Mandatory bug-bounties from major vendors

I can’t imagine letting a jury decide.

If it’s a weakness in a protocol, who pays?