I think there is a model, some traceability, RoE etc for HackerOne(which seems to be the Uber of pen test companies - but you only pay if they get you there), doubt gov, sneakey sneaky beakies etc will be able to use them... and isn’t the “hit me”covered by having a service up, users browsing, having some capital/value or being of interest to one or more sides aforementioned sneaky beakies?