Last update on: 01/01/2026
1. Objective and Economic Interest
Plakar SAS is dedicated to developing a secure, open-source, and highly versatile data resilience ecosystem. This program is designed to incentivize the global development and security community to actively contribute to the Plakar ecosystem. By rewarding targeted feature implementations and high-impact vulnerability discoveries, we aim to accelerate our roadmap and maintain world-class security standards.
The economic and strategic interests of this program include:
- Accelerating Feature Innovation: Expanding Plakar utility by encouraging the community to build specific capabilities and integration packages.
- Optimizing Engineering Costs: Leveraging global developer talent to scale development efficiently across our public open-source repositories and related dependencies.
- Enhancing Security and Resilience: Identifying and resolving software vulnerabilities proactively before they can affect our users.
- Community Enrichment: Building a highly engaged ecosystem of open-source contributors, independent developers, and security researchers.
2. Technical Scope and Eligibility Rules
This program is open to individuals and legal entities worldwide, with the strict exception of individuals residing in, or legal entities established in, countries or territories subject to European Union (EU) or French economic sanctions, trade embargoes, or comprehensive financial restrictions. Furthermore, any individual or entity listed on official EU or French asset-freeze and international sanctions registries is strictly ineligible to participate or receive financial rewards.
Program Exclusions
Employees of Plakar SAS, as well as freelancers, independent contractors, or consultants currently under active contract or agreement with Plakar SAS, are strictly excluded from participating in this program and are not eligible to receive any financial rewards or public recognition under this policy.
Reward Eligibility Rules
- Security Scope: Financial rewards are strictly limited to vulnerabilities classified as Critical or High based on standard metrics. Lower severity findings (Medium or Low) do not qualify for financial payouts but receive public recognition and thanks.
- Features and Integrations Scope: Financial rewards are strictly limited to the specific development tasks, features, and integration packages listed in the official Plakar Bounty Roadmap on our website (the Bounty Roadmap). Unlisted feature suggestions do not qualify for financial payouts.
- Upstream and Downstream Projects: Certain development tasks targeting approved upstream or downstream open-source projects are eligible for rewards, provided they are explicitly framed and listed within the official Bounty Roadmap on our website (the Bounty Roadmap).
- Precedence of the Official Roadmap: The official Bounty Roadmap on the Plakar website (the Bounty Roadmap) takes precedence and dictates the definitive payout amounts if any discrepancy arises with the general ranges announced in this policy.
- Licensing Requirement: All contributions (including source code, documentation, and integration packages) must be submitted under the same open-source license as the respective target Plakar repository. By participating in this program, contributors explicitly agree to license their work under these terms.
Safe Harbor (Legal Sanctuary)
Plakar SAS values the work of security researchers who help protect our users. If you conduct your security research and vulnerability disclosure activities in strict accordance with the rules, scope, and restrictions outlined in this policy, Plakar SAS considers your research to be authorized.
Plakar SAS formally commits not to initiate legal actions, civil lawsuits, or criminal complaints against you regarding your research. This safe harbor explicitly covers potential claims under French penal code provisions regarding fraudulent access, tampering, or remaining within an automated data processing system.
General Participation Criteria
- Participants must act in good faith and follow responsible disclosure practices.
- Feature contributions must align with Plakar architectural guidelines and pass code quality reviews.
- For security vulnerabilities, public disclosure without explicit prior authorization from Plakar SAS is strictly prohibited and results in immediate disqualification.
3. Submission and Evaluation Procedure
To maintain transparency and satisfy corporate accounting requirements under French law, all submissions must follow a structured validation workflow.
For Feature Contributions and Integrations
-
Notification: Before starting work on a feature or integration, you must write to bounty@plakar.io with a short functional outline, or a draft issue, naming the item you intend to take from the Bounty Roadmap. We confirm that the item is eligible, that your approach fits, and agree the reward with you before any code is written. Plakar SAS does not grant exclusivity: several contributors may work on the same item independently, and the reward goes to whoever lands first.
