Platform rules
What an invalid report costs on each platform
A report closed as invalid, N/A or spam can cost you reputation, credits, open submission slots, a deposit or the account. The table gives each platform’s rule, from its own pages, with the date we read it.
The rule on each platform
Programmes can add their own rules on top. Read the programme page before you submit.
| Platform | Closed as invalid or N/A | Spam, AI misuse or abuse |
|---|---|---|
| HackerOne | Closed as invalid or N/ANot Applicable: −5 reputation, and the same for a duplicate of an N/A report. When reputation drops, the platform limits how many reports you can submit over a set period. [1]A report is closed N/A when it is speculative, has no proof of concept, cannot be reproduced, rests on a video alone or shows no impact. [2] | Spam, AI misuse or abuseSpam: −10 reputation. [1]Large-scale submission of low-quality or unverified reports, including misuse of AI tools: a final warning, then a 12-month ban, then a permanent ban. A repeated pattern of inflated severity is a Code of Conduct violation. [2] |
| Bugcrowd | Closed as invalid or N/AManaged programmes: at most 5 open submissions at a time, unless the account has a proven record of quality. [3]10 or more invalid reports: identity verification before you can submit again. [4] | Spam, AI misuse or abuse10 or more invalid reports in a row: account review, and a possible 30-day suspension where they were AI-generated or automated without validation. Submission farming: a permanent ban. [4] |
| Intigriti | Closed as invalid or N/AOpen submissions are capped by the validity of your last 20: 1 below 20%, 3 from 20%, 5 from 40%, 7 from 60%, no cap from 80%. With 5 or fewer processed, the cap is 1. [5] | Spam, AI misuse or abuseReports that look like unverified AI output, or hold fabricated content or placeholder text, can be closed without response, take longer to validate, or lead to removal from the platform. AI use must be disclosed. [6] |
| YesWeHack | Closed as invalid or N/AEach programme sets a credit price per submission. A report closed as invalid, out of scope or N/A costs the price plus twice the price: three times the price in all. [7] | Spam, AI misuse or abuseSpam costs the price plus three times the price: four times in all. An accepted report pays back twice the price, plus a bonus by severity. [7] |
| Immunefi | Closed as invalid or N/AMisrepresenting the asset, the severity or the impact is prohibited: a temporary suspension or a permanent ban, loss of access to your reports and zero payout. [8] | Spam, AI misuse or abuseTesting on mainnet or a public testnet: an immediate and permanent ban. Spam, placeholder submissions, and AI or scanner reports without the impact on the asset are prohibited. [8] |
| Cantina | Closed as invalid or N/AWhere a bounty requires a deposit, a valid or a legitimate invalid submission gets it back. [9] | Spam, AI misuse or abuseSpam, low-effort or AI submissions, and an over-inflated severity: the deposit is slashed. Repeated abuse: slashed, with possible account action. [9] |
| Sherlock Audit Engine | Closed as invalid or N/AA dismissed issue counts 0 of 1 in your Issues Ratio, a submission cannot be withdrawn or edited, and each rewrite adds 0.5 to the count. No payout until the ratio is at least 20% and you have 2 valid findings. [10] | Spam, AI misuse or abuseNo separate rule on the page cited. |
What the rules ask of a report
Each line comes from the rules above. The free report check looks for all of them in a draft.
A proof on a local fork
Run it on a fork, and paste the command and its output into the report. Immunefi bans testing on mainnet or a public testnet, and HackerOne closes a report with no proof of concept.
One severity, argued
HackerOne treats a repeated pattern of inflated severity as a violation, Immunefi prohibits misrepresenting it, and Cantina slashes the deposit for it.
AI use stated
Intigriti requires you to disclose when and how AI was used. HackerOne, Bugcrowd and Intigriti hold you responsible for what an AI tool wrote.
No placeholder left
Intigriti names placeholder text as fabricated content, and Immunefi prohibits placeholder submissions.
Sources
Each number in the table points here.
- [1]HackerOne Help Center, “Reputation”dated 1 December 2025, checked 7 October 2026
- [2]HackerOne, “Code of Conduct”checked 7 October 2026
- [3]Bugcrowd Docs, “Submission Limits for MBB Programs”dated 4 May 2026, checked 7 October 2026
- [4]Bugcrowd, “Bugcrowd policy changes to address AI slop submissions”dated 10 March 2026, checked 7 October 2026
- [5]Intigriti Help Center, “Submission limits (open submissions)”dated 8 June 2026, checked 7 October 2026
- [6]Intigriti Help Center, “Community Code of Conduct”dated 9 March 2026, checked 7 October 2026
- [7]YesWeHack Help Center, “YesWeHack credits”checked 7 October 2026
- [8]Immunefi, “Rules”checked 7 October 2026
- [9]Cantina Documentation, “Deposits for Bounty Submissions”checked 7 October 2026
- [10]Sherlock Docs, “Audit Engine: For Participants”checked 7 October 2026
Check the draft before the triager does
The report check runs in your browser and sends nothing. The challenge runs on your own model and key. Free: 1 review a day.