24/7
Bug bounty coverage that finds bugs before hackers do

Tumar.One puts a global network of vetted researchers on your perimeter, continuously. You ship - they hunt. Pay only for confirmed, exploitable bugs.

Become researcher
SECURED BY OUR HUNTERS
logo-1
logo-2
logo-3
logo-4
logo-5
logo-6
logo-7
logo-8
logo-9
logo-10
logo-11
logo-12
logo-13
LIVE, RIGHT NOW

What our hunters are finding while you read this page.

A real-time stream of triaged vulnerabilities - the issues an attacker would have reached first

tumar://stream/reports.liveSTREAMING
05:57:51MED
webtotem.kz CSRF on PIN change endpoint — missing SameSite + no token
05:51:21MED
kaspi.kz Account takeover via password-reset token reuse window of 11min
05:52:08MED
webtotem.kz Rate-limit bypass on OTP endpoint via X-Forwarded-For rotation
05:52:55CRIT
astana.kz JWT alg=none accepted by mobile API gateway — full session hijack
05:53:42HIGH
kcell.kz Stored XSS in merchant onboarding flow (step-3) — reflected via company_name
05:54:29HIGH
payme.kz CSRF on PIN change endpoint — missing SameSite + no token
05:55:16HIGH
tbcbank.kz XXE in invoice import (.xlsx → xml) — read of /etc/passwd
05:56:03HIGH
egov.kz Open redirect on SSO callback — bypass of allowlist via path traversal
05:56:50MED
mbank.kz Race condition in coupon redemption — double-spend window ~140ms
05:57:37CRIT
kaspi.kz IDOR in /api/v2/wallet/transfer — auth bypass via tampered user_id
$
THE PLATFORM

Launch fast
Find faster

Real findings from week one - and they never stop

01 / scope
1week
Private program

Signed contract to first researcher onboarded

We set scope, severity scoring, payouts

02 / report
3days
First finding

Median time to your first triaged vulnerability

Validated, reproducible, with a working exploit

03 / scale
1month
Public program

Open the gates to the full researchers network

Flip to public for continuous coverage from 800+ researchers worldwide

FOR COMPANIES

From 40 to 100+ vulnerabilities in the first year

What internal teams miss, our researchers find. Red-team depth, continuous output - pay only for results

Severity mix · last 12 mo.

Heavy on what matters Light on noise

We filter out false positives before they reach you - so every report you get actually moves risk

  • High
    71%
  • Medium
    23%
  • Low
    6%
Global coverage · 24/7

Researchers in 38 countries Eyes on every timezone

FOR RESEARCHERS

Turn the hunt
into a paycheck

We make it simple to pick your targets, send clean reports, and get paid

Top researchers of all time
#00
YO@you

Hunt legally on the biggest banks, telcos and gov platforms in the region and beyond

  • Programs from Kaspi, eGov, MBank, Kcell and more
  • Fresh attack surface - web, mobile and more
  • Join real community - hundreds of researchers worldwide
  • Top 10 land on the wall of fame each season.
Avg payout last 30 days: $1,840Start research
ACTIVE PROGRAMS

Public programs open now

Dive into one of the largest live bug bounty rosters in Central Asia

See all 0 programs

Ship faster. Sleep better.
Pay only for what matters.

Most teams break even on their bug bounty program inside the first quarter. Talk to us about scoping a private launch this month.

Start Research
$ tumar contact --type=enterprise
> routing to security-success team.
> expected first reply: under 4h
$ tumar quote --vertical=fintech
> 87 programs in this vertical · median bounty $2.4k