Feed
Bounty Rolling

Sovereign Tech Resilience

Bug and fix bounties, code audits and direct contributions for open source infrastructure projects, paid by the Sovereign Tech Agency. Rolling applications.

Sovereign Tech Resilience is a program of the Sovereign Tech Agency, previously called the Bug Resilience Program. It has three components: direct contributions to open source projects, a bug and fix bounty program, and a code audit program.

The bug and fix bounty runs on the YesWeHack platform. The participating project defines the scope and fixes the vulnerabilities that are reported. YesWeHack helps invite security researchers and triage the reports. The Sovereign Tech Agency pays a bounty for each responsibly disclosed vulnerability report and a fix bounty to the project once the vulnerability is fixed. Current bounty programs cover systemd, Apache Log4j, Sequoia PGP, OpenPGP.js, ntpd-rs, CycloneDX Rust and Glib.

Direct contributions cover work such as reducing technical debt, triaging and fixing known issues, code reviews, style and contribution guides, better test coverage and release automation. Partners deliver this work after the scope is agreed with the maintainers. Code audits are offered through partners for widely used components; cURL, Jackson and LLVM take part.

The program is open to applications from open source infrastructure projects. Applications are reviewed on an ongoing basis against the program criteria. Eligible projects receive an invitation and are placed on a waiting list for the services they selected. Waiting time depends on current capacity.

Beyond the fix bounties, the agency does not pay compensation to participating projects. It pays the partners who provide the services.

Source · sovereign.tech/programs/resilience Published 3 September 2026 · Added here 8 September 2026