vulns.co
/
GKData.io MCP

Arm · 2 min read

Trusted Firmware Bug Bounty

Arm · Intigriti. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Reports need human-validated, realistic security impact. Social engineering, physical intrusion and DDoS are prohibited; disclosure requires written consent. Conditional protections cannot authorize third-party systems.

Eligibility and submission status

Participants must be 18 or older and legally reward-eligible. Sanctions restrictions and 12-month employment/immediate-family exclusions involving Trusted Firmware member companies apply. Platform first-valid-report and identity-check requirements apply.

Logged-out policy and login invitation do not independently verify current acceptance.

Advertised rewards

Advertised severity amounts: $1,000, $3,000, $10,000 and $20,000. Certain privileged-component findings are capped at Low. Dollar denomination is unverified; normalized currency and bounds remain null.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 4 published rows
AssetTypeGroup / eligibility
TrustedFirmware-A (TF-A)OtherTier 2
TrustedFirmware-M (TF-M)OtherTier 2
TF-PSA-CryptoOtherTier 2
OP-TEEOtherTier 2
Out of scope · 0 published rows
AssetTypeGroup / eligibility
No rows captured. This does not establish that the program has no assets or restrictions.

Review limitations

  • Two July 2026 notices were reviewed; complete historical coverage was not established.
  • Platform euro settlement does not establish the advertised dollar denomination.
  • Logged-out text review; authenticated eligibility and incorporated documents were not exhaustively checked.
  • High-level summaries omit inventories and testing instructions. Live terms prevail; this record grants no authorization.

Sources and provenance

  1. Trusted Firmware Bug Bounty policy Arm / Intigriti · reviewed 2026-10-03
  2. Intigriti Researcher Terms & Conditions Intigriti · reviewed 2026-10-03
  3. Trusted Firmware program updates: July 17 and July 28, 2026 Arm / Intigriti · reviewed 2026-10-03
  4. Published Intigriti asset table Arm · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software