Target authorized
The project must already have Dual-Proof Authorization and must explicitly enable the Bounty scope.
Researchers can submit sealed findings against projects that explicitly enable Lock Bounty. The platform does not publish the report, the PoC or the vulnerability. It rebuilds the authorized target state and determines whether the claimed behavior can be independently reproduced.
The project must already have Dual-Proof Authorization and must explicitly enable the Bounty scope.
The researcher's evidence bundle is hashed locally and treated as confidential security intelligence.
The claim is tested against the authorized project state in its isolated sandbox twin.
Verified claims enter private remediation; Lock re-tests the patch before TWIX settlement completes.
Projects can reserve TWIX for validated security research while Lock handles target authorization, sandbox reproduction, remediation re-test and private report custody.