You have systemsto defend. Here iswhere to start.
Most companies arrive knowing they have a problem and not which product solves it. So this page is ordered the other way round: find the sentence below that sounds like your week, and it will tell you what to do next.
An illustration of the dashboard, not live platform data.
Which of these is you?
Three doors, and they lead to genuinely different places. Pick the one that matches your situation today — you can add the others later, and most teams eventually do.
We want researchers testing us continuously
You ship often, your surface moves weekly, and an annual test describes a version you have already replaced.
Publish a bug bounty program — public, private or disclosure-only — and pay per valid finding.
Bug bounty program →We need a point-in-time test and a report
A customer, an auditor or an insurer wants third-party evidence with a named tester and a date on it.
Book a pentest or a full VAPT. You get a written report, an attestation letter, and a free retest.
Testing services →We don't have a security team at all
There is nobody whose job this is, alerts fire into a channel nobody reads, and nothing is being monitored overnight.
Managed SOC gives you analyst coverage and tuned detection; Incident Response is there if it has already happened.
Managed defense →Still not sure? See all ten services, or tell us the shape of it and we will scope it for you.
From publish to payout.
Every finding moves through the same five stages, in the same console, with a full timeline the researcher can read too.
- 01
Publish
Set scope, rules of engagement, eligibility and a severity-to-bounty table, then go live as a public, private or disclosure-only program.
→ A live program page
- 02
Receive
Structured reports arrive in your inbox — optionally pre-validated, classified and de-duplicated by our analysts first.
→ Triaged reports
- 03
Fix
Assign an owner, remediate, and track response and resolution against the SLA you published.
- 04
Retest
Request a retest from the report itself; the researcher confirms the fix and the thread records it.
→ Confirmed fix
- 05
Reward
Pay the bounty by severity. The award is tracked through approval to settlement, and the researcher's reputation updates.
→ Settled payout
Everything you need to run testing responsibly.
01
Unambiguous scope
Define in-scope and out-of-scope assets and prohibited techniques on every program. Authorization is never left to guesswork.
02
Managed triage
Optional expert validation classifies findings and resolves duplicates and severity before they reach your team.
03
Remediation & SLAs
Assign owners, track response and resolution times, and request a retest from a single report view.
04
Program types
Run public, private or vulnerability-disclosure (VDP) programs, and switch as your maturity grows.
05
Researcher access
Invite verified researchers by skill and reputation, or open to the crowd — you control who can test.
06
Audit & compliance
Every decision is traceable with an immutable report timeline and exportable records.
Signed up to first finding.
This is the actual onboarding path, not a description of one — these are the steps the product will walk you through, read from the same wizard you will see when you sign up.
- 01
Create an account
One form. You are a company account from the moment you sign up; there is nothing to request and nobody to wait for.
→ Account
- 02
Organisation
Who you are and what you build.
- 03
Security contact
Who answers a report.
- 04
Launch a program
Publish your scope and rewards.
→ A live program
- 05
First report
It arrives structured, in a thread you, the researcher and — if you want it — our analysts all read.
→ A finding to work
Inside step 3 — publishing a program
- 1. Basics
- 2. Scope
- 3. Rewards
- 4. Policy
- 5. Triage
- 6. Review
Six steps, each one resumable — the draft exists from the moment you start, so you can leave it and come back. Nothing is published until you review it at step six.
Start free. Add triage when you need it.
VDP
FreeA disclosure channel for good-faith reports.
- Public disclosure policy
- Structured intake
- Basic report workflow
Bounty
UsagePay bounties plus a platform fee on valid findings.
- Public & private programs
- Reputation-based invites
- Remediation & retest
Managed
CustomEverything in Bounty plus expert triage as a service.
- Full managed triage
- SLA reporting
- Dedicated support
Security services, scoped to you.
You do not need to know which service you want. Tell us what you are protecting and what is driving the timing, and we will come back with a scope.
- 01
You tell us the shape of it
Assets, goals, and any deadline or compliance driver. Two minutes is enough.
- 02
We scope it
Our security team sizes the work and picks the right engagement — testing, a managed program, or both.
- 03
You get a written proposal
Deliverables, timeline and cost, usually inside one business day. No obligation.