On this page
Ai+ commits Rs 100 crore to five-year device-security bug bounty
Homegrown smartphone brand Ai+ launched Project Trust+, a Rs 100 crore bug bounty programme that will pay Rs 20 crore annually for five years to security researchers testing its devices and platforms.
One email each morning: the day’s top moves in Indian retail, why each matters and what to watch. Free. Stop any time.
The numbers
Figures from ET Small Business,
- Rs 965 crore first financial-year revenue
- More than Rs 7,500 crore revenue target in current fiscal year
Other figures
- 5 years
Why it matters for the brand
Project Trust+ could make Ai+ a more credible partner for platform, telecom and enterprise alliances by institutionalising security assurance across its devices and services.
What to track next
- First disclosed critical vulnerability and the number of days from report to patch availability.
- Actual annual bounty payouts, number of accepted reports and share of high-severity findings.
- Published security-update policy across Ai+ handset models and evidence that monthly or quarterly patches arrive on schedule.
- Researcher sentiment on payout fairness, response times and whether the programme accepts findings in third-party or preloaded software.
- Consumer-review mentions of privacy, security updates and trust versus mentions of bugs, bloatware or data permissions.
Show 2 more
- Whether competitors launch comparable bounty, longer-update-support or privacy-led initiatives.
- Ai+ revenue trajectory, handset sell-through, return rates and average selling price relative to the Rs 7,500 crore current-fiscal target.
Likely next moves
Our read of what comes next — analysis, not reported by the source.
- Publish a clear bounty scope covering devices, OS builds, preloaded apps, cloud accounts, payments and customer-data systems, with severity-based reward bands and safe-harbour rules.
- Commit to measurable patch-service levels by device tier, including critical-vulnerability remediation timelines and guaranteed security-update support periods.
- Release a public vulnerability disclosure dashboard showing reports received, valid findings, payout timing, fixes deployed and median remediation time.
- Use independent security audits and certifications to validate Project Trust+ rather than relying solely on self-reported programme activity.
- Train retail staff and incorporate update-support and device-security assurances into point-of-sale messaging, warranty materials and enterprise sales pitches.
Show 1 more
- Ring-fence the Rs 20 crore annual commitment so payouts are not reduced during margin pressure or aggressive handset expansion.
The counter-case
The case against this reading — not reported by the source.
The Rs 100 crore headline is a five-year ceiling, not evidence of immediate security capability or researcher participation. A bug-bounty programme can create reputational risk if payouts are slow, scope is restrictive, disclosures are disputed, or serious flaws are publicised before fixes reach users. For a price-sensitive smartphone entrant, the commitment could also become a marketing expense with limited impact on purchase decisions, while Rs 7,500 crore of current-fiscal revenue remains an ambitious target that security messaging alone will not validate.