetration testing where required, monitoring, access control, incident response, backups or other appropriate controls.
8.5 The Client is responsible for evaluating, prioritising, remediating and testing Findings. HACKRATE is not responsible for loss caused by the Client's failure or delay in remediation, except to the extent directly caused by HACKRATE's breach and subject to Clause 13.
9. Indemnity
9.1 The Client shall indemnify HACKRATE and its officers, employees and agents against a third-party claim, and reasonable directly related costs, to the extent the claim arises from:
(a) Client Materials, the Environment, Program rules or instructions infringing a third party's rights;
(b) the Client lacking authority to permit the Program, reporting or validation activity; or
(c) the Client's unlawful or material breach of the Agreement.
9.2 HACKRATE shall indemnify the Client against a third-party claim that the unmodified mVDP Form, when used as permitted by the Agreement, infringes that third party's Intellectual Property Rights, except to the extent the claim arises from Client Materials, Finding Materials, unauthorised modifications, combinations not supplied or approved by HACKRATE, or continued use after HACKRATE provides a non-infringing alternative.
9.3 An indemnity under this Clause is conditional on the indemnified Party:
(a) promptly notifying the indemnifying Party, provided that delay relieves the indemnifying Party only to the extent materially prejudiced;
(b) not admitting liability or settling without prior written consent, not to be unreasonably withheld or delayed;
(c) giving the indemnifying Party reasonable control of the defence and settlement; and
(d) providing reasonable cooperation at the indemnifying Party's cost.
9.4 No settlement may impose an admission, payment or non-monetary obligation on the indemnified Party without its prior written consent.
10. Compliance
10.1 Each Party shall comply with laws applicable to its performance, including Data Protection Legislation, anti-bribery, anti-corruption, sanctions and Export Control Laws.
10.2 Neither Party shall use the Services to facilitate unlawful activity, evade sanctions, obtain unauthorised access or interfere with third-party systems or communications.
10.3 If a change in law materially affects the Services, the Parties shall cooperate in good faith to agree necessary changes. HACKRATE may modify affected Services where reasonably necessary for compliance, security or continued operation, or terminate affected Services on reasonable notice if lawful provision becomes impracticable. Prepaid fees for Services not provided after such a termination shall be handled under the Order Form and Clause 14.
10.4 HACKRATE may perform reasonable Client, representative and payment verification and may suspend or refuse Services where necessary to meet legal or risk-management obligations.
11. Confidentiality
11.1 Each receiving Party shall:
(a) keep the disclosing Party's Confidential Information confidential;
(b) protect it using at least reasonable care and no less care than it uses for its own similar information;
(c) use it only to perform or exercise rights under the Agreement; and
(d) disclose it only as permitted by this Clause.
11.2 Confidential Information may be disclosed to employees, Affiliates, auditors, professional advisers, insurers, financing sources, agents and subcontractors who need it for the Agreement and are bound by confidentiality obligations, and to authorities or courts where legally required.
11.3 Where legally permitted, a Party required to disclose Confidential Information shall give reasonable advance notice and cooperate with lawful efforts to limit the disclosure.
11.4 Confidential Information does not include information that the recipient can demonstrate:
(a) is lawfully public without breach;
(b) was lawfully known without restriction before disclosure;
(c) is lawfully received from a third party without confidentiality duty; or
(d) was independently developed without use of the Confidential Information.
11.5 The confidentiality obligations continue for five years after termination, except that trade secrets, credentials, personal data, non-public Findings and security-sensitive information remain protected for as long as they remain confidential or as required by law.
12. Intellectual Property Rights
12.1 HACKRATE and its licensors retain all Intellectual Property Rights in the mVDP Form, Services, documentation, templates, methods, software and improvements. No rights are transferred except the limited right to use the Services under the Agreement.
12.2 The Client and its licensors retain all Intellectual Property Rights in Client Materials and the Environment.
12.3 The Client grants HACKRATE a non-exclusive, worldwide, royalty-free licence during the Term, and afterwards only as needed for legal retention, backup and dispute handling, to host, copy, transmit, display, modify and otherwise use Client Materials solely to provide, secure and support the Services and comply with law.
12.4 Ownership of Finding Materials created by a User is governed by the mVDP User Terms of Use. Under those terms, the User retains ownership and grants HACKRATE and the Client a broad licence to use the materials for triage, validation, remediation, security, audit, compliance, evidence and related internal purposes. The Client shall not publicly identify a User or publish Finding Materials without the authorisation required by the Program and applicable law.
12.5 HACKRATE may generate and use Aggregate Data for operating, securing, analysing, benchmarking and improving the mVDP Form and Services and producing non-identifying statistics. HACKRATE shall not sell Client-identifiable or User-identifiable data under this Clause and shall not use Aggregate Data to publicly identify or rank the Client without prior written consent.
12.6 Feedback voluntarily provided by the Client may be used by HACKRATE without restriction or payment, provided it does not include the Client's Confidential Information or personal data and does not publicly identify the Client without consent.
