For companies

You have systemsto defend. Here iswhere to start.

Most companies arrive knowing they have a problem and not which product solves it. So this page is ordered the other way round: find the sentence below that sounds like your week, and it will tell you what to do next.

Find where to startRequest a proposal
Program consoleLive
Open reports7
Awaiting your review2
Avg. time to triage1.8 days
Bounties paid (YTD)$214,000

An illustration of the dashboard, not live platform data.

Start here

Which of these is you?

Three doors, and they lead to genuinely different places. Pick the one that matches your situation today — you can add the others later, and most teams eventually do.

We want researchers testing us continuously

You ship often, your surface moves weekly, and an annual test describes a version you have already replaced.

Publish a bug bounty program — public, private or disclosure-only — and pay per valid finding.

Bug bounty program →

We need a point-in-time test and a report

A customer, an auditor or an insurer wants third-party evidence with a named tester and a date on it.

Book a pentest or a full VAPT. You get a written report, an attestation letter, and a free retest.

Testing services →

We don't have a security team at all

There is nobody whose job this is, alerts fire into a channel nobody reads, and nothing is being monitored overnight.

Managed SOC gives you analyst coverage and tuned detection; Incident Response is there if it has already happened.

Managed defense →

Still not sure? See all ten services, or tell us the shape of it and we will scope it for you.

How a program runs

From publish to payout.

Every finding moves through the same five stages, in the same console, with a full timeline the researcher can read too.

  1. 01

    Publish

    Set scope, rules of engagement, eligibility and a severity-to-bounty table, then go live as a public, private or disclosure-only program.

    → A live program page

  2. 02

    Receive

    Structured reports arrive in your inbox — optionally pre-validated, classified and de-duplicated by our analysts first.

    → Triaged reports

  3. 03

    Fix

    Assign an owner, remediate, and track response and resolution against the SLA you published.

  4. 04

    Retest

    Request a retest from the report itself; the researcher confirms the fix and the thread records it.

    → Confirmed fix

  5. 05

    Reward

    Pay the bounty by severity. The award is tracked through approval to settlement, and the researcher's reputation updates.

    → Settled payout

What you get on day one

Everything you need to run testing responsibly.

01

Unambiguous scope

Define in-scope and out-of-scope assets and prohibited techniques on every program. Authorization is never left to guesswork.

02

Managed triage

Optional expert validation classifies findings and resolves duplicates and severity before they reach your team.

03

Remediation & SLAs

Assign owners, track response and resolution times, and request a retest from a single report view.

04

Program types

Run public, private or vulnerability-disclosure (VDP) programs, and switch as your maturity grows.

05

Researcher access

Invite verified researchers by skill and reputation, or open to the crowd — you control who can test.

06

Audit & compliance

Every decision is traceable with an immutable report timeline and exportable records.

Your first week

Signed up to first finding.

This is the actual onboarding path, not a description of one — these are the steps the product will walk you through, read from the same wizard you will see when you sign up.

  1. 01

    Create an account

    One form. You are a company account from the moment you sign up; there is nothing to request and nobody to wait for.

    → Account

  2. 02

    Organisation

    Who you are and what you build.

  3. 03

    Security contact

    Who answers a report.

  4. 04

    Launch a program

    Publish your scope and rewards.

    → A live program

  5. 05

    First report

    It arrives structured, in a thread you, the researcher and — if you want it — our analysts all read.

    → A finding to work

Inside step 3 — publishing a program

  1. 1. Basics
  2. 2. Scope
  3. 3. Rewards
  4. 4. Policy
  5. 5. Triage
  6. 6. Review

Six steps, each one resumable — the draft exists from the moment you start, so you can leave it and come back. Nothing is published until you review it at step six.

What it costs

Start free. Add triage when you need it.

VDP

Free

A disclosure channel for good-faith reports.

  • Public disclosure policy
  • Structured intake
  • Basic report workflow

Bounty

Usage

Pay bounties plus a platform fee on valid findings.

  • Public & private programs
  • Reputation-based invites
  • Remediation & retest

Managed

Custom

Everything in Bounty plus expert triage as a service.

  • Full managed triage
  • SLA reporting
  • Dedicated support

Full plan comparison and FAQ →

Talk to us

Security services, scoped to you.

You do not need to know which service you want. Tell us what you are protecting and what is driving the timing, and we will come back with a scope.

  1. 01

    You tell us the shape of it

    Assets, goals, and any deadline or compliance driver. Two minutes is enough.

  2. 02

    We scope it

    Our security team sizes the work and picks the right engagement — testing, a managed program, or both.

  3. 03

    You get a written proposal

    Deliverables, timeline and cost, usually inside one business day. No obligation.

Request a proposal1 business day

By submitting you agree to be contacted about your enquiry. We never share your details.

Publish your firstprogram this week.

Create an accountSee who is already here