PUBLIC OFFER
PUBLIC OFFER №KHS/23/30
Astana city 13.11.2023
KazHackStan LLP (BIN 120540005677), hereinafter referred to as the “Operator”, represented by Director Satiyev O.S., acting on the basis of the Charter, expresses its intention to conclude an Agreement on the provision of services to provide access to a web resource located in the Internet at the address: https://tumar.one/ (hereinafter referred to as the Agreement) and is an official offer to provide access to the TumarOne Platform.
Terms and Definitions
- “Operator” is a legal entity that owns the Platform, and which, independently and at its own discretion, determines the procedure for using the Platform on the Internet, including the procedure for posting information on the Platform. All exclusive property rights to the Platform belong to the Operator.
- “Platform” is a web resource located on the Internet at https://tumar.one/. Platform is a reward program for vulnerabilities found in information systems and resources.
- Offer in the text of this Agreement – is an offer published on the Operator's Website: https://tumar.one/public-offer is the Operator's Offer to all researchers in accordance with paragraph 5 of Article 395 of the Civil Code of the Republic of Kazakhstan.
- Acceptance – in accordance with Article 396 of the Civil Code of the Republic of Kazakhstan, the response of the potential User, to whom this Offer is addressed, on its full and unconditional acceptance and consent to the terms of this Agreement by performing the actions specified in section 1 of this Agreement. Acceptance of the Offer entails the conclusion of an Agreement between the Operator and the User. By performing actions on the Acceptance of this Offer, the User confirms his legal status and capacity, the absence of any restrictions, including those determined by the current legislation on the conclusion of this Agreement, as well as his legal right to enter into contractual relations with the Operator.
- User (researcher) is a fully capable individual who has expressed acceptance of the Offer in accordance with clause 1.2. of the Agreement and registered on the Platform, who carry out work on the search for vulnerabilities in accordance with the terms of the Agreement, acting on their own behalf.
- Registration is filling out the registration form by the User located on the Platform by specifying the necessary information.
- Registration Form is a form located on the Platform, which the User must fill out in order to be able to use the website in full.
- Personal Account is a personal section of the User in the Platform, protected by authorization parameters using a login and password, providing the functions of the Platform in accordance with the Regulations, available to the User after authorization on the Operator's Website.
- Regulations is a document that defines the procedure for working in the Platform in accordance with Appendix No. 1 to this Agreement, which is an integral part thereof.
- Verification is the process of confirming the identity of the Researcher in order to pay for confirmed vulnerabilities.
- Client is an organization (the owner of the relevant information systems) that posts a Program on the Platform to search for vulnerabilities in its web services and applications, and that decides on accepting reports and the amount of remuneration.
- Program is an initiative to identify vulnerabilities in the Client's web services and applications, as well as to determine ways to implement unacceptable events, which is posted on the relevant page of the Platform.
1. General Provisions
- 1.1. The text of the Agreement is a public offer. Acceptance of the offer means registration on the Platform at the following address https://tumar.one/public-offer and continuation of its use. By accepting this Public Offer Agreement, the User guarantees his legal status and capacity, as well as his legal right to enter into contractual relations with KazHackStan LLP. Before using the Platform, the User must carefully read the terms of its use contained in this Agreement. The start of using the Platform means the proper conclusion of this Agreement and the User's full consent to all its terms.
- 1.2. The User's acceptance upon conclusion of the Agreement is the expressed consent to its terms and a set of the following actions of the User during registration in the Operator's Platform:
- 1.2.1. Entering the registration data according to the registration form.
- 1.2.2. familiarization, agreement and acceptance of the terms of the Offer.
- 1.2.3. performance by the User of the actions specified in this Agreement, indicating full and unconditional acceptance of all its terms, as well as by ticking the box "I agree with the terms of service" on the Operator's website during registration.
2. Subject of the Agreement
- 2.1. The Operator provides the User with access to the Platform free of charge, which hosts the programs of the Operator's Clients, in which the User searches for vulnerabilities. In turn, the Operator pays a reward to the User for the vulnerabilities found in accordance with the Agreement and the provisions of each individual program.
- 2.2. The User searches for vulnerabilities of programs placed on the Platform in the manner specified in the Agreement.
3. Rights and Obligations of the Parties
- 3.1. The User has the right to:
- 3.1.1. Use the Platform except for the time of preventive, technical and emergency maintenance.
- 3.1.2. Make and send proposals to the Operator to improve the functionality of the Platform or in writing to the Operator's e-mail specified on the Operator's website.
- 3.1.3. Send a request to the Operator's technical support service regarding the spread of data on vulnerabilities.
- 3.1.4. Take part in promotions, events, and receive bonuses.
- 3.1.5. Receive remuneration from the Operator.
- 3.2. The User undertakes:
- 3.2.1. Comply with the terms of this Agreement.
- 3.2.2. Use the Platform in accordance with its purpose, as well as in accordance with the provisions of the Agreement, the Regulations and other documents and information published on the Operator's Website and in the Platform.
- 3.2.3. Use valid identity and contact details on the Platform.
- 3.2.4. Monitor notifications on the Platform and email specified when registering on the Platform. The User has exactly 2 weeks from the appearance of the application to accept the retest, after the expiration of the deadline, the application for retesting will be automatically rejected.
- 3.2.5. Not to impersonate another person on the Platform.
- 3.2.6. Not to publish in the media, the Internet, social networks data, information about the Platform without the official written consent of the Operator.
