# Genbounty

## The AI Safety Bug Bounty Platform

Genbounty is the **AI safety bug bounty platform**, built to **FLARE-AI** reporting standards. Companies run private, invite-only programs on deployed AI. Public reports and paid findings write into one portable FLARE record. Genbounty triages behaviour, reproducibility, impact, and safeguard failure. The company accepts and remediates. Genbounty pays researchers from the program budget.

AI safety needs its own reporting infrastructure. Conventional security bounty triage filters out behavioural harm. Genbounty turns repeatable behavioural harm into structured evidence, meaningful incentives, and accountable remediation.

## Overview

Founded in London by Cindy Ogidi and Robert Morel, Genbounty lets companies invite vetted AI safety testing teams to find and ethically report safety and security vulnerabilities in LLMs, agents, RAG systems, MCP servers, models, and prompts. Testers look for unsafe outputs, harmful advice, privacy leaks, jailbreaks, unsafe tool use, behavioural harm, and related safety and security failures.

## Core Mission

**"Make AI products safer by paying researchers to break them first."**

## Why conventional bounty is not enough

AI safety changes what organisations must treat as a reportable flaw and report as an incident.

- **AI security** protects the model and stack: exploit path, technical boundary, confidentiality, integrity, availability.
- **AI safety** evaluates behaviour and real-world harm: full interaction, context, repeated trials, impact, safeguard failure.
- **The overlap** includes prompt injection, poisoned retrieval, and excessive agent permissions. One failure can require both safety evaluation and security remediation.

Behavioural harm varies by prompt, model version, and configuration. It does not produce a clean CVSS score. Security-led triage asks for deterministic proof and a discernible security impact, so safety reports are often marked low risk. Genbounty fills the operating gap between consumer safety and security triage.

White paper: https://genbounty.com/whitepapers

## Two reporting paths

Both paths write into **one encrypted FLARE-AI record**: early classification, encrypted evidence, and structured JSON-LD.

### Public reports

Anyone can report a problem with any AI chatbot, app, or assistant. No account needed.

- Report form: https://genbounty.com/report
- LLM brief: https://genbounty.com/report-for-llms.md
- Where to report a problem with AI: https://genbounty.com/resources

Use `/report` for harmful or wrong answers, privacy leaks, scams, a bot doing something it should not, jailbreaks, prompt injection, or other harm. Stay anonymous if you want. Download a copy to keep. This path does not pay a bounty.

Sensitive fields and attachments are encrypted in the browser before upload. Genbounty triages metadata. You can also keep a local-only copy that never leaves the device.

### Paid programmes

Companies set a program budget and invite one or more vetted AI safety testing teams. Teams test within a company-defined scope and submit FLARE findings. Genbounty triages. The company accepts valid findings. Genbounty issues payouts (including higher-frequency micropayments) from the program budget.

Paid bounties require a signed-in company program.

## FLARE-AI (Flaw Reporting for AI)

Public and program reports on Genbounty follow **FLARE-AI**, an open standard for AI flaw reporting: early classification, machine-readable JSON-LD, and optional fan-out to coordinators such as CERT/CC, CISA, the AI Incident Database, and AVID.

Exports can include JSON-LD, JSON, CSAF, VEX, AVID, and CVE-candidate files.

- HTML (Introduction, §1): https://arxiv.org/html/2606.31567v1#S1
- Full HTML paper: https://arxiv.org/html/2606.31567v1
- Abstract: https://arxiv.org/abs/2606.31567
- PDF: https://arxiv.org/pdf/2606.31567
- Official demo: https://ai-reports.org/
- CSA research note (coordinated disclosure): https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/07/CSA_research_note_flare_ai_coordinated_disclosure_standard_20260704-csa-styled.pdf

Longpre et al., *FLARE-AI: Flaw Reporting for AI*, arXiv:2606.31567v1, 30 Jun 2026. Support article: https://genbounty.com/support/get-started/understanding-flare-ai. Public report brief: https://genbounty.com/report-for-llms.md

