A standing offer to pay researchers who report vulnerabilities through a defined disclosure process.
Why it matters
It changes the economics at the margin: a researcher who finds a flaw has a lawful, paid route that competes with the alternative. It also gives a project something an audit cannot — continuous coverage of code as it changes, rather than a snapshot of one commit.
What you can check
A bounty is meaningful in proportion to its terms: the maximum payout against the value actually at risk, whether the scope covers deployed contracts or only the repository, and whether there is a published safe-harbour commitment not to pursue good-faith researchers.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.