AXUM SEC Beta Launches in 10 Days

Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.

AI Agents Coming Soon— AXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.AI Agents Coming Soon— AXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.
Axum SEC Logo
Crowd-sourced

Continuous discovery

Bug bounty, priced by valid findings

Unlimited testers against a scope you control. Open a public program, invite a private audience under NDA, or phase the rollout — and pay for validated findings rather than billed hours.

Custom severity scoring, advanced researcher vetting and dedicated tester pools are Enterprise-tier capabilities.

Platform viewLive
  • Submittednew
  • Triagedvalid
  • Duplicate checkclear
  • Rewardapproved

What you get from the crowd

Continuous coverage across the attack surface you defined, with the operational controls to keep it manageable.

Coverage model
Continuous

Testing runs between scheduled engagements instead of pausing after a pentest.

Program shapes
Public, private, hybrid

Choose the audience and grow it when the program is ready.

Commercial model
Per finding

Rewards follow validated, priced findings — not retainer hours.

Severity bands
Customisable

Align payouts with your own risk model rather than a vendor default.

Capabilities

Built for programs that have to stay manageable

A bounty program is easy to launch and hard to run well. These are the controls that decide whether it produces signal or noise.

Public, private and hybrid programs

Open to everyone, invitation-only for sensitive targets, or phased with a core of trusted researchers opening to a wider audience.

Private researcher access

Invite trusted researchers under NDA with controlled, higher-quality submissions on assets you would rather not expose publicly.

Researcher vetting

Advanced vetting controls for sensitive programs, so participation is a decision rather than a default.

Custom severity scoring

Weight the platform’s scoring with your own risk model so a reward reflects business impact, not only a generic reading.

Hall of fame and leaderboards

Public recognition that gives researchers a reason to return, and gives your program a visible track record.

Reputation and analytics

Contributor quality tracked over time, with historical reporting across programs so trends are visible rather than anecdotal.

Scope and rules come first

The quality of a bounty program is decided before the first submission arrives. These are the settings worth getting right.

  • Define in-scope and out-of-scope assets, grouped by type, tier and priority.
  • Attach rate limits, test accounts and testing windows to the asset they belong to.
  • Publish the out-of-scope list — exclusions save triage time and prevent disputes.
  • Set reward bands per severity tier, and review them after each cycle.
  • State evidence expectations: ask for the smallest artefact that proves the issue.
  • Publish response timelines so researchers know what to expect and when.

Program mechanics

The operational details program owners ask about first.

Reward basis
Per validated finding, priced against the program’s severity bands.
Payout timing
On-demand runs or scheduled cycles, with thresholds and per-method minimums.
Duplicate handling
Merge, mark with attribution, or split rewards according to the published policy.
Disclosure
Coordinated timelines configured per program, with safe harbour language in the policy.
Reporting
Program-level analytics, historical trends and an attributable audit trail.
Automation
Assisted classification and semantic duplicate alerts at submission time (Professional tier).

Lifecycle

From launch to verified fix

The same pipeline runs every submission, so expectations on both sides stay predictable.

  1. 01

    Define the program

    Choose the model, set scope, severity bands and rules of engagement. Reuse it for every cycle.

  2. 02

    Open the audience

    Go public, invite a private group under NDA, or phase the rollout with a trusted core.

  3. 03

    Receive and triage

    Submissions are acknowledged automatically, classified, checked for duplicates and validated.

  4. 04

    Reward and record

    Validated findings are priced against the severity model and recorded against the budget.

  5. 05

    Remediate and verify

    The fix is tracked to closure and, where the program requires it, confirmed by a retest.

  6. 06

    Disclose and report

    Coordinated disclosure, advisories and recognition happen on the same record.

Documentation

Running the program, in detail

Scope modelling, triage states and reward mechanics are documented in full.

Scope and rules of engagement

How targets, severity tiers and testing boundaries are modelled and enforced.

Read the doc

Triage pipeline

The states a submission moves through, and how overlap is resolved.

Read the doc

Payouts and KYC

What rewarding researchers involves, from verification to settlement.

Read the doc

Common questions

Bug bounty questions we hear most

How do we keep a public program from becoming unmanageable?
By starting private or hybrid, publishing a precise out-of-scope list, and letting assisted classification and duplicate detection absorb the first pass. Most programs grow their audience once triage volume is predictable.
What stops us paying twice for the same bug?
Semantic duplicate detection flags likely repeats at submission time, and the platform supports merge, duplicate-with-attribution and reward-split policies. Attribution decisions stay with a human reviewer.
Do researchers see our environment details?
Only what the program publishes. Scope is explicit, evidence is stored under access control, and researcher identity can be withheld from engineering-facing tickets.
Can we run a bounty and an expert engagement at the same time?
Yes — that is the point of a shared scope model. Both models read the same target definitions, tiers and rules, so adding one does not duplicate the other.

Launch a program your team can actually run.

Start with scope and rules of engagement, open a private audience, and grow from there. We will help you set the severity bands before the first submission arrives.