More than 85 companies have joined intigriti so far!

Torfs

Up to €5000

Torfs - the well-known shoe retailer in Belgium - is still a 100% family business today. This family character guarantees a number of important values within the company where employees are central. A head office in Sint-Niklaas and a spectacular distribution center in Temse offer support to the points of sale and customers of the E-Commerce website. With more than 80 stores in Flanders, 2 shops in the French part of Belgium and a growing online shop in Belgium, The Netherlands and several marketplaces, Torfs wants to be and remain the most customer-friendly optichannel shoe store chain.

De Volkskrant

Up to €2000

De Volkskrant is a Dutch daily morning newspaper. Founded in 1919, it has a nationwide circulation of about 250,000 papers per day.

Port of Antwerp

Responsible disclosure

The Antwerp Port Authority has a key role in the port's day-to-day operation. The Port Authority manages and maintains the docks, the bridges, the locks, the quay walls and the land. The personnel is also responsible for safe shipping traffic in the docks, the bridges and locks. In addition, the Port Authority provides tugs and cranes, carries out dredging work and promotes the port at home and abroad.

OneSpan Mobile

Up to €4000

OneSpan (formerly known as VASCO Data Security) is a global leader in digital security with two-factor authentication, transaction data signing, document e-signature and identity management solutions designed for financial institutions, enterprises, healthcare institutions as well as government agencies. In this project, we request researchers to validate the security of two mobile authentication products (soft tokens), namely DIGIPASS for Mobile and the DIGIPASS App.

Hoplr

Sustainable

Responsible disclosure

Hoplr is the social network for inclusion and citizen engagement. As a social network we consider the safety and continuity of our online services as one of our top priorities. Our team is continually working to optimize our systems and processes, yet despite all the efforts we make to secure our systems, vulnerabilities may still be present. We are happy with your help to further improve our systems and to protect our users and customers even better.

IAM KU Leuven

Up to €2500

KU Leuven uses a central identity management platform to manage the accounts of its 32k employees and 115k students (up to 500k accounts known irrespective of access rights). Most of the web applications can be accessed via a central login system, which authenticates the user and communicates their identity and access rights to the web application. Recently KU Leuven introduced a strong authentication method named "KU Leuven authenticator" based on n-Auth technology. We challenge you to find the bugs in our IAM system! If you find any, we will be more than happy to pay the bounty!

UZ Leuven

Sustainable

Up to €2500

The external website of the University Hospitals of Leuven.

Tomorrowland

€50 ‐ €2500

Tomorrowland is one of the most-loved and best-known music festivals on the planet. Because of this Tomorrowland usually sells out in minutes and manages a large fanbase. Tomorrowland also innovates by providing its visitors cashless onsite payments and a wide range of online services. This has increased Tomorrowland's digital footprint. We value all help we can get securing this digital footprint.

Online enrollment for students

Up to €2500

The online enrollments application allows students to apply for educational programs at the university or at university colleges. Every year approximately 40.000 applicants enter their personal information and educational preferences into this application. We challenge you to find the bugs in our online enrollment application.

Algemeen Dagblad

Up to €2000

With around 900 editors Algemeen Dagblad (AD) has become the largest journalistic organization in the Netherlands, offering both national and extensive regional news coverage.

Jooki

Responsible disclosure

Jooki by Muuselabs - the IoT speaker for kids Jooki is a music player that kids can independently use in a safe and screen-free environment. Upload your own content for offline use or listen online to your favourite Spotify playlists or web radios. Jooki has all cool tech you can imagine: WiFi, Bluetooth, a microphone, speakers, NFC tags, voicemail service... The Jooki devices have a web UI at http://my.jooki.rocks and communicate with various APIs on that domain. We invite you to exploit them! At the moment we are not offering monetary awards, however, notable exploits will be rewarded with a Jooki (retail value €199). We plan to expand the scope of the project to include exploits of the Jooki devices.

Het Parool

Up to €2000

Het Parool is a Dutch regional newspaper that started in the Second World War as a social-democratic tinted resistance newspaper.

Phished

Responsible disclosure

Phished helps companies raise staff awareness of cyber risks by sending employees realistic mimics of cyberattacks. This process is fully automatic and leads to an efficient cybersecurity strategy. Phished is active in several countries within Europe, together accounting for some 250 customers, mainly multinationals, SMEs, hospitals, and government institutions.

Telenet - Base

Sustainable

Up to €1500

At Telenet we place great importance on the security of our systems and data. Despite the measures we take to optimise our security, it is nevertheless possible that something will slip through the net. The brands that are part of Telenet group are Telenet, Base and 9lives. Should you discover a security problem, we have a system in place for you to report it to us in a responsible way. We are happy to have your help to improve our systems and protect our customers even better.