- 3.2.7. Not to allow deceptive, illegal or unethical actions that may cause property or reputational damage to the Operator.
- 3.2.8. Observe and not violate the copyright and intellectual property rights of the Operator.
- 3.2.9. Go through the verification process to receive payment for confirmed vulnerabilities.
- 3.2.10. Sign the Act of Work Performed / Services Rendered provided by the Operator and return it to the Operator.
- 3.2.11. Register on the platform for signing the EDS (Act of Work Performed / Services Rendered) and sign the EDS (Act of Work Performed / Services Rendered) if the User is a citizen or resident of the Republic of Kazakhstan. The Platform is determined by the Operator independently.
- 3.2.12. If the User is not a citizen and resident of the Republic of Kazakhstan, in this case, the User undertakes to provide the Operator with a scanned copy of the Act of Work Performed / Services Rendered in accordance with the form established and provided by the Operator. This scanned copy must be provided before the exchange of originals between the parties.
- 3.3. The User is prohibited from: using any means of "deep linking", collecting information on pages, robots, "spiders" or other automatic devices, programs, algorithms or methods, as well as any similar or equivalent manual processes to access, acquire, copy or track any part of the System and its contents, attempt to circumvent technical limitations in the System, perform any actions aimed at restoring, studying, copying of the source code (source code) of the Platform, reverse engineer, disassemble or in any other way attempt to extract the source code of the System, copy the graphical interface of the System, conduct testing, conduct performance testing, penetration testing, including with the help/participation of third parties, use the Platform in any illegal way, reproduce or circumvent the navigational structure or presentation of the Platform or its contents in order to obtaining or attempting to obtain any materials, documents or information by any means that have not been specifically provided by the Platform, allowing unauthorized access to the Platform by hacking, password "analysis" or any other illegal means, committing actions that pose a threat to the information security of the Platform and/or providing an opportunity for third parties to perform these actions, as well as committing actions falling under the Criminal Code of the Republic of Kazakhstan and the Code of the Republic of Kazakhstan on Administrative Offences.
- 3.4. If the User becomes aware of the facts of performing the actions provided for in clause 3.3. of this Agreement, the User is obliged to inform the Operator thereof and provide supporting materials (if necessary).
- 3.5. The Operator has the right to:
- 3.5.1. Modify or release a new version of the Platform at any time, including adding new features and functionality to the Platform or removing existing features and functionality from the Platform.
- 3.5.2. Carry out technical, preventive and emergency work on the Platform.
- 3.5.3. Unilaterally add new, change and cancel existing terms of use published on the Operator's Website and in the Platform, change the terms and rates of remuneration.
- 3.5.4. Make changes and additions to the terms and conditions of the Agreement unilaterally, cancel and publish a new edition by publishing on the Operator's Website and send a notification about this to the Personal Account.
- 3.5.5. Consider on an individual basis the request received from the User in accordance with the Agreement and, if necessary, conclude a separate agreement.
- 3.5.6. The Operator has the right to block the User's access to the Platform for violation of the terms of this Agreement by the User.
- 3.5.7. The Operator has the right to unilaterally block the User's access to the Platform and/or terminate the Agreement at any time without explanation or any notice.
- 3.5.8. Conduct promotions, events, provide bonuses, discounts and perform other actions related to the use of the System.
- 3.6. The Operator undertakes:
- 3.6.1. Ensure the performance of the Platform's functions 24/7, round-the-clock availability of the System, except for the time of preventive, technical and emergency maintenance.
- 3.6.2. Notify the User of changes and additions made to this Agreement.
- 3.6.3. Pay remuneration to the User in accordance with the terms of each individual program.
4. Financial Conditions and Payment Procedure
- 4.1. The Operator shall pay remuneration to the User in the manner, term and amount provided for in the Agreement, in a separate provision on the Operator's Client's program page.
- 4.2. The fee is paid after passing the verification stage, filling in the details for receiving payment and signing by the parties of the Act of work performed/services rendered in the form provided by the Operator.
- 4.3. Remuneration to the User may be paid with the help of a third party. When settling accounts with the User by a third party, the Operator's obligations to pay remuneration shall be deemed to have been fulfilled.
- 4.4. The remuneration paid to the User under this Agreement shall be paid minus the amount of taxes, fees, deductions, and other mandatory payments established by the current legislation of the Republic of Kazakhstan.
- 4.5. The Operator pays remuneration to the User on the basis of the specified bank details by the User on the Platform, accordingly, the Operator is not responsible for the correctness and accuracy of the details specified by the User. The Operator shall be deemed to have fulfilled its obligations to pay the reward for the confirmed vulnerabilities in full if the User has no claims and is notified within 14 (fourteen) calendar days from the date of payment of the remuneration by the Operator to the User.
5. Liability of the Parties
- 5.1. The User is responsible for:
- 5.1.1. violation, non-fulfillment or improper fulfillment of obligations under the Agreement, including for violation of the Regulations and requirements published on the Operator's Website and in the Platform.
- 5.1.2. for all actions performed on the Platform under the User's login.
- 5.1.3. inaccuracy of the information provided to the User during registration in the System.
- 5.1.4. for the distribution and use of vulnerabilities at their own discretion.
- 5.1.5. failure to read the notifications sent to the Personal Account and/or to the e-mail specified during registration with the User.
- 5.1.6. violation of the Operator's copyright and intellectual property rights.