-
Implementation: Develop in a repository you own, referencing the targeted item from the Bounty Roadmap in your commits and description.
-
Review and Merge: Open a pull request against the relevant Plakar repository. The maintainer team reviews it against our architectural guidelines and code quality standards. Expect review comments, and expect to address them; an agreed reward does not commit us to merging work that does not meet those standards.
-
Claim: Once your pull request is approved and merged, claim the reward by writing to bounty@plakar.io. The reward is attributed strictly to the first valid, complete, and merged pull request for that item.
Unsolicited pull requests against roadmap items are welcome as contributions, but carry no reward: we do not pay for code we did not agree to in advance.
For Bug and Vulnerability Reports
-
Notification: Verify that the issue affects users within the limits of our threat model. If it does, write to security@plakar.io and summarize what you found and what it allows (for example: “I found an issue that lets me do X without holding Y”). Give us only what we need to gauge the severity and decide whether the issue is worth investigating — no details and no reproducer at this stage.
-
Triage: Our team will come back to you within five business days. We will either explain why the details are not needed — the issue may be a duplicate, already fixed, or awaiting a bugfix release — or open an exchange and ask you for a full description and reproduction steps so we can confirm the issue is legitimate.
-
Exchange: Once the submission is confirmed, we assign a severity against CVSS and agree any reward with you directly. Critical and High findings are eligible for a financial reward; Medium and Low findings receive public recognition and our thanks. We will keep you involved through analysis and remediation, coordinate disclosure with you, and credit you when the fix is published, unless you would rather we did not.
Public disclosure before we have explicitly authorized it remains strictly prohibited at every stage and results in immediate disqualification.
Corporate Record Keeping
Plakar SAS permanently retains all technical exchanges, feature specifications, vulnerability reports, and reward decisions. Under French legal frameworks, this documentation is mandatory to justify corporate expenses and confirm the reality of the services delivered to the company.
4. Rewards
Plakar pays for two kinds of contribution: security vulnerabilities, and the development tasks listed on our official Bounty Roadmap on the Plakar website (the Bounty Roadmap). Both programs are active and funded. For development tasks, the roadmap remains the final authority on which tasks are eligible.
What we no longer publish are the payout figures.
We used to, and the tables turned out to be an excellent magnet for automated, LLM-generated submissions. They look credible at first glance, they cite real function names from our codebase, they use the right vocabulary, they arrive pre-formatted to look like the thing we asked for. On examination they collapse. Every one of them still cost us a real review, done by the same small team that builds Plakar, and the volume became untenable. So the numbers are gone: not crawled, not scraped, not usable as a price list to aim a bot at.
The consequence for anyone contributing in good faith is small. Talk to us first, in both programs, and we agree the amount with you directly.
Security Vulnerability Rewards
The bogus reports followed recurring patterns: severity inflation (a minor bug filed as critical), threat models that require the victim to actively cooperate with the attacker (install a malicious plugin the attacker wrote themselves), and, in one case we still think about, an attack on a repository by someone who did not hold the key … demonstrated by using the key to decrypt part of the repository.
If you have found a vulnerability, write to security@plakar.io with a brief description of the issue and a working reproduction: the exact steps, commands, or code that demonstrate the flaw against a real Plakar setup. A report without a reproduction we can run is not something we can evaluate, and we will not chase one down for you. We will first confirm we are talking to a human, then assess the finding on its merits and discuss compensation with you if it is legitimate. Severity is still evaluated against CVSS, and critical and high findings are still rewarded, we simply do that assessment with you rather than advertising the numbers to crawlers.
Feature and Integration Rewards
Two categories are eligible, and only for tasks explicitly listed on the Bounty Roadmap:
- Integration: a full, turnkey Integration Package, providing source, destination and storage connectors for an enterprise system listed on the roadmap.
