Websites & Web Apps
Assess common application weaknesses, authentication controls, access controls and security configuration.
OreFX Studios
Start assessment ↗
OreFX Studios performs controlled, permission-based security assessments to help teams discover vulnerabilities, understand the risk, and fix what matters.
We work within an agreed scope, document what we test, and turn findings into practical remediation guidance. No unauthorized access. No vague reports. Just a controlled test with a clear outcome.
Assess common application weaknesses, authentication controls, access controls and security configuration.
Review application behavior and security boundaries under an agreed testing scope.
Check exposed services, configuration, hardening and other authorized attack surfaces.
Evaluate API endpoints, authorization, validation and security controls within the approved scope.
Assess selected infrastructure components and identify practical security improvements.
We define ownership, targets, timing, permitted techniques and testing boundaries before anything begins.
Our team performs authorized security testing designed to identify meaningful weaknesses without unnecessary disruption.
We document qualifying findings, their impact and the evidence needed to understand the issue.
You receive clear recommendations so your team can prioritize fixes and improve resilience.
OreFX only tests systems when the owner has explicitly authorized the assessment.
Every engagement has a defined scope and agreed rules. Unauthorized hacking, credential theft, disruption, persistence, or access to systems outside the approved scope is not part of the service.
OreFX uses a vulnerability-based reward model. If a qualifying finding is discovered, payment follows the reward or contract agreed before testing begins.
Qualifying findings in scope
DC$20,000+
Per authorized host assessment
DC$20,000+
Web, mobile & API targets
DC$20,000+
All testing requires explicit authorization. We only test systems you own or have permission to test. Payout terms are agreed in writing before testing begins.
OreFX only tests systems that you own or for which you hold explicit written permission. By requesting an assessment you certify that you are authorized to authorize testing of the target you provide.
Every engagement defines the targets, timing, permitted techniques and boundaries in writing before testing begins. We test only the approved scope and do not extend beyond it without your written agreement.
OreFX uses a vulnerability-based reward model. Rewards follow the published rate table and the amount is agreed in writing before testing begins. Payment is due for qualifying, verified findings only, as defined in the engagement contract.
Findings, reports, target details and any client information are kept confidential. Nothing is published or shared with third parties without your written consent, including after the engagement ends.
Qualifying findings are documented with impact and the evidence needed to understand them. You receive clear remediation guidance so your team can prioritize fixes.
An authorized assessment reduces but does not eliminate risk. OreFX is not liable for issues outside the approved scope, and no engagement is a guarantee of absolute security. Testing is performed on a best-efforts basis within the agreed rules.
Either party may terminate an engagement in accordance with the agreed contract. Work already performed up to the date of termination is documented and settled as agreed.
We use the details you provide (name, contact, target) solely to run and communicate about the requested service. We do not sell or share them beyond what is required to deliver the engagement.
Test only the systems listed in your approved scope. Never expand scope, probe adjacent systems, or test targets that are not explicitly agreed — doing so ends the engagement.
Credential theft, data exfiltration, persistence, disruption, or any technique outside the agreed rules is prohibited. Unauthorized hacking, fraud or illegal activity is not part of the service and may be reported.
All testing is performed professionally and documented. Findings are reported privately to the client first; public disclosure happens only with written permission and after the issue is resolved.
All requests go through the contact form or an approved ticket channel. Include your name, a reliable contact, the target, and confirmation that you are authorized to request testing.
Only qualifying, verified findings within the approved scope are eligible for rewards. Informational or out-of-scope findings may be reported but are not guaranteed a payout.
Do not use the platform to request testing of systems you do not own, to file fraudulent claims, or to misuse the service in any way. Violations terminate the engagement and may be reported to relevant authorities.
You agree to comply with all applicable laws governing the systems you ask us to test. By engaging OreFX you confirm you understand and accept these rules.
Questions, scope details or a request to test — the fastest way to reach OreFX is through the Discord server. Open a ticket and we'll take it from there.
Join the server ↗