Russian IT service provider RTK-TSOD has initiated a bug bounty program on the Standoff Bug Bounty platform developed by Positive Technologies. The initiative aims to enhance the protection and cyber resilience of the company’s information systems by engaging independent security researchers, according to a representative from Positive Technologies who spoke with CNews.
The program’s scope will cover publicly accessible IT services operated by RTK-TSOD. Client infrastructure remains explicitly outside the testing perimeter, with customer resources excluded from any security assessments. Researchers participating in the program will focus on discovering exploitable vulnerabilities that could lead to tangible damage, including privilege escalation, unauthorized data access, service disruption, or remote code execution.
How Will the Bug Bounty Program Be Structured?
Access to the bug bounty program will be limited initially to a select group of researchers occupying top positions in the Standoff Bug Bounty platform’s ranking system. Only registered specialists who have completed verification will be eligible to participate. The company plans a phased expansion over time to eventually include all registered security professionals on the platform.
Denis Poladyev, Director of Information Security at RTK-TSOD, explained the rationale behind the private launch format: ‘We are deliberately starting the bug bounty in a private format to limit the circle of participants to the most verified and qualified researchers. At the initial stage, the maximum payout for a discovered vulnerability will be up to 150 thousand rubles, depending on its criticality level. In the future, as the number of discovered errors decreases and we transition to open stages, we plan to increase rewards to maintain the program’s attractiveness.’
What Results Has the Platform Achieved?
Roman Prikhodko, Head of Standoff Bug Bounty, noted that the initiative represents an investment in digital product reliability and client trust. He referenced research data from the platform’s 2025 operations showing that 80% of participants in existing programs reported that bug bounty initiatives fully or partially met their expectations.
The Standoff Bug Bounty platform serves as a Russian marketplace for identifying vulnerabilities in corporate systems. More than 500 vulnerability discovery programs have been published on the platform, with total rewards exceeding 470 million rubles distributed to security researchers.
Source: CNews