- 5.1.7. violation of the terms of the Agreement, as well as the copyright and intellectual rights of the Operator, the User is obliged to pay the Operator a fixed amount of money equal to the value for the actual damage caused to the Operator out of court. The cost of the actual damage caused to the Operator as a result of the violation of the Agreement, as well as the copyright and intellectual property rights of the Operator, shall be assessed by the Operator. The Operator has the right to demand the execution of this clause in court in accordance with the terms of this Agreement.
- 5.1.8. dissemination of false information about the Operator and the Platform, committing deceptive, fraudulent, and other illegal actions falling under the Criminal Code of the Republic of Kazakhstan and the Code of Administrative Offenses of the Republic of Kazakhstan.
- 5.1.9. committing deceptive, illegal, or unethical actions that may cause/have caused property or reputational damage to the Operator, the Platform.
- 5.1.10. Violation of the Affiliate Program in accordance with the terms of the Partnership Agreement and the current legislation of the Republic of Kazakhstan.
- 5.2. Under no circumstances shall the Operator be responsible for:
- 5.2.1. unavailability of the Platform for reasons beyond the control of the Operator, if the unavailability of the Platform depends on the services of third parties provided to the Operator, including, but not limited to: colocation services, hosting, Rent a Rack, provision of VPN channels, in case of malfunction of communication channels or data centers, actions/omissions of third parties ensuring the provision of a communication channel, Internet, electricity, as well as information systems of participants, owners of payment systems, and in other circumstances beyond the control of the Operator and affecting the provision of the Platform under the Agreement.
- 5.2.2. untimely reading by the User of the notifications sent to the Personal Account and to the email specified by him during registration in the Platform.
- 5.2.3. inability of the User to use the Platform due to the User's non-compliance with the provisions of the Agreement, the Regulations, the User's lack of Internet connection, the functioning of the Platform on a faulty computer and other reasons beyond the control of the Operator.
- 5.2.4. loss of the User's data stored in the System in the event of force majeure (force majeure) determined in accordance with the legislation of the Republic of Kazakhstan and in the Agreement.
- 5.2.5. any damage, any loss of income, profit, information or savings, for direct or indirect losses, including lost profits of the User, related to the use or inability to use the Platform, including in the event of prior notification by the User of the possibility of such damage, or for any claim of a third party.
- 5.2.6. improper fulfillment of the terms of the Agreement, for any damage, any loss of income, profit, information or savings, for direct or indirect losses, including lost profits of the User, related to the use or inability to use the System, including in the event of prior notification by the User of the possibility of such damage, or under any claim of a third party in the case of free use of the Platform by the User, and the User is not entitled to impose any penalties (penalties, penalties), lawsuits, claims, etc. against the Operator.
- 5.2.7. Loss or inability to receive tax deductions or benefits from the User related to the services provided by the Operator.
- 5.3. The aggregate amount of the Operator's liability under the Agreement, including the amount of penalties (penalties, penalties) and/or reimbursable damages, for any claim or claim against the Operator/Contract or its performance, is limited 100 MCI and on the date on which the claim was brought.
- 5.4. The Parties shall be exempt from liability for partial or complete non-fulfillment of obligations under this Agreement, if this failure was the result of force majeure circumstances determined in accordance with the legislation of the Republic of Kazakhstan and in the Agreement.
- 5.5. The User shall indemnify and hold harmless the Operator from any and all claims, losses, damages, costs, lawsuits, debts, demands, fees, proceedings, causes of such proceedings, encumbrances, privileges, withholdings and expenses, including attorneys' fees, related to damage to or destruction of property, whether movable or personal, or otherwise, in the beneficial or absolute possession of the Operator/third parties, or under his/her responsibility, as a result of any act or omission of the User, whether or not the damage or loss is caused in whole or in part by any act, omission, fault, negligence or lack of due diligence on the part of the User, whether at common law or at law.
- 5.6. The User hereby releases the Operator from any and all liability to third parties, including for any and all claims, losses, damages, costs, lawsuits, debts, demands, fees, proceedings, causes of such proceedings, encumbrances, privileges, withholdings and expenses, including attorneys' fees, as well as those related to: (a) personal injury, including death; (b) loss suffered by a third party, including property damage, arising out of or related in whole or in part to the Contract.
6. Consent to the Collection, Processing and Storage of Personal Data; Confidentiality
- 6.1. The conditions for the collection, processing and storage of personal data are provided for in Appendix No. 2 to the Agreement.
- 6.2. Confidential information includes: trade secrets, information (data) about persons, objects, facts, events and/or processes, regardless of the form of their provision, directly or indirectly related to the Operator, its affiliates and/or customers, namely, including: on the signing of Contracts by the Operator and their execution, information on cooperation and projects of the Operator, information on the implementation of specific projects, information regarding the Operator's activities, any information about the methods, technologies, ideas, concepts, tools, components, technologies, recipes, computer programs used or developed by the Operator, information about the organizational aspects of the Operator, information about the accounting rules of both accounting and management, the provisions of the Operator's accounting policy, the charts of accounts used by it, the procedures for entering and storing accounting information, information about information systems, software products of the Operator and service personnel, as well as any information that has become known in connection with the provision of the Services.
