> For the complete documentation index, see [llms.txt](https://docs.bypassec.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.bypassec.com/the-platform/hacking-competitions/researchers/reporting-findings.md).

# Reporting Findings

## Introduction

After registering as a researcher on the platform, you will gain access to available competitions and can begin reporting your first vulnerabilities.

## Competition Types

At Bypassec, we offer two types of tournaments:

* <mark style="color:green;">**Public**</mark>: Accessible to all researchers.
* <mark style="color:purple;">**Private**</mark>: Restricted to high-performing researchers selected by Bypassec.

To view available competitions, access the "**Competitions**" tab within the platform.

<figure><img src="https://1280147-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6pzVprfiCeyXuo0L4T%2Fuploads%2Fi9caZp5DNXAM1zWgBfwh%2FCaptura%20de%20Tela%202026-04-19%20a%CC%80s%2012.14.52.png?alt=media&amp;token=1e2f3463-1e02-4c3d-956c-f8e917d8f8b4" alt=""><figcaption></figcaption></figure>

Each competition has its own testing policy and scope, which can be viewed by clicking on the competition.

{% hint style="warning" %}
It is **strictly prohibited** to conduct tests on assets that are not explicitly defined in the scope section, as described in the Terms and Conditions of the platform.
{% endhint %}

## Reporting Vulnerabilities

To report a vulnerability, fill in all available fields and describe the exploitation process in detail.

<figure><img src="https://1280147-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6pzVprfiCeyXuo0L4T%2Fuploads%2FaOQQDoSV3cxGjLBbxWhY%2FCaptura%20de%20Tela%202026-04-19%20a%CC%80s%2012.15.14.png?alt=media&amp;token=159837ef-3d94-4547-9a8b-d0fec6e9192a" alt=""><figcaption></figcaption></figure>

Once you have reported a vulnerability, you can track its progress in the "Dashboard" tab.

<figure><img src="https://1280147-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6pzVprfiCeyXuo0L4T%2Fuploads%2FwbPF5SVDnTHQaJQbNCnK%2FCaptura%20de%20Tela%202026-04-19%20a%CC%80s%2012.34.04.png?alt=media&amp;token=7286ccff-f52a-4dbe-aa5b-6718dc16ace2" alt=""><figcaption></figcaption></figure>

## Report Validation

When vulnerabilities are reported, they undergo a validation process by the Bypassec team before their status is updated.

Incomplete reports or those lacking a clear description and reproduction steps will be automatically invalidated and will not be eligible for a reward. Similarly, vulnerabilities that do not demonstrate a relevant impact on the organization will be considered invalid.

{% hint style="info" %}
Reports are validated only after the tournament has concluded.
{% endhint %}

The available statuses are:

* <mark style="color:blue;">**Pending:**</mark> The vulnerability has been reported and will be validated by Bypassec at the end of the competition.
* <mark style="color:purple;">**Duplicate:**</mark> The vulnerability is valid and has also been reported by other researchers.
* <mark style="color:green;">**Valid:**</mark> The vulnerability is valid and unique.
* <mark style="color:red;">**Invalid:**</mark> The vulnerability is invalid and will not be eligible for rewards.

{% hint style="warning" %}
During the validation process, Bypassec may contact the researcher via email or Discord if the report requires additional information. The researcher will have **48 hours** to respond before the vulnerability is invalidated.
{% endhint %}

## File Uploads

All evidence regarding the reported vulnerability must be submitted through the platform's native upload feature.

{% hint style="danger" %}
It is **strictly prohibited** to store or submit evidence using applications that make them publicly available without any protection or credentials.
{% endhint %}