Twago

Responsible disclosure

Twago is the leading platform for online work in Europe. On Twago, individuals or companies of all sizes find the experts they need for projects, and freelancers and agencies find work and grow their businesses.

Showpad

Up to €3000

Today’s buyers don’t have time for unprepared sellers. Buyers expect sales conversations that drive value and provide insights. Showpad surfaces content and training to salespeople in the context of their everyday work – and for every sales opportunity. All in a single platform designed to maximize sales productivity and empower sellers to exceed buyer expectations. Let out your inner corporate spy and get paid to steal your competitor's confidential data from our platform!

Application Required

Hardware Info

Up to €2000

Since its establishment in 1999, Hardware Info has been informing consumers in the Netherlands and Belgium about computer hardware and consumer electronics. Part of Hardware Info is a leading test lab, where more than 1500 products are tested professionally every year. In the test lab, the editors of Hardware Info have professional testing equipment at their disposal in order to be able to give as professional an opinion as possible about products. Based on the test results, we publish extensive comparison tests, but also in-depth single product reviews. The PC Advice systems are, as far as possible, also put together based on well-tested products. Editorial independence is of paramount importance at Hardware Info: that is why the commercial exploitation of the website is strictly separate from the editors. In addition to the website, Hardware Info also appears as a magazine six times a year. Hardware Info has been part of De Persgroep Online Services B.V. since September 2016.

Brussels Airlines bookings

Up to €5000

This project is focussing on the flight search and booking engine of Brussels Airlines

Napoleon Games

€50 ‐ €10000

Napoleon Games is the Belgian leading gambling website where your can play several types of games: www.napoleoncasino.be, www.napoleondice.be, www.napoleonsports.be etc. Napoleon Games is a legal and safe website and is approved by the Belgian Gaming Commission.

intigriti

Sustainable

€150 ‐ €7500

At intigriti, we practice what we preach. We’ve built the platform with the greatest care and attention for security, but all software contains bugs and we are no exception to this rule. We encourage you to responsibly disclose any security vulnerabilities they may encounter and will reward you accordingly.

Student Assessment System

Up to €2500

The Student Assessment System (internally referred to as the Print&Scan application) is a tool for processing multiple choice exams. The inputs for the tool are a file containing user information, a file containing student's answers to the multiple choice exam and and the correct answers. After processing the files, the tool presents the user with some statistics about the exam, as wel as the calculated scores for the students. Each year about 1000 exams are processed using this tool, grading over 50.000 students. Since the results of this tool are used to determine whether students are able to graduate, it is important that it is secure. We challenge you to find the bugs in our Print&Scan tool.

Nexuzhealth

Sustainable

Up to €4000

Website + Android Apps + iOS Apps Android Apps KWS Companion The application is only to be used by doctors and no logon information will be given. mynexuz CPV The application is only to be used by personnel of UZ Leuven responsible for transport of patients and no logon information will be given. mynexuzhealth app This application is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. iOS Apps KWS Companion The application is only to be used by doctors and no logon information will be given. Website mynexuzhealth website This website is intended to be used by patients in order to consult their private data, their doctors & appointments and more. Login: see below. In order to be able to logon to the mynexuzhealth website and app, an ethical hacker will need to request one or more logon credentials via the platform. You can request this information via support (support@intigriti.be). The information they will receive is - A user ID of 8 numbers - A PIN code of 4 numbers - A QRCode

Humo

Up to €2000

Humo brings high-profile cover stories and revealing interviews and files. And that with a characteristic approach: reliable information, a critical attitude and a sense of humor and self-relativity. The reader is treated every week on articles about television, society, sports, culture and pop, sharp columns and quirky discussions of TV programs, books, films and music.

KU Leuven - www.kuleuven.be

Responsible disclosure

KU Leuven has a very diverse web landscape. Keeping this environment and the data it contains as secure as possible is an ongoing effort. We would like to invite you to help us in this effort. We are happy to have your help to improve the security of our systems .

Kinepolis Group

Up to €5000

Our website is a way to inform and inspire customers about the latest and brightest. It allows to: • Get up to date information about the movies and events we offer; • Choose your favorite movie theater, pick a date and time; • Buy tickets and enhance your experience by choosing for ‘cozy seat’ instead of our normal seats. Just in case you want to have a ‘cozy night’ with your significant other! Cry of laughter or maybe some scary movies are your favorite ones. Via a My Kinepolis account we target movies and unique promotions based on your preferences. While researching our website you can already explore our schedule and plan your next trip to one of our movie theaters. We are ready to be challenged!