- 6.3. Trade secret includes:
- 6.3.1. on the cost of production, profitability;
- 6.3.2. on the property of the Operator, its composition, value;
- 6.3.3. contracts (commercial, civil and other contracts with clients and third parties) and on the terms and conditions of all concluded contracts;
- 6.3.4. on the structure of production and technological processes;
- 6.3.5. on the organization of the Operator's security, communication and signal system;
- 6.3.6. internal documents of the Operator (all internal regulations of the organization);
- 6.3.7. personal and business correspondence with clients and third parties;
- 6.3.8. constituent documents of the Operator and clients, as well as third parties;
- 6.3.9. personal, contact information, phone numbers and information of the Customer's clients and partners.
- 6.4. The User undertakes not to disclose confidential information, information constituting a trade secret of the Operator, which will be entrusted to the User or become known as a result of the provision of the Services.
- 6.5. The User undertakes not to transfer to third parties and not to publicly disclose information constituting a trade secret of the Operator without his written consent.
- 6.6. The User undertakes to comply with the requirements of the Customer's instructions and regulations to ensure the safety of trade secrets.
- 6.7. In the event of an attempt by unauthorized persons to obtain trade secret/confidential information from me, the User undertakes to immediately inform the Customer.
- 6.8. The User undertakes to keep trade secrets/confidential information and personal data of the Operator's customers and/or partners.
- 6.9. The User undertakes not to use/transfer/disclose/copy confidential information for any purpose, regardless of the current relationship with the Customer.
7. Miscellaneous Provisions
- 7.1. The platform is provided on an “as is” basis. The Operator does not guarantee the compliance of the Platform or its components with the goals and expectations of the User.
- 7.2. The Parties shall be exempt from liability for non-fulfillment or improper fulfillment of the terms of this Agreement in the event of force majeure circumstances determined in accordance with the current legislation of the Republic of Kazakhstan, if they provide evidence that these circumstances prevented the fulfillment of obligations under this Agreement. Force majeure includes natural disasters (earthquakes, floods, mudflows, other natural disasters and catastrophes), fires, including server equipment on which the System and all data stored in the System are located, circumstances that cannot be foreseen or prevented (or can be foreseen, but cannot be prevented), as well as the issuance by state bodies of the Republic of Kazakhstan of acts prohibiting and/or preventing the Parties from fulfilling their obligations under this Agreement, other decisions of the supreme state bodies of the Republic of Kazakhstan (prohibition of import or export, currency restrictions, etc.), blockades, wars, military conflicts, strikes, revolutions, services of third parties provided to the Operator, including colocation, malfunctions of communication channels or data centers, action/inaction of third parties providing the provision of a communication channel, the Internet, electricity, as well as service participants of information systems, owners of digital signature holders, payment systems, circumstances beyond the control of the Operator and affecting the fulfillment of obligations by the Parties under the Agreement, etc. The deadlines for the performance of obligations under the Agreement shall be proportionately shifted to the duration of force majeure if they significantly affect the terms of the provision of services under the Agreement or that part thereof that is subject to performance after the occurrence of force majeure circumstances. From the moment of elimination of force majeure circumstances, this Agreement shall operate in the usual manner. In the event of force majeure: a) the User shall send a notice to the Operator within 5 calendar days; b) the Operator informs about it on its official Website; c) the Operator informs about it in the personal account of the Platform.
- 7.3. The Parties have agreed that all legal disputes will be considered in the Court at the location of the Operator.
- 7.4. The Agreement is valid throughout the territory of the Republic of Kazakhstan and another state of the User (if the User is a citizen of another state).
- 7.5. The Agreement comes into force from the moment of the User's Acceptance of the Offer and is valid indefinitely. Registration on the Platform in the manner provided for in this Agreement means the Participant's full and unconditional consent to all the terms of the Program, the Agreement and the Appendices.
- 7.6. This Agreement is published on the Operator's Website.
- 7.7. In the event that any part and terms of this Agreement are held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
Appendix No. 1
to the Public Offer Agreement for the provision of services for the provision of access to the web resource located on the Internet at: https://tumar.one/
REGULATIONS for work on the Platform
Rules and Guidelines
Getting Started
- Register and create a Researcher account.
- Immediately after registration, enable two-factor authentication (2FA) in your account settings.
- Complete the onboarding process - the system collects data about your experience, interests, and the time available for research.
- Complete identity verification - it is required to receive monetary rewards (see “User Verification”).
- Read these Rules and Guidelines in full before submitting any vulnerability reports.
After registration, you will receive instructions on filling in your personal and contact details, submitting reports, tracking rewards, and receiving payouts for confirmed vulnerabilities.
User Verification
To receive monetary rewards, all researchers must complete identity verification:
- Provide an electronic copy of your identity document (both sides).
- Provide a photo that clearly shows your face next to the document.
- After successful verification, the payout feature becomes available in your account.
The data provided during verification is processed to confirm your identity and make payouts in the manner and on the terms established by the Privacy Policy. The Operator does not transfer your data to third parties, except in cases provided for by the Privacy Policy and the legislation of the Republic of Kazakhstan, and is not responsible for incorrectly or inaccurately provided data.
Vulnerability Disclosure Policy
A vulnerability is a reproducible flaw in a system that can be intentionally used to compromise its integrity or confidentiality, or to cause a malfunction.
- Do not publicly disclose or share with third parties any information about a discovered vulnerability until you have received the explicit permission of the information system owner.
- If you follow the established Bug Bounty rules and act in good faith and within the approved scope of the program, the Operator will not take legal action regarding such research.
- Interact only with your own accounts or with the explicit permission of the account owner.
Rules of Participation
To participate in any program, you must act ethically, responsibly, and in accordance with these rules.