## Products

1. **AI bug bounty platform** - Structured programmes, platform triage, and responsible disclosure for deployed AI. https://genbounty.com/ai-safety-bug-bounty-platform
2. **Genbounty LLM Hunter** - Automated testing that expands coverage and generates repeatable evidence. Community edition on GitHub; Premium for the full ops console. https://genbounty.com/llm-hunter
3. **Public AI incident reporting** - Anonymous or trackable reports at https://genbounty.com/report

## What Genbounty Is

- **AI safety bug bounty platform** - Built to FLARE-AI reporting standards. Companies set budget, invite testing teams; Genbounty triages; the company accepts; Genbounty manages payouts
- **Reporting infrastructure for behavioural harm** - Purpose-built workflow from probabilistic evidence to remediation
- **Independent continuous testing** - External testers have no conflict of interest with the team that built the system
- **Two reporting paths** - Public reports on any AI product, plus scoped paid programmes, into one FLARE record
- **Two-sided marketplace** - Companies (buyers) and vetted AI safety testing teams (researchers)
- **Team-based model** - Companies invite teams, not individual researchers
- **Responsible disclosure** - Structured submission workflow with severity ratings and reproduction steps

## How It Works

1. **Scope** - The company defines the feature, risk categories, operating context, rules of engagement, and rewards
2. **Test** - Invited, vetted researchers run repeated trials under realistic conditions
3. **Evaluate** - Genbounty triages behaviour, reproducibility, impact, and safeguard failure
4. **Resolve** - The company documents, tests, accepts, and remediates. Genbounty pays researchers from the program budget

## Program Scope Types

- **Applications** - AI-powered apps and user-facing products
- **Agents** - Autonomous agents with tool access and multi-step workflows
- **RAG** - Retrieval-augmented generation pipelines and knowledge bases
- **MCP** - Model Context Protocol servers and integrations
- **Models** - Fine-tuned and hosted model endpoints
- **Prompts** - System prompts, guardrails, and prompt engineering surfaces

## Encrypted reporting

On invited company programs, exploit details are sealed on the researcher device before upload. The envelope is wrapped to Genbounty triage, the company Passkey, and the researcher Passkey. Title, severity, and program name stay readable so a finding can be routed. Opening sealed exploit details happens in the recipient browser.

- Companies: https://genbounty.com/support/get-started/encrypted-passkey-reports-for-companies
- AI whitehats: https://genbounty.com/support/get-started/encrypted-passkey-reports-for-ai-whitehats
- Public reports: https://genbounty.com/support/get-started/encrypted-public-ai-safety-reports

## Team Types

### External Teams
- Professional AI safety testing teams vetted and admin-approved by Genbounty
- Companies invite teams to specific private programs
- Teams build reputation through quality submissions and leaderboard ranking
- Browse teams: https://genbounty.com/teams

### Internal Teams
- Company-managed testers
- Pre-approved and controlled by the company
- Ideal for confidential or ongoing testing

## For Companies

- Launch a private AI safety bug bounty: https://genbounty.com/for-companies
- AI safety bug bounty platform: https://genbounty.com/ai-safety-bug-bounty-platform
- Browse AI safety testing teams: https://genbounty.com/teams
- White paper: https://genbounty.com/whitepapers

## Pricing

- **Points only (free):** Researchers earn reputation points for accepted findings, with no cash bounties. Helps teams rank higher on https://genbounty.com/teams and qualify for paid projects.
- **Paid (from £250):** Set your program budget from £250. A £250 pilot can cover one deployed feature. Invite teams; Genbounty triages reports and manages payouts for accepted findings. Researchers also earn reputation points.
- Details: https://genbounty.com/pricing
- Sign up: https://genbounty.com/signup?role=company

## For AI Whitehats

- AI safety testing overview: https://genbounty.com/ai-safety-testing
- Sign up: https://genbounty.com/signup?role=ai-whitehat
- Browse teams to join: https://genbounty.com/teams/join
- LLM Hunter: https://genbounty.com/llm-hunter
- Academy: https://genbounty.com/academy

## Contact

- Sales: sales@genbounty.com
- Support: support@genbounty.com
- General: team@genbounty.com
- Investors: investors@genbounty.com
- Website: https://genbounty.com