Tempo-Team

Responsible disclosure

Tempo-Team offers daily new and varied jobs for every level and field.

Suivo

Sustainable

Up to €2000

The Suivo Web Platform provides access to Tracking data from vehicles equiped with Suivo hardware. The platform is built around 4 components: - Real-time Tracking data - Analytics based on historical Tracking data, both in a web view en generated reports - Communication: tasks and messages - Fleet management (Maintenance planning etc.)

De Morgen

Up to €2000

De Morgen has a broad view of the news with attention to political current affairs, culture and media. The editors are critical, dig deeper and often make the news of the day under the motto more insight, more salmon. De Morgen is aiming for an open-minded audience that is looking for qualitative news coverage, background and interpretation of the news. The newspaper looks young and fresh and has won international prizes with its design.

Speakap Responsible Disclosure

Responsible disclosure

Since 2010, Speakap has helped more than 400 companies across 120 countries, 42 languages, and many time zones, reach their full potential with more productive employees. With an award-winning, easy-to-use employee app, Speakap empowers company leaders to share the right content with the right people at the right time. Speakap boasts very high adoption rates with users logging in almost 6x a day for 50+ seconds per time.

itsme

Up to €5000

Help us to get better at what we do: Privacy & Security of convenient online identity. We want to make the web a better place for every Belgian citizen or resident with a Belgian Mobile Subscription. Apart from internal practices to ensure that what we bring to the market is already developed and tested to be secure, we want to raise the bar for ourselves by asking you to help us track down vulnerabilities.

Infomaniak

Sustainable

€100 ‐ €2500

Infomaniak is Switzerland's largest web-hosting company, also offering live-streaming and video on demand services. Founded in 1994, Infomaniak is an independent company wholly owned by its founders and employees. Not only are 70% of their employees highly qualified engineers, they also focus systematically on internal development and open source solutions to design their products. Guaranteeing the security and confidentiality of the data entrusted to them is one of their priorities.

Application Required

VTM GO

Up to €2000

VTM GO offers a lot of strong Flemish and exclusive international series & films for free. From news and news to the most powerful fiction and reality shows.

VRT

Responsible disclosure

Flemish Radio and Television Broadcasting Organization

GULP

Responsible disclosure

GULP is a leading personnel service provider in the areas of IT, engineering and finance.

Randstad

Responsible disclosure

Randstad is the global leader in the HR services industry. By combining our passion for people with the power of today’s intelligent machines, we support people and organizations in realizing their true potential.

Risesmart

Up to €1500

We at RiseSmart believe protecting the privacy and security of our customers is of utmost importance. In order to ensure it we would like to proactively find and fix any vulnerabilities or security threats before anyone else with wrong intentions may start exploiting it. We invite researchers like you to give us a chance to notify us about any security threats and help us to protect our customers and make the internet a safer place. Below is a short description of our modules Torch: A Service Delivery Platform where a dedicated team having Professional Branding Expert, Personal Career Coach and Job Concierge etc. working one-on-one with Participant. Spotlight: A Web Consumer Portal offering complete talent mobility solution where job seeker can access tailored Opportunities, Networking Tools and Actionable Content etc. Insight: A Web enterprise portal helps you to manage your important outplacement data, reports, metrics, and analysis. Relevant and actionable information at your fingertips.

T&C Required

Arkane Network

€100 ‐ €5000

Arkane is a multi-blockchain wallet provider that builds an open network between individuals, ecosystems and dapps.

Access router

Up to €2500

The access router is a router in the KU Leuven datacenter that ensures the connectivity between the KU Leuven network and its ISP. Suspected vulnerabilities in our access router that can be abused and can lead to: - Disruption of the proper operation of our equipment - Unauthorized access to, modification or deletion of configuration

eHealth Hub VZN KUL

Sustainable

Up to €2000

The national project “eHealth Hubs & MetaHub” coordinated by the eHealth platform is meant to make medical results from hospitals (and in the near future medical laboratories) available to any caregiver who currently is treating the patient . For detailed information see https://www.ehealth.fgov.be/nl/zorgverleners/online-diensten/hubs-metahub and the URL in the next paragraph. This system supplements the traditional system of addressed ‘email type’ communication to individual referrers. Before medical data about a patient can be shared, that patient has to grant the ‘eHealth informed consent’ (see http://www.patientconsent.be ). Further, care providers declare a therapeutic relationship with the patient. Communication between the hubs and between external physicians and a hub is according to the KMEHR standard: https://www.ehealth.fgov.be/standards/kmehr/content/page/web-services The scope of this project is confined to the hub exploited by VZNKUL (Vlaams Ziekenhuis Netwerk KU Leuven) implementation of this hub system. The central metahub hub from the Belgian government, the other hubs, and the systems at other partners of this project are out of scope.