- Do not disclose information about a discovered vulnerability until you have received the explicit permission of the information system owner (see “Vulnerability Disclosure Policy”).
- Do not use threats of public disclosure of reports as a means of pressure - on moderators, the information system owner, or the platform - to influence a decision, speed up review, or increase the reward. Such behavior is treated as extortion and results in immediate sanctions, up to permanent account suspension.
- Make every effort not to harm users or services - always act in good faith.
- Use only your own accounts, phone numbers, and devices for research. Do not attempt to access other users’ accounts or data.
- If during testing you accidentally gain access to personal data, immediately delete all related information and notify the platform team.
- Take all reasonable measures to avoid breaches of confidentiality and service availability: unauthorized access to data, destruction of data, interruption or degradation of the service.
- Provide a manual proof of concept (PoC) for each vulnerability (see “Report Requirements” and “Responsible Use of AI Tools”).
- Communicate with all platform participants respectfully and professionally (see “Respectful Communication”).
- The following actions are prohibited and will result in denial of payment and possible account sanctions:
- Physical interference with the operation of data centers or offices
- Social engineering targeting company employees
- Hacking the company’s infrastructure to gather material for a report
- Attempts to access other users’ accounts or data
Depending on the context and severity of the incident, consequences range from an official warning to temporary or permanent loss of privileges on the platform.
Respectful Communication
All researchers are expected to communicate respectfully and professionally with moderators, information system owners, and other platform participants. The moderation team works hard to review every report fairly and promptly. Please treat them accordingly.
Rude, aggressive, or disrespectful communication with moderators - regardless of your disagreement with a decision - is grounds for account sanctions. We expect a professional tone in every situation.
Private and Public Programs
Private programs are available by invitation only. All reports remain confidential. Researchers may not publicly discuss discovered vulnerabilities. It is prohibited to disclose the existence of a private program, your invitation to it, or any of its contents. Access to private programs is granted by invitation. Invitations are extended to researchers who have established themselves on the Platform; selection takes into account, but is not limited to, in particular:
- Verification - completed identity verification (a mandatory condition; see “User Verification”).
- Reputation - the researcher’s reputation on the Platform and position on the leaderboard.
- Points - points accumulated for accepted reports.
- Quality, not quantity - the share of accepted and substantive reports matters more than the total number of reports submitted; a large number of duplicate, “informational”, or rejected reports reduces the chances of an invitation.
- Behavior - compliance with the rules and program scope, respectful communication with moderators, and absence of violations (see “Rules of Participation” and “Respectful Communication”).
The Platform determines the researchers invited to private programs at its own discretion. An invitation to a private program is not guaranteed and may be revoked in the event of a violation of the Platform’s rules.
Public programs are available to all researchers on the platform and are an excellent way to develop skills and build reputation on the platform. Researchers may not publicly discuss discovered vulnerabilities.
Out-of-Scope Targets
When submitting a report, you select the vulnerability type. If there is no suitable type in the list, the “Other” or “Custom” category is available.
Before selecting the “Other” category, review the program description and make sure the affected target is within the approved scope (domains and vulnerability types).
If a vulnerability outside the domain scope is discovered accidentally during testing and is of high severity, you may report it, but a reward and points are not guaranteed; the report may also be rejected.
QazNet Programs - Special Rules
QazNet programs cover resources in the .kz domain zone and are implemented in support of the national “Cyber Shield 2” concept. Given the scale of the zone, these programs do not involve direct contractual relationships with all information system owners - reports are accepted in an open format, and the decision to accept a report and the reward amount remains with the information system owner. For this reason, response and payout times under the QazNet program may be long or absent.
Reports submitted under any QazNet program must meet the following requirements:
- Specify the domain or confirmed ownership of the IP. If you submit an IP address without a domain name, you must indicate which resource or owner it belongs to and attach proof of ownership (e.g., reverse DNS, WHOIS). Reports with an IP address without confirmed ownership are not considered.
- The research target must meet at least one of the following conditions: (a) a domain name in the .kz top-level zone; or (b) the resource is hosted in Kazakhstan (the server is physically located in KZ IP space). Reports on resources that do not meet these criteria are rejected regardless of the type or severity of the vulnerability.
- Inactive and abandoned resources are not accepted. A resource is considered inactive if all of the following conditions are met at once: (a) the site has no active functionality (no forms, authentication, dynamic or user-generated content); (b) the page returns only a blank screen, a single line of text, a 403/503 error without content, or a default web-server page. If a researcher believes a resource is active despite these external signs, this must be justified in the report (e.g., by indicating active endpoints, API responses, or forms). In exceptional cases, at the moderator’s discretion, such reports may be accepted with the “Noted” status, without a reward.
Testing Rules
General Rules
Automated testing tools must not exceed 5 requests per second per target host and no more than 3 parallel threads at a time.
Avoid aggressive testing - you are testing a live production environment. Aggressive scans may trigger security systems and lead to your account, phone number, or IP address being blocked by the target.
Mobile Application Testing
When submitting vulnerabilities in mobile applications, describe all steps starting from the SSL pinning bypass. Reports that skip this step may be considered incomplete.
The following are not accepted for mobile applications:
- Reverse engineering or lack of binary obfuscation
- Lack of root/jailbreak detection
- Lack of SSL certificate pinning
- Missing security flags in native libraries
- Vulnerabilities that require malware, root, or jailbreak on the device to exploit
- Attacks requiring MITM or physical proximity to another person’s device (NFC, Bluetooth, Wi-Fi)
If you have test accounts ready for the application under test, provide them to the moderators - this speeds up moderation and reduces the load on the infrastructure.
