Sudan's national channel for bug bounty & vulnerability disclosure.
Report security issues in government services, critical infrastructure, telecoms, and major Sudanese companies through one trusted channel. Coordinated by SCA Sudan under a unified national safe-harbor framework.
A single, accountable place to disclose security issues in Sudan.
Built and operated by SCA Sudan to give researchers a clear way to help, give organizations a way to receive help safely, and give the country a single source of truth on its cyber risk posture.
One national channel
No more guessing where to report. Every Sudanese government service, telecom, bank, and critical-infrastructure operator runs its program from the same trusted platform โ visible side by side at /programs.
Legal safe-harbor
Good-faith research that follows the program policy is shielded from prosecution under Sudan's coordinated disclosure framework. No surprise lawsuits, no chilling effect on legitimate testing.
Coordinated disclosure
Reports flow through a structured state machine: intake โ triage โ reproduction โ fix validation โ reward โ public advisory. Both sides see the same status, with full audit history.
Find issues. Earn recognition. Stay legal.
- Clear scope, response SLAs, and disclosure timelines on every program.
- Encrypted intake with attachment scanning and end-to-end audit trail.
- Hall-of-Fame credit and optional rewards (bounty programs).
- Multi-factor sign-in. Safe-harbor for good-faith research.
Run a national-grade VDP or bug bounty.
- Editable policy templates, in/out-of-scope assets, branded program page.
- Triage workflow built around the global ISO/IEC 29147 disclosure norm.
- VDP (no reward) or BBP (with reward bands in SDG, USD, EUR or USDT).
- Per-tenant RBAC, full audit, optional invitation-only privacy.
National visibility into cyber risk.
- SCA Sudan staff get cross-tenant visibility, audit, and incident escalation.
- Aggregate metrics by sector (telecom, banking, government, energy, transport).
- Coordinated advisory publication for systemic issues.
- Aligns with national cybersecurity strategy and CNI protection mandate.
From submission to public advisory in four stages.
Every report carries an audit chain. Both researcher and organization see the same state at the same time. SCA Sudan oversees timelines and escalates where SLAs slip.
- 1
Researcher submits
Pick a program, review scope and policy, file a report with reproducible steps and impact statement.
- 2
Triage & reproduce
Organization confirms the vulnerability, sets the final severity, and assigns an engineer.
- 3
Fix & validate
Engineer ships the fix, validator confirms remediation, optional reward is decided per band.
- 4
Coordinated disclosure
After the fix, SCA Sudan and the program publish a public advisory crediting the researcher.
Sudan Cybersecurity Authority
SCA Sudan is the federal body responsible for cybersecurity policy, critical-infrastructure protection, and national incident response. The Authority operates this platform as part of its mandate to provide a unified, accountable channel for coordinated vulnerability disclosure across the Republic.
Read more about SCA SudanProtect
Defend Sudan's critical national information infrastructure across telecom, energy, finance, government and transport.
Detect
Operate national threat-intelligence and incident-detection capabilities through SD-CERT and partner agencies.
Respond
Coordinate national-level incident response, including this CVD platform, alongside sectoral CSIRTs.
Build
Develop national cyber capability through workforce, research, and partnerships with OIC-CERT, AfricaCERT, and ITU.
Good-faith research is welcome and legally protected.
Common questions
Who can submit a vulnerability report?โพ
Anyone โ a Sudanese national or an international researcher. You need to register a researcher account and verify your email. National ID is collected for Sudanese citizens to enable reward payouts; international researchers can submit reports without disclosing national ID.
Is there always a financial reward?โพ
Not always. Programs choose between a Vulnerability Disclosure Program (VDP) โ recognition and Hall of Fame credit only โ or a Bug Bounty Program (BBP) with monetary rewards. The badge on each program card tells you which is which.
Will I get in legal trouble for testing?โพ
Not if you follow the program policy and the national safe-harbor terms: stay in scope, don't exfiltrate sensitive data, don't cause downtime, don't share the bug publicly before coordinated disclosure. SCA Sudan recognises this platform as the lawful channel for good-faith research.
What if the organization ignores my report?โพ
Every report has SLAs visible to both sides. If an organization misses its acknowledgement or response window, SCA Sudan staff can escalate. After the agreed disclosure window โ typically 90 days โ researchers may request coordinated public disclosure even without the org's consent.
Can my organization run a private (invite-only) program?โพ
Yes. Programs can be Public (listed for all researchers) or Private (invite-only). Sensitive sectors โ banking, government IDs, defence-adjacent โ typically start private and graduate to public over time.
How is severity determined?โพ
Researchers provide their own estimate. The organization sets the final severity during triage, optionally with a CVSS v3.1 vector. The program's severity cap on each asset (if set) bounds the final score for that asset.
Report a vulnerability
Pick a program, read its policy, and file a report with reproducible steps. Your submission is encrypted in transit and at rest.
Run a program
Onboard your organization, define scope and policy, and start receiving coordinated reports from Sudan's researcher community.