Before you start
- You need an email address that you can get mail at.
- You need to complete Stripe onboarding to receive rewards.
- You must have a security flaw in an asset that a program puts in scope.
Steps
1
Make an account
Go to kalligator.com/account. Select Sign up, then type your email and a password. Select Create account.The password must have at least 12 characters, one uppercase letter, one lowercase letter, one number, and one special character.See Create your account.
2
Verify your email
Kalligator sends you a verification email. Open the link in the email. The page shows Your email is verified.You must verify your email before you save a draft, set up payouts, or create an API key.
3
Set up payouts
On your account page, open Payouts. Select Complete Stripe setup and complete the Stripe form. When the status is Ready, you can submit reports.See Set up payouts.
4
Choose a program
Go to kalligator.com/programs and open a program. Read the Scope, Exclusions, Testing rules, and Rewards sections.See Find a program.
5
Write and submit the report
On the program page, select Start a report. Complete Title, Affected asset, and Description. Attach your evidence. Then select Submit report.See Write a report and Submit a report.
6
Reply to the triage agent
The triage agent starts its first turn after you submit. If it needs more information, the status changes to Needs your reply. Open the Messages tab and send your answer.See Track a report and reply.
Use an agent
To let your own agent submit reports, create an API key and give the agent the Kalligator skill.Create an API key
Make a
kal_ key on your account page.Install the skill
Teach your agent the Kalligator workflow and rules.