AXUM SEC Beta Launches in 10 Days

Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.

AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.
Axum SEC Logo
Back to documentation
PlatformPlatformPrograms

Program models

Version 1.04 min readLast updated September 23, 2026

The nine program models available on AXUM SEC, what each one is for, and how to choose between them.

A program model is the contract between your organisation and the people testing it: who may test, what they may test, how findings are rewarded, and how much of the process is public. AXUM SEC supports nine models, and they can run in parallel against the same scope.

Choosing a model

Three questions usually settle it:

  1. Do you need depth or breadth? Scheduled depth with evidence for auditors points at expert-led engagement. Continuous breadth across a wide attack surface points at the crowd.
  2. Are you ready to pay for findings? If not yet, start with disclosure. It establishes a safe inbound channel and measurable response habits before money is involved.
  3. How sensitive is the target? The more sensitive the asset, the more vetting, NDA coverage and invitation control the model needs.

The nine models

ModelWho testsRewardTypical use
Vulnerability Disclosure Program (VDP)Anyone who follows the policyRecognition onlyStanding safe channel for unsolicited reports
Responsible Disclosure ProgramAnyone who follows the policy, with a formal coordination processRecognition, sometimes discretionaryOrganisations that need defined timelines and legal safe harbour
Private Bug Bounty ProgramInvited researchers onlyPer validated findingSensitive targets, or a first bounty before going public
Hybrid Bug Bounty ProgramA core of invited researchers, opening to a wider audience in phasesPer validated findingManaged growth of a program's audience
Ad Hoc Bug Bounty ProgramInvited researchers, on demandPer validated findingA specific release, migration or new surface
Time-Limited Bug Bounty ProgramDefined audience, defined windowPer validated findingLaunch events, compliance deadlines, conference timing
Challenges and ContestsDefined audience, competitive formatPrizes or leaderboard-based rewardsTargeted problems, recruiting, community engagement
Crowdsourced Security TestingVetted community, structured engagementPer validated finding or tieredContinuous testing with more control than an open bounty
PTaaS EngagementCertified experts, named testersFixed, tiered or subscriptionScheduled depth, compliance evidence, complex targets

What every model shares

Whichever model you choose, the operational machinery is the same:

  • Scope definition — in-scope and out-of-scope assets, grouped by type, tier and priority.
  • Rules and governance — engagement policy, participation requirements, approval queues and conflict handling.
  • Researcher or expert onboarding — invitations, policy acceptance, NDA acceptance where required, and participation status.
  • Communications — program-level announcements, realtime chat and retained history.
  • Report handling — classification, duplicate checks, reviewer guidance and lifecycle state.
  • Remediation tracking — tasks, ownership, deadlines and proof of closure.
  • Financial controls — budget allocation, reward workflow and metered consumption where relevant.
  • Security controls — centralised authentication, role-based access and controlled evidence handling.

Because the machinery is shared, moving from a VDP to a bounty program — or adding expert engagements later — does not mean rebuilding your process.

Combining models

Most mature programs use more than one:

  • A VDP runs permanently as the inbound channel for anything reported outside an active program.
  • A private bounty covers high-value assets continuously with a controlled audience.
  • An ad hoc or time-limited bounty is opened when a new surface ships.
  • A PTaaS engagement sits on the calendar for scheduled depth, compliance evidence and retesting.

All of them read from the same scope definition, so a target added once is covered by every active model.

Availability and limits

  • Private researcher access is Professional-tier; advanced researcher vetting and dedicated tester pools are Enterprise-tier.
  • Custom severity scoring, custom disclosure timelines and SLA response guarantees are Enterprise-tier. Default models and SLAs are available on lower tiers.
  • Program models describe how testing is organised. They do not by themselves constitute legal advice on disclosure policy — that should be reviewed by your counsel.

Related in Programs