13. Limits on Liability
13.1 Subject to Clause 13.8, HACKRATE's aggregate liability to the Client for damage to tangible property directly caused by HACKRATE, excluding loss or corruption of data, shall not exceed the fees paid or payable under the affected Order Form for the six months immediately preceding the event.
13.2 Subject to Clauses 13.4 to 13.8, HACKRATE's aggregate liability to the Client arising out of or in connection with an Order Form, whether in contract, tort, negligence, statutory duty, indemnity or otherwise, shall not exceed the fees paid or payable under that Order Form for the six months immediately preceding the event giving rise to the claim. If the event occurs during the first six months, the cap is the fees paid or payable for that initial six-month period.
13.3 A Party seeking recovery shall notify the other Party without undue delay after becoming aware of a matter reasonably likely to give rise to a claim and shall use reasonable efforts to mitigate avoidable loss. Delay reduces recovery only to the extent it materially prejudices the other Party.
13.4 The cap in Clause 13.2 does not apply to HACKRATE's indemnity under Clause 9.2 for third-party Intellectual Property Rights claims, but any separate cap stated in the Order Form applies.
13.5 Neither Party is liable to the extent a claim results from a product or service supplied directly by a Third Party to the claimant, or from the claimant's acts, omissions, unlawful instructions or failure to mitigate.
13.6 HACKRATE is not liable to the extent a claim results from unauthorised modification of the mVDP Form, use contrary to documentation or the Agreement, or combination with unapproved systems, code or materials.
13.7 Subject to Clause 13.8, neither Party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business, goodwill, opportunity or data, whether direct or indirect. This exclusion does not prevent recovery of amounts properly payable to a third party under an indemnity or reasonable costs of restoring data from available backups where directly caused by a Party's breach.
13.8 Nothing in the Agreement excludes or limits liability for:
(a) death or personal injury caused by negligence;
(b) fraud, fraudulent misrepresentation or wilful misconduct;
(c) breach of confidentiality or unlawful processing of personal data to the extent liability cannot lawfully be limited;
(d) amounts owed under payment obligations; or
(e) any liability that cannot lawfully be excluded or limited.
14. Payments and Invoicing
14.1 The Client shall pay HACKRATE Fees in accordance with the Order Form. Unless the Order Form states otherwise, fees are payable in advance and invoices are due within the period stated on the invoice.
14.2 Subscription renewal, notice periods and price changes are governed by the Order Form. Automatic renewal applies only if expressly stated there. HACKRATE shall give any contractually required renewal or price-change notice.
14.3 Fees are non-refundable except as expressly stated in the Order Form, where HACKRATE terminates without cause before providing prepaid Services, or where required by applicable law. Termination does not affect accrued fees.
14.4 Fees exclude VAT and similar taxes, which shall be added where applicable. Each Party is responsible for taxes imposed on its income, personnel or operations.
14.5 If an undisputed amount is overdue, HACKRATE may charge lawful default interest and, after reasonable notice, suspend affected Services until payment. The Client shall raise a good-faith invoice dispute promptly and pay undisputed amounts on time.
15. Termination
15.1 Either Party may terminate an Agreement immediately by written notice if the other Party:
(a) commits a material breach that cannot be remedied; or
(b) fails to remedy a remediable material breach within 30 days after receiving written notice describing the breach and required remedy.
15.2 HACKRATE may suspend or terminate the Program immediately where continued operation creates a material security, safety or legal risk, or where the Client lacks authority over the Environment. HACKRATE will notify the Client as soon as reasonably practicable.
15.3 Termination does not affect accrued rights, liabilities or clauses intended to survive, including confidentiality, intellectual property, data protection, liability, payment and dispute resolution.
15.4 On termination, the Client's access and the mVDP Form will end, subject to a reasonable export or transition period if stated in the Order Form. HACKRATE may retain data as required by the Agreement, Privacy Notice, DPA, backup cycles and applicable law.
16. Data Protection
16.1 Each Party shall comply with Data Protection Legislation for its processing under the Agreement.
16.2 The Parties' data-protection roles depend on the specific processing activity and are not automatically the same for every activity:
(a) each Party acts as an independent controller where it determines its own purposes and means, including the Client's decisions about the Program, Environment, remediation and legal response, and HACKRATE's account administration, service security, fraud prevention, legal compliance and service improvement;
(b) to the extent HACKRATE processes personal data solely on the Client's documented instructions, HACKRATE acts as processor and the Parties shall enter into or apply a data processing agreement before that processing; and
(c) if a specific activity makes the Parties joint controllers, they shall put an Article 26 GDPR arrangement in place before commencing it and make its essence available to affected data subjects.
16.3 The Client shall identify and document a lawful basis for personal data it instructs HACKRATE to collect or disclose, including contact data submitted by Users and personal data incidentally contained in Finding Materials. The Client shall design Program scope and instructions to minimise exposure of personal data.