- Feature: architectural components, performance optimizations, or functional tools listed on the roadmap, including listed upstream and downstream project developments.
Amounts depend on the difficulty of the specific task and are agreed before you start, not after you submit. Claim the task by writing to bounty@plakar.io with the roadmap item you want, a short outline of how you intend to implement it, and enough about yourself for us to establish we are talking to a human. We will confirm the task is unclaimed, agree the reward with you, and only then do you write any code.
Unsolicited pull requests against roadmap items are welcome as contributions but carry no reward. We do not pay for code we did not agree to in advance, which is the only defence we have found against generated submissions that pattern-match a roadmap entry without implementing it.
5. Invoicing, Payout, and Tax Compliance
All financial rewards are processed and paid from France by Plakar SAS. Payout workflows depend strictly on the legal and tax status of the beneficiary.
General Payout Conditions
- Payment Timeframe: Validated rewards will be executed via bank wire transfer within 30 days following the formal approval and validation of the commercial invoice or the individual signed certificate.
- Transfer Fees: Plakar SAS will absorb all standard bank wire transfer fees associated with processing and issuing the bounty payout.
For Registered Businesses and Freelancers
If you participate as a company, sole trader, or registered freelancer, you must issue a valid commercial invoice before payment can be executed.
- Invoice Details: Invoices must be addressed to Plakar SAS (149 avenue du Maine, 75014 Paris, France, RCS Paris 933 509 754).
- Value Added Tax (VAT):
- French entities must include the standard French VAT.
- European Union entities (outside France) must utilize the reverse charge mechanism and display their intra-community VAT number.
- International entities outside the European Union must invoice without VAT, in compliance with applicable export regulations.
For Private Individuals
If you participate as an individual contributor without a registered business, the payout is processed under non-commercial corporate expense guidelines.
- Accounting Treatment: The payout is handled as a gross corporate charge (TTC). Plakar SAS cannot deduct or recover VAT on this transaction.
- Mandatory Certificate (Attestation): To receive the bounty payout, individual contributors must provide a signed certificate. The template provided in Appendix A must be fully completed and signed. No funds will be wired without this valid document.
- Tax Responsibility: This reward constitutes taxable income for the recipient. The beneficiary is explicitly informed that they are solely responsible for declaring this income to their local tax authorities. Plakar SAS will issue a payment confirmation document upon request to support individual tax declarations.
Appendix A: Honor Certificate Template for Individuals
Please send this completed and signed document to accounting@plakar.io with a copy to bounty@plakar.io when claiming your reward.
Subject: Statement of Honor regarding the Plakar Bounty Program Payout
I, the undersigned:
- Full Name: [Your first and last name]
- Date of Birth: [DD/MM/YYYY]
- Primary Tax Residence Address: [Your full address, Postal Code, City, Country]
- Contact Email Address: [Your email address]
Directly concerning the following contribution:
- Reward Object / Contribution Reference: [Specify the merged Pull Request URL, the internal bounty entry URL on the Plakar website (for example the Bounty Roadmap with the relevant item or anchor), or a validated Vulnerability ID]
- Approved Reward Amount: [Specify the exact amount, e.g., €500]
Declares on my honor the following statements:
- I am participating in the Plakar SAS bounty program as a private individual (natural person) and not under any registered professional structure or commercial enterprise.
- I certify that I do not hold any VAT-registered status or self-employed registration related to the development or activity of the rewarded contribution.
- I acknowledge that I have been formally informed that the bounty reward paid by Plakar SAS for the specified contribution and approved amount constitutes taxable income in my country of tax residence.
- I certify that it is my sole and complete responsibility to declare the entirety of this income to the competent tax authorities of my place of residence.
- I certify that the banking information provided for the wire transfer (IBAN/BIC or international account details) is accurate and belongs to a bank account opened under my own name.
In witness whereof, I provide this statement to serve and be used where applicable.
Signed at: [Your City]
On: [Current Date]
Signature of the Beneficiary: [Your Signature]