Delen Private Bank

€100 ‐ €15000

Delen Private Bank is a family-based specialist in asset management, focused on wealth preservation, growth and careful planning. Our core values - entrepreneurship, personal service and long-term vision – inspire us to apply a proactive yet prudent investment philosophy. Honest, no-nonsense products and services help our clients to enjoy the good and beautiful things in life – both today and tomorrow.

Brussels Airlines

Up to €5000

Safety is and has always been the first priority in the aviation world. Our IT solutions are no exception to this rule. We are therefore actively looking for experienced test pilots. Are you willing to take our application in hard turns, dives and looping in order to identify any possible vulnerability? Just put on your jacket, go through our safety checklist, turn on the engines and you are ready to fly! Our engineering team is eager to hear your debrief after landing, and will make sure to address any flaw you might have noticed. Please allow them a grace period before disclosing your findings, as in return they will make sure to provide you feedback on their progress. Have a good flight

OneSpan Trusted Identity Platform

Up to €2000

OneSpan (formerly known as VASCO Data Security) is a global leader in digital security with two-factor authentication, transaction data signing, document e-signature and identity management solutions designed for financial institutions, enterprises, healthcare institutions as well as government agencies. Trusted Identity Platform, or TID, is OneSpan's cloud-based platform that delivers security technologies to secure digital interactions. In this project, we request researchers to validate the security of the TID Developer Portal and the TID Microservices (Adaptive Authentication services).

EURid

€50 ‐ €5000

EURid is the registry manager of the .eu, .ею (Cyrillic script) and .ευ (Greek script) country code top-level domains (ccTLD) upon the appointment of the European Commission since 2003. We take the security of our systems and services seriously to ensure the protection and privacy of our users and customers and the stability and availability of our services. Nevertheless, if you stumble upon an issue you consider a vulnerability, let us know as soon as possible following these guidelines.

PDQ.com

Up to €2000

With PDQ Deploy and PDQ Inventory, you can complete a majority of Windows sysadmin tasks without even leaving your desk. That vacation is just around the corner.

Application Required

Sentiance

Sustainable

Up to €2500

At sentiance we process enormous amounts of sentive data to provide our clients with rich insights & analytics used by them to optimize their business. All our products are built with security in mind and each feature has been carefully assessed to prevent security vulnerabilities to be introduced in our services. However, no security team is perfect and therefore we would like to call in the help of the bug bounty community to point out where we might have missed a bug. If you think you found a valid security vulnerability we would absolutely love to hear about it and award you if it's eligible per our policy.

Red Bull

Responsible disclosure

Red Bull appreciates the work of security researchers to make the internet a better - and more secure - place. Even though we aim to prevent security issues by applying state-of-the art development and operations processes, systems and technical services outside our direct control might have vulnerabilities and weaknesses and we aim to identify and address those before any negative impact occurs. As appreciation we have a unique reward system in place, please see FAQ for more information.

Tweakers

Up to €2000

Tweakers is a Dutch technology website featuring news and information about hardware, software and the Internet. We take security very serious as many of our users use our site as a trusted source. Therefore we have decided to collaborate with ethical hackers that can inform us about potential vulnerabilities in our systems. If you happen to find a vulnerability we'd be more than happy to hear about it and, if its impact is significant enough, award you a bounty as token of appreciation.

Monster Worldwide

Responsible disclosure

Monster is your source for jobs and career opportunities. Search for jobs, read career advice from Monster's job experts, and find hiring and recruiting advice.

Nexuzhealth Web PACS

Sustainable

Up to €1000

This website is used to provide patient access to their radiology images (PACS). Patients logon with their date of birth, and a unique code provided to them by the physician. This code provides access to one study.

Bpost2

Responsible disclosure

The purpose of this website is to publish general information about bpost and its subsidiaries and their respective activities.

Trouw

Up to €2000

Trouw reaches thousands of people involved daily with in-depth journalism via print and online via the news site, news apps and digital newspaper

iBOOD.com

Up to €500

iBOOD looks forward to working with the security community to find security vulnerabilities in order to keep our business and customers safe. A security vulnerability is a weakness in a product, service or system that could allow an attacker to compromise the integrity, availability, or confidentiality of that product, service or system. Thank you in advance for your contribution!