Bounty Trust Desk campaign intake.
For teams preparing a bounty, creator-task, quest, or launch campaign. Submit the public brief, task sheet, reward rules, and proof requirements; VegaSec reviews unsafe wording, farming/abuse loops, operator escalation, and audit-core separation in a private lane.

Bounty Trust Desk intake
Campaign review stays private: task wording, proof rules, abuse risk, and operator escalation before launch.
What we review
- Public-source evidence pass: market data, holder/owner posture, repo activity, contract source provenance.
- Static analysis of any Solidity source you submit (slither + semgrep) with audit-grade enrichment.
- Operator-authored risk memo with severity, confidence, failure mode, remediation direction, and explicit approval state.
- Optional Trust Index entry alignment so the public artifact and the private memo do not contradict.
What is NOT included
- Not a formal smart contract audit attestation. Use a contracted audit firm for that scope.
- Does not tell anyone to buy, sell, hold, or invest; not custody, and not a replacement for a contracted audit firm.
- Not retrospective forensic incident response. Filed separately if you have an active incident.
- Not on-chain monitoring beyond the requested scope window.
Deliverables
- Private Review memo (Markdown + shareable HTML preview) covering executive summary, scope, findings, evidence authority, severity, confidence, failure mode, remediation and limitations.
- Optional buyer-call summary: 1-page executive brief framed for a non-technical reviewer.
- Re-scan + Trust Index re-evaluation after the project ships the documented remediation.
Turnaround / SLA
Standard
Reply within 48h · memo within 5 business days
Default for non-launch reviews.
Priority
Reply within 24h · memo within 3 business days
Launch window or buyer call inside two weeks.
Critical
Reply same business day · memo within 48h
Pre-launch blocker, active diligence, public exposure within 72h.
SLA tiers cover operator reply and memo turnaround. They do not promise a particular verdict or score outcome. Operator may extend SLA if scope grows during triage; you are notified before any extension is committed.
Confidentiality and data posture
- Submissions are stored server-side under VegaSec operator access only. Operator inbox is gated behind an env flag.
- Notes are scanned for common secret/key patterns and redacted before storage. Do not paste seed phrases, private keys, API keys or wallet credentials: VegaSec does not need them.
- Mutual NDA is available on request before any privileged material is exchanged.
- Default data retention is 90 days from intake. Earlier deletion on request.
- VegaSec is not custodian of any asset and does not transact on your behalf at any point.
Pricing framework
Free reservation intake
Reserve a priority review lane with target and context. The public scan remains free and unaffected.
Quote after scope
Once scope is agreed (single contract / repo / multi-contract / time-pressured launch), VegaSec returns a fixed quote and SLA tier. No billable work starts without confirmation.
Independent from public score
A paid Private Review does NOT raise the public Trust Index score. The two surfaces are intentionally separated. Public score reflects public-source evidence only.