Bug-bounty / vuln-report triage

Triage teams are drowning in
AI-generated vuln reports.

Submit a binary and a bounty report. groundre verifies its technical claims about the binary deterministically — is the cited address real and reachable? is the primitive present? — then maps the verdicts to an evidence-backed PAY / REVIEW / REJECT recommendation. No LLM grades the report. Binary/native reports only (firmware, IoT, compiled C/C++) — not web/source bugs.

1 · The samplebinary the report is about
ELF / PE / Mach-O. The sample never leaves the sandbox.
Loads a bundled sample + a report mixing true and planted-wrong claims, then runs the real verify flow.
2 · The reportJSON claims or prose
The triage gap. Platforms today route reports through human triagers or an LLM judge — the same class of model that writes the AI slop. groundre adds the missing layer: deterministic, binary-level verification of the report's factual claims, so "the bug is at 0xdeadbeef" is checked against the real binary before anyone spends time on it.