Client PortalOngoing Partnership

Defensive Security.
Built to Hold.

My team of 14 cybersecurity professionals offer SIEM management, intrusion detection and prevention, endpoint defense, and 24/7 monitoring, delivered by senior practitioners who treat your infrastructure like their own. Defense that actually works protects your privacy and the privacy of those who matter to you.

Track Record

How We've Actually Been Paid

This isn't a menu of things we'd like to sell you. It's the model we've used, engagement after engagement, to get paid for finding vulnerabilities and writing technical analysis of websites and applications. Two payments, in this order: a simple fee to open the engagement, and a bounty for what we actually find.

$50 – $200

Step 1: Service Agreement

Opens a 3-Month Contract

A flat, simple fee for signing terms and laying out scope, what's in bounds, what's off-limits, and what "done" looks like. This part is never the moneymaker; it just gets the clock started. The fee scales with the size of the service, $50 for a narrow scope, up to $200 for a broad one. The contract itself runs three months, and what we earn by the end of it depends on deliverables, not on this initial number.

Variable

Step 2: The Bug Bounty

Where the Real Pay Comes From

Once the agreement is signed, we hunt. We find vulnerabilities, build a working proof of concept for each one, and hand back a remediation plan alongside it, every finding delivered with its CWE identifier and, where one exists, its CVE. This is the part of the contract with flexible, deliverable-based pay: the more real, exploitable findings, the more the engagement earns.

Ready to Start

Need a scoped engagement for your business, on this same model?

Become a Client →

The Team

One Playbook, Divided Work

As a team, we work from an in-house playbook built out of prior engagements, so no one starts from zero. We strategize together and break the scope into tasks and responsibilities, so anyone with the drive, the passion, and the skill can take part in the hunt, not just the most senior person in the room. Unless we've found something worth escalating sooner, we report our audit findings to the client once every two weeks: what's protected, and against what kind of attack. The moment we do find something, we communicate it to the business right away, sharing enough detail to establish the finding and set expectations for payment before the bounty is settled.

Join the Hunt

Have the skills and the drive? There's a seat on the playbook for you.

Become a Bounty Hunter →

Bounty Payout

Priced by Severity

Once a bounty is paid, we hand over the finer detail: the CWE and, where applicable, the CVE, each with its Core Structural Components, its place in the Abstraction Hierarchy (Pillar, Class, Base, or Variant), and a CVSS score, alongside a remediation strategy and a retest to confirm the fix holds. These are the standard bounty rates:

SeverityPayoutWhat It Usually Means
Low $50 Limited impact, hard to exploit, or requires unusual conditions
Medium $100 Real exposure, but bounded by scope, privilege, or reach
High $500 Direct path to sensitive data or unauthorized account access
Critical / Zero-Day $1,000 Full compromise, or a flaw with no existing public fix

A Note on Rates

These are the standard numbers, not the only numbers. Rates flex with the needs of the business and with standing: established partners who've worked with Fortuna Security before earn better terms than a first engagement.

Track Record

Vulnerabilities We've Found

A sample of findings from past engagements. Every CWE entry shares the same core structure, an ID, a name, a description, and relationships to neighboring weaknesses, and sits somewhere in the Abstraction Hierarchy running from broad Pillar down to specific Variant. CVSS scores below are illustrative ranges for this class of finding; private engagement findings aren't assigned a public CVE unless a client chooses to disclose.

CWE-79 · Base

Cross-Site Scripting (XSS)

CVSS ~6.1 · Medium

Identified unsanitized user input reflected back into the page, demonstrating the potential for malicious script execution in a victim's browser.

CWE-200 · Base

Sensitive Data Exposure

CVSS ~7.5 · High

Found the /auth/me endpoint returning internal authentication fields, including password-reset and email-verification tokens, enabling unauthorized access to security-sensitive account data.

CWE-602 · Base

Client-Side Enforcement Flaw

CVSS ~5.4 · Medium

Bypassed frontend access restrictions using nothing more than browser developer tools, since the real enforcement never existed server-side.

