AXUM SEC Beta Launches in 10 Days

Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.

AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.
Axum SEC Logo
Back to documentation
PlatformPlatformOverview

Platform overview

Version 1.04 min readLast updated September 23, 2026

How the AXUM SEC platform is put together — two testing engines, one control plane, and where each capability lives.

AXUM SEC runs two models of offensive security on one control plane: crowd-sourced discovery through bug bounty and disclosure programs, and expert-led testing through PTaaS engagements. This document explains the structure behind both, and which part of the platform does what.

The problem the structure solves

Security testing is usually bought piecemeal: an annual penetration test here, a bounty program there, spreadsheets in between, and a finance team reconciling global payouts by hand. Each tool solves one slice, so the coordination cost grows with every addition.

The platform is built around the opposite assumption: scoping, testing, triage, remediation, payment and disclosure are one lifecycle, and they should share one source of truth.

Two engines, one control plane

Crowd-sourcedExpert-led
ModelBug bounty, VDP, challenges and contestsPTaaS engagements
Who testsThe global researcher community, vetted per programCertified, invited experts
CoverageContinuous and broadScheduled, deep and structured
Best forBreadth, continuous assurance, long-tail classes of bugDepth, compliance evidence, complex or high-value targets
CommercialsPay per validated findingFixed, tiered or subscription

Both run against the same scope definition, the same triage pipeline and the same remediation trail. That is what makes the combination useful rather than duplicative: the crowd keeps testing between engagements, and experts produce the scheduled, defensible evidence that auditors and customers ask for.

What sits around the engines

Every program — crowd or expert — is supported by the same platform services:

  • Identity and access — standards-based token authentication, OAuth sign-in, TOTP multi-factor authentication, role-based access for every participant type, and session revocation.
  • Secure collaboration — an encrypted evidence store, malware scanning, in-app notifications, email notifications and realtime chat.
  • AI assistance — classification, duplicate detection, remediation guidance and report drafting applied to the parts of triage that do not scale by hiring.
  • Financial operations — multi-currency wallets, per-program and per-engagement budgets, subscription management, usage metering and invoicing.
  • Global payouts and tax — tiered KYC, payout channels in several rails, withholding calculation, digital tax forms and annual reporting workflows.
  • Integrations — Jira, GitHub, GitLab, Azure DevOps, Slack and Microsoft Teams, so remediation lands where engineering already works.

Program lifecycle in one timeline

  1. Create the program. Choose a program model, define scope, set reward tiers and rules of engagement, and invite collaborators.
  2. Onboard participants. Researchers accept the program policy; experts accept an NDA and receive scoped, time-limited credentials.
  3. Receive and triage submissions. Reports move through review, validation and duplicate checks, with every state change visible to the reporter.
  4. Reward and record. Valid findings are priced against the program's severity model, and the reward is recorded against the budget.
  5. Remediate and verify. The fix is tracked to closure and, where the program requires it, confirmed by a retest.
  6. Disclose and report. Coordinated disclosure, advisories and recognition happen on the same record, with an audit history that can be exported.

Where each capability lives

Customer-facing areaBacking capability
Program models, scope, tiers, rules of engagementProgram and engagement management
Crowd-sourced discoveryResearcher programs, submissions, reputation and leaderboards
Expert engagementsEngagement management plus expert identity, invitations and entitlement checks
Identity, MFA, roles, sessionsAuthentication and access decision service
AI triage, duplicate detection, remediation guidanceAI enrichment pipeline
Notifications, chat, disclosure workflowsMessaging and templating services
Wallets, budgets, subscriptions, incentives, invoicingFinancial operations service
Payouts, KYC, withholding, tax formsPayout, tax and reporting workflows
Encrypted evidence storage, malware scanningEncrypted file service with scanning and quarantine
API surface, authentication enforcement, rate limitingAPI gateway

These are service boundaries rather than marketing groups — "one platform" is a structural property, not a positioning line.

Availability and limits

  • Fine-grained role-based access control, MFA and audit trails are part of the platform's baseline security model.
  • Some capabilities are plan-dependent. Advanced researcher vetting, dedicated tester pools, custom severity scoring, threat modelling assistance and custom disclosure timelines are Enterprise-tier. Private researcher access, AI triage, duplicate intelligence, automated payouts, compliance exports, historical analytics, VPN access, source code review and retesting are Professional-tier.
  • The platform handles withholding calculation, form generation and reporting workflows; it does not replace your own tax or legal counsel.