Managed bug bounty triage
Keep your platform.Lose the noise.
Managed triage for bug bounty and vulnerability disclosure programmes. On HackerOne, Bugcrowd and comparable platforms, or on your own programme hosted directly on your site. Every report validated and reproduced, severity set in your context, researchers answered, and only confirmed vulnerabilities reaching your engineers.
The cost
What your queuecosts you today.
Count the last month of submissions. How many were valid? How many hours did an engineer spend reading the rest? How long did a researcher wait for an answer, and how many stopped submitting after that?
Every one of those is a cost you are already paying. None of them appear on an invoice.
Programmes
Works withany programme.
- Platform programmesHackerOne, Bugcrowd, Intigriti, YesWeHack and comparable platforms. The platform is where reports arrive. We take the queue from there and do the triage: validated, reproduced, deduplicated, and written up before anything reaches you.
- Self-hosted programmesA disclosure programme can run on your own site: a security.txt, a policy page, and reports arriving at an inbox with nobody owning them. We take that queue exactly the same way, through your inbox, ticketing system or a shared channel. No platform required, and no platform fee.
- Programmes you have not launched yetIf you are considering opening a programme, we can design the policy and scope, set the bounty table, and run it from the first submission, so it starts well rather than being fixed later.
The work
What we do.
Every incoming report is validated and reproduced against your environment. Severity is set in the context of your architecture and your risk appetite, not in the abstract. Researchers are answered, including the awkward conversations about duplicates and out of scope submissions. Bounties are awarded inside your published table. Only confirmed vulnerabilities reach your engineers, written up and ready to act on.
The pipeline
Many in. One out.
The deliverable
What each validreport arrives as.
Severity with justification. Clean reproduction steps. Impact in business terms. Fix guidance a developer can act on. Posted to one agreed channel or alias, and retested once you have fixed it.
SLA
Response targets.
| First response to a researcher | 1 business day |
|---|---|
| Triage decision | 2 business days |
| Critical and high validated | within 1 business day of arrival |
| Retest after fix | included |
These are our own commitments, held on UK business days, Monday to Friday, excluding English bank holidays.
If we miss a target, part of that month's fee is credited back.
In scope
Validation, reproduction, severity, researcher communication, bounty decisions within your published table, duplicate and out of scope handling, retest after the fix, and feedback on how the programme and its policy are holding up.
Where the boundary sits
Routing. We can file findings straight into your tracker, but that needs a level of access to your systems most clients would rather not grant an outside supplier. So by default every validated finding goes into one agreed channel, normally a single Slack channel or an email alias, and your team distributes it from there. If you would rather we filed directly, we will, once access is agreed.
What we do not do. Triage stops at the written-up finding. Running your remediation is not part of this service, and we do not offer round-the-clock monitoring, threat detection, a security operations centre or managed detection and response.
If you want help fixing them. We do that too, scoped and priced separately. Say so and we will quote it. It sits outside the monthly fee rather than quietly inside it, which is also what keeps the response times above honest.
That boundary is why the response times above are real. Our clock runs from the moment a report arrives to the moment a written-up finding reaches you. It does not depend on your release cycle, which we cannot control and will not pretend to.
Severity set with justification
Experience
Built from nothing.More than once.
Our people have designed, launched and run bug bounty and disclosure programmes from nothing for multiple organisations: the policy, the scope, the bounty table, the researcher relationships, and the day to day queue, through to handover once the client was ready to take it in house. We are still testing and still hunting bounties, so severity calls are made by people who find these bugs themselves.
If you are running a programme that has drifted, or thinking about opening one, we have done both before.
- Programme design, not just triage.Programme design, policy, scope, bounty table and researcher community, not only report triage.
- Carried the queue, not just the tickets.Day to day validation and the internal work of getting findings actually fixed, through to handover.
- Still testing.Active penetration testing and personal bug bounty hunting, so severity calls are made by people who find these bugs themselves.
Pricing
What it costs.
From £1,800 per month
scaled to your monthly submission volume, retest included. Priced in GBP, other currencies quoted on request. Exact pricing depends on how many submissions you receive each month.
If your programme is smaller than that, say so and we will tell you honestly whether this service is worth it to you.
Terms
Terms.
- A free two week pilot on your live queue.No charge, no obligation.Up to 25 reports, so we can give each one proper attention.
- We put something behind the targets.If we miss a response target, part of that month's fee is credited back.
Next
Once we knowyour stack.
Triage and testing fit together. After a few months on your queue we understand your architecture better than an external tester arriving cold, which makes the next penetration test faster and sharper.
Start
How to start.
A free two week pilot on your live queue. No charge, no obligation. You see the write-ups before you commit to anything. If it is not better than what you have, you have lost nothing.
Up to 25 reports, so we can give each one proper attention.
Questions
How is this different from the triage my platform already does?
We are the triage. Generic platform validation confirms a report looks valid in the abstract, without knowing your architecture, your risk appetite or which of your services matter. We take the raw queue, reproduce each report against your environment, rate it in your context, drop the duplicates and the out of scope noise, and hand your engineers only what is real and already written up.
Do we have to leave HackerOne or Bugcrowd?
No. Keep your platform. The platform is where reports arrive, and we take the queue from wherever it arrives: HackerOne, Bugcrowd, a comparable platform, or a security.txt and an inbox with nobody owning it. Nothing about your programme has to move.
Who talks to the researchers?
We do, all of it. Validation questions, requests for more detail, duplicate and out of scope decisions, and the bounty conversation. Your team never has to manage a researcher relationship or explain a rejection.
Who decides bounty amounts?
Bounties are awarded at validation, inside the table you have already published. Anything outside your published table comes to you for a decision rather than being decided on your behalf.
What are your response times?
First response to a researcher within one business day. Triage decision within two business days. Critical and high validated within one business day of arrival. Retest after the fix is included. Business days are Monday to Friday, UK, excluding English bank holidays. If we miss a target, part of that month's fee is credited back. These are our own commitments, not a platform's.
How do valid findings reach our engineers?
By default, into one agreed channel, normally a single Slack channel or an email alias: severity with justification, reproduction steps, business impact and fix guidance, and your team distributes from there. We can file straight into your tracker instead, but that needs a level of access to your systems most clients would rather not grant an outside supplier, so the single channel is the default. If you would rather we filed directly, we will, once access is agreed.
What does it cost?
From £1,800 per month, scaled to your monthly submission volume, with retest included. Exact pricing depends on how many submissions you receive each month. Priced in GBP, other currencies quoted on request. If your programme is smaller than that, say so and we will tell you honestly whether this service is worth it to you. Detail on enquiry.
How do we start?
A free two week pilot on your live queue. No charge, no obligation. Up to 25 reports, so we can give each one proper attention. You see the write-ups before you commit to anything. If it is not better than what you have, you have lost nothing.