How We Actually Work

Every engagement runs on a written agreement, a team playbook, and a two-payment model: a flat fee to open the contract, and a bounty for what we confirm. It's the same model whether you're a business hiring us, a partner returning for another round, or a student earning a seat on the team.

Service Agreement, Scoped by Size

A flat fee opens the engagement and sets its length: $50 for a Narrow Scope on a 3-month term, $100 or $200 for a Standard or Broad Scope on 6 months. Everything tested is written into the agreement before we touch a system.

Bug Bounty, Priced by Severity

Once the agreement is signed, we hunt. Confirmed findings are billed separately, from $50 for a low-severity issue up to $1,000 for a critical or zero-day, each delivered with a working proof of concept and a remediation plan.

Findings, With the Full Detail

Every confirmed vulnerability comes with its CWE identifier, CVSS score, and place in the Abstraction Hierarchy, alongside the remediation strategy and a retest to confirm the fix actually holds.

Written Consent, Every Time

Nothing gets touched without a signed scope, and testing halts immediately if you ask. Sensitive data we encounter is encrypted, shared only with your named contacts, and destroyed when the engagement closes.

Join the Team as a Bounty Hunter

The hunt runs on an in-house playbook, with tasks broken out so anyone with the skill and the drive can take part, not just the most senior person in the room. Vetted students earn a share of the bounty they help confirm.

The Defensive Stack

For clients who want more than a fixed-scope hunt: an ongoing, scoped-by-consultation partnership covering SIEM, IDS/IPS, endpoint defense, and 24/7 monitoring, built on the same written-consent process as everything else we do.

Established Partners, Better Rates

The pricing above is the standard. Clients who've worked with us before, or who want a longer-term relationship past a single 3 to 6-month contract, earn better bounty rates on every return engagement.

3–6moContract Terms
$50–$1KBounty Range
14 DaysReporting Cycle
12hFinding Escalation

Chat with us today.

What do you want to protect?

What happens after you submit

  1. Initial review of your environment description by a senior engineer
  2. 15 to 30 minute scoping call to define objectives, constraints, and timeline
  3. Tailored engagement proposal with defined scope, deliverables, and pricing
  4. Written authorization agreement executed before any testing begins

Discord

fortuna_security

Available weekdays 9am to 6pm EST. Use emergency line for active incidents.

Email

fortunasecurity@proton.me

All emails are responded to within one business day. For active incidents use the incident page.

Response Time

Within 1 Business Day

Scoping calls are typically scheduled within 48 hours of form submission. Emergency intake is immediate.

Before You Book

Frequently Asked Questions