CWE-521 · Base

Weak Password Policy

CVSS ~5.3 · Medium

Demonstrated that the application accepted 8-character passwords with no complexity or common-password checks, lowering the bar for credential-stuffing attacks.

CWE-287 · Class

MFA Authentication Bypass

CVSS ~8.1 · High

Demonstrated that accounts with MFA enabled could still be accessed with valid credentials alone, without ever completing the required second factor.

CWE-862 · Base

Missing Authorization

CVSS ~8.6 · High

Identified an endpoint that performed a privileged action for any authenticated user, with no check confirming the requester actually held the role or permission required to use it.

Before We Start

Every Engagement Starts With Written Consent

Nothing gets touched without a signed agreement first. Before any testing begins, we put the same document in front of every client: a written authorization that spells out exactly what we're allowed to test, what we're not, and what happens if anything goes sideways. It's not glamorous, but it's the reason clients can trust us with production systems in the first place.

In Plain Terms

If it isn't listed in the signed scope, we don't touch it. If a deliverable or add-on isn't initialed, we don't bill for it. If you tell us to stop, we stop, immediately, no exceptions.

1

Scope, In Writing

Every system, domain, and IP address we're allowed to test is listed by name before we begin. Anything not on that list is off-limits, full stop.

2

What We Won't Do

No denial-of-service, no physical intrusion, no destructive testing, no exploiting past a proof-of-concept, unless a separate written amendment says otherwise.

3

Findings, Reported Fast

Anything we discover gets reported through a secure channel within 12 hours, and testing halts immediately if a client's authorized contact asks us to stop.

4

Your Data, Protected

Anything sensitive we encounter is encrypted, shared only with the contacts you name, and destroyed once the engagement closes, unless you ask us to keep it.

5

Legal Footing, Both Ways

Testing stays within the CFAA and applicable state law. Every deliverable and add-on is priced and initialed in writing before work starts, and any dispute goes to good-faith negotiation before anything else.

6

An Emergency Stop, Always On

A named contact can end testing instantly for any reason. When that happens, we send a full written status report within 24 hours.

Long-Term Standing

Worked with us before, or want to grow past a single 3-month contract? Established partners earn better bounty rates.

Become a Partner →

The Defensive Stack

After offensive measure we can Monitor & Manage

  • SIEM (Security Information & Event Management): Collect and correlate logs from across your entire environment, giving you a single place to monitor activity, investigate alerts, and identify threats before they become incidents.
  • IDS (Intrusion Detection System): Monitor your network traffic for known attack signatures and suspicious behavior, alerting us the moment malicious activity is detected.
  • IPS (Intrusion Prevention System): Stops malicious traffic in real time by automatically blocking attacks before they can reach your systems.
  • EDR (Endpoint Detection & Response): Provides deep visibility into every endpoint, detects malicious processes, automatically isolates compromised devices, and preserves forensic evidence for investigation.
  • Log Management & Retention: Securely stores and organizes system logs, making it possible to investigate security incidents days, weeks, or even months after they occur while maintaining a complete audit trail.

Action

A team of 14 and growing manage these systems. Collectively trading shifts and using industry recognized systems to alert us alongside newer, more powerful models. With these tools and our expertise, we swarm like ants on a grasshopper in the winter when a threat arrives. Our tuning process focuses on cutting threats early, so your team's attention continue focusing on your pleasing your clients, while we focus on guarding them.

What We Offer

  • Full visibility across your logs, network, and endpoints
  • Rules and alerts tuned to your environment
  • A documented, repeatable process your team can maintain
  • Training so your staff understands the reasoning behind every alert
  • A direct line to a senior analyst.

The Defensive
Stack

Bug bounty work finds and fixes what's broken today. For clients who want more than that, an ongoing partnership covering SIEM, IDS/IPS, endpoint defense, and 24/7 monitoring, we build the same trust and consent-first process into a standing relationship. We start with a conversation about what you actually have and what you're trying to protect.

Book a Scoping Call