Submitting Vulnerability Reports
- Go to the “Programs” section and select a program. Read the program description carefully - it lists the in-scope domains and accepted vulnerability types.
- Click “Submit Vulnerability.”
- Attach all supporting materials. Complete evidence significantly increases the likelihood of a reward and points.
- After submission, the report receives the “New” status.
- You can withdraw a report via “My Reports” while it is in the “New” status - before it is reviewed by a moderator.
Report Requirements
Every valid report must contain:
- Proof of the vulnerability
- A description of the exploitation
- Complete step-by-step reproduction instructions
Incomplete, unclear, or poorly structured reports may be rejected without further review. The Operator and moderators reserve the right not to review reports in which the exploitation steps are provided only in attachments.
If you find an API documentation page (Swagger, OpenAPI, Postman collections, etc.) or another resource where a single finding automatically affects dozens of requests, submit one report for the entire finding rather than a separate report for each endpoint or request.
If several separate reports are submitted for a single finding, Tumar.One moderators and the information system owner’s moderators reserve the right to merge them into one; points and payment are awarded for the first correctly submitted report.
Images, video recordings, and scripts with the .py or .sh extension are accepted as proof of concept (PoC). HTML pages and other formats are not accepted as PoC: on their own, they do not confirm that a vulnerability was exploited. A report with a PoC in an unsupported format may be rejected.
Responsible Use of AI Tools
The use of GenAI tools and automation (scripts, fuzzers, scanners) to assist research is allowed under the following conditions:
- You must manually check and confirm each vulnerability before submitting.
- The report body must describe manual reproduction of the vulnerability - step by step, without references to “run the script.” A script may be attached as supplementary material (.py or .sh), but it does not replace the description of the manual steps.
- The moderator must be able to reproduce the vulnerability from the report description without running the attached script.
- Reports submitted without manual checking and verification, as well as reports without a step-by-step description, are subject to rejection.
Mass Submission Policy
If the same vulnerability is found on different domains within QazNet programs, the following procedure applies. Whether reports belong to the same finding is determined by the nature of the vulnerability - its class and vector - and not by the title or severity level specified by the researcher.
Mass submission of nearly identical reports (for example, 50 reports in a day for a single finding across different QazNet domains) creates noise and a significant load on the moderation team. In such cases, the first report is processed as usual (triage and scoring); each subsequent report for the same finding is also reviewed and moderated but, as a rule, receives a minimal score - for example, 1 point per report.
Systematic submission of repetitive, low-value reports, including for the purpose of artificially accumulating points, is classified as bad-faith use of the platform. In such cases, the Operator may take action against the account - from a warning to permanent restriction of access.
For applicable report-quality requirements, see “Report Requirements” and “Responsible Use of AI Tools.”
Report Statuses
Processing from submission to payout usually takes about 3 months but may take longer. Specific timelines depend on the program and the information system owner’s response speed and are not guaranteed. The Platform forwards reports to information system owners weekly, and response times may vary.
The SLA for the “New” → “Moderated” stage is about 2 weeks on average. Individual programs may specify a different SLA in their description; if no SLA is specified, the platform’s indicative value applies. The “Moderated” → “Sent to Owner” stage may take up to 2 weeks or longer. Further stages depend on the owner’s response and are not guaranteed.
| Status | Meaning |
|---|---|
| New | The report has been submitted and is awaiting initial analysis |
| Moderated | Reviewed by a moderator, not yet sent to the information system owner |
| Need Info | Not enough information - the report needs improvement |
| Duplicate | The vulnerability was already reported earlier (see “Duplicate Confirmation”) |
| Sent to Owner | The report has been forwarded to the information system owner |
| Accepted | The owner accepted the report; points are awarded and a monetary reward is possible |
| Owner Rejected | The information system owner rejected the report; the researcher is given the reason. No points are awarded. |
| Mod Rejected | A moderator rejected the report; the researcher is given the reason. No points are awarded. |
| Noted | A non-critical but valid finding; points may be awarded, no monetary reward is provided |
| No Response | The owner did not respond; points are awarded, no monetary reward is paid |
| Retest | A re-check after remediation has been requested; additional points may be awarded |
| Fixed | Following the “Retest”, the researcher confirmed the vulnerability was fixed |
| Not Fixed | Following the “Retest”, the researcher confirmed the vulnerability was not fixed |
Retest requests (“Retest”) must be answered within 2 weeks. After this period, the request is closed automatically. Both private and public programs may request a re-check.
Separately: if the owner accepted the report (the “Accepted” status) but the program does not provide a payout or no reward was assigned, the report remains in the “Accepted” status, with points awarded and no monetary reward.
Duplicate Confirmation
If your report is assigned the “Duplicate” status, you may be provided with the submission date of the original report as confirmation. By default, no other information about the original report is disclosed - including the report ID, its contents, and the nickname of the researcher who submitted it - however, it may be disclosed at the discretion of the program moderators.
Final Severity Determination
A researcher may specify their own severity assessment in the report, but it is taken into account only as input. The severity decision is final after moderation. Appeals against severity decisions and report decisions are not available. A researcher may leave a comment in the report with additional technical justification; the moderation team reviews it at its discretion but is not obligated to change the assessment.
Rewards and Payouts
To receive monetary rewards, you must first complete identity verification on the platform (see “User Verification”).