16.4 HACKRATE shall provide privacy information concerning its processing through the Hackrate Privacy Notice. The Client shall provide any additional notice required for its own processing and shall not rely on HACKRATE's notice to cover undisclosed Client purposes.
16.5 Each Party shall implement appropriate technical and organisational measures, restrict access on a need-to-know basis, and ensure authorised personnel are bound by confidentiality.
16.6 The Parties shall cooperate without undue delay on data-subject requests, regulatory inquiries and personal data breaches that materially affect shared processing. The Party receiving a request remains responsible for responding for processing for which it is controller; HACKRATE will provide reasonable assistance where required by the DPA or law.
16.7 Neither Party shall use User contact information or Finding Materials for unrelated marketing, profiling or surveillance. The Client may contact a User about the relevant Finding where permitted by the Program, Privacy Notice and applicable law.
16.8 International transfers shall use a lawful transfer mechanism, including an adequacy decision, the European Commission's then-current standard contractual clauses or another safeguard permitted by Data Protection Legislation.
16.9 If a DPA applies, its provisions on subprocessors, security, assistance, audit, deletion and international transfers prevail for processor activities.
17. Variations
17.1 Except for updates permitted by Clause 2.4, a variation is effective only if recorded in writing and accepted by authorised representatives of both Parties. A valid electronic signature or clear electronic acceptance satisfies the writing requirement.
18. Force Majeure
18.1 A Party is not liable for delay or failure caused by Force Majeure, provided it promptly notifies the other Party, uses reasonable efforts to mitigate the impact and resumes performance when reasonably possible.
18.2 If Force Majeure materially prevents the affected Services for 30 consecutive days, either Party may terminate those affected Services by written notice without penalty, except for amounts accrued before termination.
19. Assignment
19.1 Neither Party may assign the Agreement without the other Party's prior written consent, not to be unreasonably withheld or delayed, except that either Party may assign it to an Affiliate or in connection with a merger, reorganisation or sale of substantially all relevant assets, provided the assignee assumes the obligations and does not create a material confidentiality risk.
19.2 HACKRATE may use subcontractors to provide the Services and remains responsible for their performance to the same extent as for its own obligations, subject to the DPA for subprocessors.
20. Waiver
20.1 A delay or failure to exercise a right is not a waiver. A waiver is effective only if in writing and applies only to the specific circumstance for which it is given.
21. Severance
21.1 If a provision is invalid, unlawful or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable or, if that is not possible, treated as deleted. The remaining provisions continue in effect.
21.2 The Parties shall in good faith seek a lawful replacement that most closely reflects the original commercial purpose.
22. No Partnership
22.1 Nothing in the Agreement creates a partnership, joint venture, employment, fiduciary or agency relationship between the Parties, or authorises either Party to bind the other.
23. Notices
23.1 Formal notices under the Agreement must be in writing and sent by personal delivery, tracked post or email to the addresses stated in the Order Form or later notified under this Clause. Routine operational communications may be sent through the Platform or agreed service channels.
23.2 A notice is deemed received:
(a) on delivery, if delivered personally;
(b) two business days after dispatch, if sent by tracked domestic post, or five business days if sent internationally; and
(c) when transmitted, if sent by email during the recipient's normal business hours and no delivery-failure message is received, otherwise at the start of the next business day.
23.3 A change of notice details is effective on the date specified in the change notice or, if later, two business days after receipt. This Clause 23.3 refers to the details in Clause 23.1.
24. Law, Dispute Resolution and Language
24.1 The Agreement and any non-contractual obligations arising from it are governed by the substantive laws of Hungary, excluding its conflict-of-laws rules.
24.2 In the event of any dispute arising from or in connection with the Agreement, including its breach, termination, validity or interpretation, the Parties exclude state-court proceedings and submit the dispute to the exclusive and final decision of the Permanent Arbitration Court attached to the Hungarian Chamber of Commerce and Industry (Commercial Arbitration Court Budapest). The Arbitration Court shall proceed under its Rules of Proceedings in force when the arbitration begins, excluding the Sub-Rules of Expedited Proceedings unless the Parties agree otherwise. The number of arbitrators shall be three, the seat of arbitration shall be Budapest, Hungary, and the language shall be English.
This does not prevent either Party from seeking urgent interim or protective relief from a competent court, or from enforcing an arbitral award.
24.3 If the Agreement is made available in more than one language, the English version prevails to the extent of any inconsistency, unless mandatory law requires otherwise.
Hackrate
Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.
US Patent Applied for HackGATE #63/645,845
Products
From the Blog
-
Hackrate Ranked 1st in Hungary and 22nd Globally at Hack The Box’s Global Cyber Skills Benchmark 2026
May 29 • 13 min read
-
Press release: Hackrate becomes Hungary’s first CVE Numbering Authority
Jan 13 • 5 min read ★
-
Let 2026 be the year bug bounty becomes part of how you build and operate
Jan 05 • 4 min read