HollowGround/how it works

How It Works

The Pipeline

Hollow Ground is an automated evidence-collection pipeline for authorized AI platform security research. Submit a request, we verify your authorization scope, and the pipeline exports a deterministic zip clone of the target workspace.

Step 1 — Submit Your Request

Provide your bug bounty handle, the target platform, and a link to your active program scope. We confirm authorization before any export begins.

Step 2 — Scope Verification

We cross-check your submission against the platform's published bug bounty scope. SoGood's program is open and publicly verifiable. Every clone requires an in-scope authorization — no exceptions.

Step 3 — Workspace Export

The automated pipeline exports the workspace state: conversation history, file attachments, integration configuration, and permission mappings. The output is a deterministic zip with a SHA-256 hash and a signed scope manifest.

Step 4 — Secure Delivery

You receive the zip file and manifest via the email you registered. The manifest records the platform, scope, researcher handle, and timestamp — everything your triage report needs.

What's in the Zip

  • Workspace state snapshot (JSON)
  • Conversation/session history export
  • File and attachment index
  • Integration and permission map
  • `manifest.json` — scope, authorization reference, SHA-256 hash, timestamp
  • Authorization

    Every export is tied to a specific bug bounty scope. We do not process requests for assets outside the published program scope. If a platform's program excludes a workspace type, we will reject the request and tell you why.

    Current authorized platforms: SoGood (open program, no invite required).

    Built with