The reward amount is determined by the program terms. Programs with monetary rewards publish payout ranges in their description; programs without monetary rewards provide points only.
In public programs, the information system owner may decline a submitted report; in that case, points and/or a monetary reward may not be awarded.
After a reward is confirmed, the report is assigned the “Need signature” status. At this stage, the researcher must sign a contract and/or an Act of Work Performed / Services Rendered provided by the Operator. Researchers who are not citizens of the Republic of Kazakhstan may be required to execute additional agreements. The platform terms are accepted by the researcher upon registration or login by clicking the checkbox “By continuing, you acknowledge that you have read, understood and agreed to the Privacy and Personal Data Processing Policy and Public Offer” - this action is recognized as acceptance of the Public Offer Agreement for the provision of access to the web resource.
If a payout is assigned the “Rejected” status due to a technical error on the service side, the Operator begins fixing it and informs the user. For any questions, the user can contact support: email info@tumar.one, Telegram bot @TumarOneSupportBot.
Payouts are made to a bank card. For international transfers (outside the Republic of Kazakhstan), you must provide the SWIFT code of the recipient bank; the transfer currency is US dollars (USD). The recipient bank must not be on sanctions lists (OFAC and other applicable ones). In some cases, payment via PayPal is possible. The payment and contact details you provide are processed to make payouts in the manner established by the Privacy Policy. The Operator is not responsible for incorrectly provided details or data.
Payout Statuses
| Status | Meaning |
|---|---|
| Reviewing | The payout has been assigned and is awaiting confirmation by the Operator |
| Need signature | The reward is confirmed; a signature and/or digital signature on the Act of Work Performed / Services Rendered is required |
| Processing | The payment is being processed by the banking service |
| Paid | Successfully paid out |
| Rejected | Payment error; contact platform support |
Taxes and the Act of Work Performed / Services Rendered
The Operator acts as the researcher’s tax agent: it independently withholds and remits tax on rewards in accordance with the legislation of the Republic of Kazakhstan. On this basis, all researchers must sign an Act of Work Performed / Services Rendered; foreign nationals additionally sign the relevant document. This is a requirement of the tax authorities.
All amounts shown on the platform are Gross - that is, before the deduction of taxes and other mandatory payments. The researcher actually receives the amount net of such deductions, so the final payout may be less than the amount shown in the report.
This arrangement relieves the researcher of concerns about legalizing income earned through bug bounty. The Platform does not transfer the researcher’s personal data to third parties, except in cases provided for by the Privacy Policy and applicable law.
Vulnerabilities That Are Not Accepted
The following vulnerability types are not accepted by default across all programs. Individual program descriptions may specify exceptions or additional restrictions - be sure to review the program terms before submitting a report.
- IDOR - considered only in cases of high severity (determined by our specialist upon confirmation of the vulnerability)
- Any XSS other than Stored XSS
- Stored XSS - considered depending on the significance of the web resource
- Clickjacking
- Insecure Redirect URI
- Directory Listing Enabled - considered only when critical data is disclosed (passwords, backups, etc.)
- Sensitive Data Exposure - considered only when critical data is discovered
- Enabled debug mode - considered only if critical data is disclosed
- CSRF - considered only for critical functionality
- Admin panel disclosure - considered only when account takeover or access to critical information is possible
- User Enumeration - considered only when critical data is disclosed
- Security Misconfiguration - considered only with evidence that the threat can be realized
- Denial of Service (DoS)
- Spam
- Social engineering targeting employees, contractors, or customers
- Any physical attempts to gain access to the property and/or data centers of the information system owner
- Reports based solely on automated scanner output - a manual proof of concept is required
- Errors in third-party software - considered only with proven impact on the target
- Missing security headers that do not directly lead to a vulnerability
- SSL/TLS configuration weaknesses without proven exploitability
- Vulnerabilities affecting only outdated or unsupported browsers/platforms
- Password and account recovery policies (e.g., reset-link expiration, password complexity)
- Outdated DNS records pointing to systems not owned by the information system owner
- DMARC Policy Not Configured
Vulnerability Types by Severity Level for Public Programs
Points are awarded by vulnerability severity level as follows:
- Low severity - from 0 to 30 points
- Medium severity - from 31 to 60 points
- High severity - from 61 to 100 points
High severity:
- Remote Code Execution (RCE)
- SQL Injection
- XML External Entity Injection (XXE)
- Server-Side Template Injection (SSTI)
- Account Takeover
- Authentication Bypass
- Privilege Escalation
Medium severity:
- Server-Side Request Forgery (SSRF)
- 2FA Bypass
- Using Default Credentials
- Path Traversal
- Local File Inclusion (LFI)
- Unsafe File Upload
- Subdomain Takeover
- DBMS Misconfiguration
- File Extension Filter Bypass
- Insecure Data Storage
- Race Condition
Low severity:
- Brute Force
- Zone Transfer
- Mail Server Misconfiguration
- Insecure Data Transport
- Using Components with Known Vulnerabilities
- Parameter Pollution
- CRLF Injection
- Weak Registration Implementation
- Lack of Password Confirmation
- No Size Limit (File Upload)
- Misconfigured DNS
- HTTP and HTTPS Available
- Insecure CAPTCHA
- Potentially Unsafe HTTP Method Enabled
The severity level depends on the potential impact of the discovered vulnerability. For this reason, security analysts evaluate each report individually. In addition, vulnerability assessments differ across programs, so before submitting a report be sure to review the program description and follow its rules.
