Public, private and hybrid programs
Open to everyone, invitation-only for sensitive targets, or phased with a core of trusted researchers opening to a wider audience.
AXUM SEC Beta Launches in 10 Days
Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.
Continuous discovery
Unlimited testers against a scope you control. Open a public program, invite a private audience under NDA, or phase the rollout — and pay for validated findings rather than billed hours.
Custom severity scoring, advanced researcher vetting and dedicated tester pools are Enterprise-tier capabilities.
Continuous coverage across the attack surface you defined, with the operational controls to keep it manageable.
Testing runs between scheduled engagements instead of pausing after a pentest.
Choose the audience and grow it when the program is ready.
Rewards follow validated, priced findings — not retainer hours.
Align payouts with your own risk model rather than a vendor default.
Capabilities
A bounty program is easy to launch and hard to run well. These are the controls that decide whether it produces signal or noise.
Open to everyone, invitation-only for sensitive targets, or phased with a core of trusted researchers opening to a wider audience.
Invite trusted researchers under NDA with controlled, higher-quality submissions on assets you would rather not expose publicly.
Advanced vetting controls for sensitive programs, so participation is a decision rather than a default.
Weight the platform’s scoring with your own risk model so a reward reflects business impact, not only a generic reading.
Public recognition that gives researchers a reason to return, and gives your program a visible track record.
Contributor quality tracked over time, with historical reporting across programs so trends are visible rather than anecdotal.
The quality of a bounty program is decided before the first submission arrives. These are the settings worth getting right.
The operational details program owners ask about first.
Lifecycle
The same pipeline runs every submission, so expectations on both sides stay predictable.
Choose the model, set scope, severity bands and rules of engagement. Reuse it for every cycle.
Go public, invite a private group under NDA, or phase the rollout with a trusted core.
Submissions are acknowledged automatically, classified, checked for duplicates and validated.
Validated findings are priced against the severity model and recorded against the budget.
The fix is tracked to closure and, where the program requires it, confirmed by a retest.
Coordinated disclosure, advisories and recognition happen on the same record.
Documentation
Scope modelling, triage states and reward mechanics are documented in full.
How targets, severity tiers and testing boundaries are modelled and enforced.
Read the docThe states a submission moves through, and how overlap is resolved.
Read the docWhat rewarding researchers involves, from verification to settlement.
Read the docCommon questions
Start with scope and rules of engagement, open a private audience, and grow from there. We will help you set the severity bands before the first submission arrives.