Payouts and KYC
Researcher onboarding tiers, payout channels, thresholds, cycles, currency conversion and what the researcher sees before being paid.
Paying researchers internationally is the part of running a bounty program that most often stalls — usually in finance, not in security. This document covers how identity verification and payouts are handled.
KYC tiers
Verification is progressive, so a researcher is not asked for everything on day one:
| Tier | What is verified | Why |
|---|---|---|
| Tier 1 | Email and phone | Account integrity, basic contactability |
| Tier 2 | Government ID and proof of residence | Identity and determination of tax residency |
| Tier 3 | Payout method details | Where the money is sent, in whose name |
A researcher can submit findings from Tier 1, but a payout requires the tiers that the payout method and jurisdiction demand. Identity data is access-controlled and minimised in responses.
Payout channels
Researchers choose the channel that works in their country:
| Channel | Options |
|---|---|
| Digital wallets | PayPal, Payoneer, Skrill |
| Local bank transfer | ACH (US), SEPA (EU) |
| International wire | SWIFT with BIC/IBAN |
| Cryptocurrency | USDT (TRC-20/ERC-20), USDC, Bitcoin |
Channel availability depends on the researcher's country and the tier of the program. A channel that is unavailable is not offered, rather than offered and then failing.
Thresholds and cycles
- Minimum payout thresholds — a global minimum plus per-channel minimums, so a channel's fixed cost does not exceed the reward.
- Payout cycles — on-demand runs, or scheduled cycles (weekly, monthly) that batch rewards together.
- Queued rewards — approved rewards wait in a queue that the finance team can inspect before a run executes.
- Batch execution — a run is executed as a batch with a per-item result, so a single failure does not lose the rest.
Automatic payout execution is Professional-tier; lower tiers execute runs manually from the same queue.
Currency conversion
- Rewards are priced in the program currency and paid in the researcher's chosen currency.
- Conversion uses real-time rates at execution time.
- Fees are disclosed per channel, and conversion is shown as a separate line rather than folded into a net figure.
What the researcher sees
A payout is a calculation, and the calculation is shown before money moves:
- Gross reward — the agreed amount for the finding.
- Platform fees — where applicable, shown explicitly.
- Withholding — the amount withheld for the researcher's jurisdiction, with the rate applied.
- Net payable — what will actually arrive.
- Status — queued, processing, paid or failed, with the failure reason where one exists.
Explaining the calculation up front removes most payout disputes before they start.
When a payout fails
Payout failures are a normal part of international payments rather than an exception:
- The failure reason is recorded against the item and surfaced to the researcher.
- The reward returns to the queue rather than being lost, and the researcher can correct the payout method.
- Repeated failures on a channel surface to the finance team so the channel can be reviewed.
Availability and limits
- KYC tiers, payout channels, manual run execution and transparent calculation are available on all tiers.
- Automated payouts, compliance exports and historical analytics are Professional-tier.
- The platform performs withholding calculation, form generation and reporting workflows. It does not provide tax advice, and the customer remains responsible for its own compliance position.
Related docs
- Tax and reporting — forms, treaties and annual reporting
- Financial operations — budgets, wallets and metering
- Identity and access — how identity data is protected