Leaderboard and Seasons
The Tumar.One researcher leaderboard is updated at the start of each season. A researcher’s position is determined by the total number of points earned in the previous season. The top researchers of the year make the annual Top 10 and are invited on stage at the KazHackStan conference.
| Season | Period |
|---|---|
| Season 1 | October – December |
| Season 2 | January – March |
| Season 3 | April – June |
| Season 4 | July – September |
Contacts and Support
For any questions, you can contact us by email at info@tumar.one or via Telegram support: @TumarOneSupportBot.
Appendix No. 2
to the Public Offer Agreement for the provision of services for the provision of access to a web resource located on the Internet at: https://tumar.one/
Privacy and Personal Data Processing Policy
1. Policy
- 1.1. Operator - a legal entity that owns the Platform and which independently and at its own discretion determines the procedure for using the Platform on the Internet, including the procedure for posting information on such a Platform.
- 1.2. Platform - a vulnerability reward program for information systems and information resources.
- 1.3. All exclusive rights to the Platform and its individual elements (including software, design) belong to the Operator in full. The transfer of exclusive rights to the User is not the subject of this Privacy Policy.
- 1.4. User - a person using the Platform.
- 1.5. Legislation - the current legislation of the Republic of Kazakhstan.
- 1.6. Personal data - personal data of the User, which the User provides independently during registration or in the process of using the functionality of the Platform.
- 1.7. Data - other data about the User (not included in the concept of Personal data).
- 1.8. Service(s) - services provided by the Operator on the basis of an agreement.
2. Collection and Processing of Personal Data
- 2.1. The Operator collects and stores only those Personal Data that are necessary for the provision of Services by the Operator and interaction with the User.
- 2.2. Personal data may be used for the following purposes:
- 2.2.1. provision of Services to the User;
- 2.2.2. identification of the User;
- 2.2.3. interaction with the User;
- 2.2.4. sending advertising materials, information and requests to the User;
- 2.2.5. carrying out statistical and other studies;
- 2.2.6. User verification.
- 2.3. The Operator, among other things, processes the following data:
- 2.3.1. last name, first name and patronymic;
- 2.3.2. email address;
- 2.3.3. Telegram account and/or phone number (including mobile number);
- 2.3.4. biometric data for verification;
- 2.3.5. bank details;
- 2.3.6. identity documents;
- 2.3.7. other personal data (if necessary).
- 2.4. The User is prohibited from indicating personal data of third parties on the Platform (with the exception of the condition of representing the interests of these persons, having documentary evidence of third parties for the implementation of such actions).
3. Procedure for Processing Personal and Other Data
- 3.1. The Operator undertakes to use Personal Data in accordance with the Law “On Personal Data” of the Republic of Kazakhstan and the internal documents of the Operator.
- 3.2. With regard to Personal Data and other User Data, their confidentiality is maintained, except when the specified data is publicly available.
- 3.3. The Operator has the right to keep an archive copy of Personal Data. The Operator has the right to store Personal Data and Data on servers outside the territory of the Republic of Kazakhstan.
- 3.4. The Operator has the right to transfer Personal Data and User Data without the consent of the User to the following persons:
- 3.4.1. to state bodies, including bodies of inquiry and investigation, and local governments upon their reasoned request;
- 3.4.2. in other cases expressly provided for by the current legislation of the Republic of Kazakhstan.
- 3.5. The Operator has the right to transfer Personal Data and Data to third parties not specified in clause 3.4. of this Privacy Policy in the following cases:
- 3.5.1. The User has agreed to such actions;
- 3.5.2. The transfer is necessary as part of the User's use of the Platform or the provision of the Services to the User.
- 3.6. The Operator carries out automated processing of Personal Data and Data.
4. Protection of Personal Data
- 4.1. The Operator carries out appropriate protection of Personal and other data in accordance with the Law and takes the necessary and sufficient organizational and technical measures to protect Personal data.
- 4.2. The applied protection measures, among other things, allow protecting Personal Data from unauthorized or accidental access, destruction, modification, blocking, copying, distribution, as well as from other illegal actions of third parties with them.
5. Other Provisions
- 5.1. This Privacy Policy and the relationship between the User and the Operator arising in connection with the application of the Privacy Policy shall be subject to the law of the Republic of Kazakhstan.
- 5.2. All possible disputes arising from this Privacy Policy are subject to resolution in accordance with applicable law at the place of registration of the Operator. Before applying to the court, the User must comply with the mandatory pre-trial procedure and send the Operator a corresponding claim in writing. The term for responding to a claim is 30 (thirty) working days.
- 5.3. If, for one reason or another, one or more provisions of the Privacy Policy are declared invalid or unenforceable, this does not affect the validity or applicability of the remaining provisions of the Privacy Policy.
- 5.4. The Operator has the right at any time to change the Privacy Policy (in whole or in part) unilaterally without prior agreement with the User. All changes come into force from the moment it is posted on the Platform.
- 5.5. The User undertakes to independently monitor changes to the Privacy Policy by reviewing the current version.
- 5.6. All suggestions or questions regarding this Privacy Policy should be communicated by email: info@tumar.one.
By transferring personal and other data to the Platform Operator through the Platform, the User confirms his consent to the use of the specified data on the policy and conditions set forth in this Privacy Policy.
If the User does not agree with the policy of this Privacy Policy, he is obliged to stop using the Platform.
Unconditional acceptance of this Privacy Policy is the beginning of the use of the Platform by the User.