Program models
The nine program models available on AXUM SEC, what each one is for, and how to choose between them.
A program model is the contract between your organisation and the people testing it: who may test, what they may test, how findings are rewarded, and how much of the process is public. AXUM SEC supports nine models, and they can run in parallel against the same scope.
Choosing a model
Three questions usually settle it:
- Do you need depth or breadth? Scheduled depth with evidence for auditors points at expert-led engagement. Continuous breadth across a wide attack surface points at the crowd.
- Are you ready to pay for findings? If not yet, start with disclosure. It establishes a safe inbound channel and measurable response habits before money is involved.
- How sensitive is the target? The more sensitive the asset, the more vetting, NDA coverage and invitation control the model needs.
The nine models
| Model | Who tests | Reward | Typical use |
|---|---|---|---|
| Vulnerability Disclosure Program (VDP) | Anyone who follows the policy | Recognition only | Standing safe channel for unsolicited reports |
| Responsible Disclosure Program | Anyone who follows the policy, with a formal coordination process | Recognition, sometimes discretionary | Organisations that need defined timelines and legal safe harbour |
| Private Bug Bounty Program | Invited researchers only | Per validated finding | Sensitive targets, or a first bounty before going public |
| Hybrid Bug Bounty Program | A core of invited researchers, opening to a wider audience in phases | Per validated finding | Managed growth of a program's audience |
| Ad Hoc Bug Bounty Program | Invited researchers, on demand | Per validated finding | A specific release, migration or new surface |
| Time-Limited Bug Bounty Program | Defined audience, defined window | Per validated finding | Launch events, compliance deadlines, conference timing |
| Challenges and Contests | Defined audience, competitive format | Prizes or leaderboard-based rewards | Targeted problems, recruiting, community engagement |
| Crowdsourced Security Testing | Vetted community, structured engagement | Per validated finding or tiered | Continuous testing with more control than an open bounty |
| PTaaS Engagement | Certified experts, named testers | Fixed, tiered or subscription | Scheduled depth, compliance evidence, complex targets |
What every model shares
Whichever model you choose, the operational machinery is the same:
- Scope definition — in-scope and out-of-scope assets, grouped by type, tier and priority.
- Rules and governance — engagement policy, participation requirements, approval queues and conflict handling.
- Researcher or expert onboarding — invitations, policy acceptance, NDA acceptance where required, and participation status.
- Communications — program-level announcements, realtime chat and retained history.
- Report handling — classification, duplicate checks, reviewer guidance and lifecycle state.
- Remediation tracking — tasks, ownership, deadlines and proof of closure.
- Financial controls — budget allocation, reward workflow and metered consumption where relevant.
- Security controls — centralised authentication, role-based access and controlled evidence handling.
Because the machinery is shared, moving from a VDP to a bounty program — or adding expert engagements later — does not mean rebuilding your process.
Combining models
Most mature programs use more than one:
- A VDP runs permanently as the inbound channel for anything reported outside an active program.
- A private bounty covers high-value assets continuously with a controlled audience.
- An ad hoc or time-limited bounty is opened when a new surface ships.
- A PTaaS engagement sits on the calendar for scheduled depth, compliance evidence and retesting.
All of them read from the same scope definition, so a target added once is covered by every active model.
Availability and limits
- Private researcher access is Professional-tier; advanced researcher vetting and dedicated tester pools are Enterprise-tier.
- Custom severity scoring, custom disclosure timelines and SLA response guarantees are Enterprise-tier. Default models and SLAs are available on lower tiers.
- Program models describe how testing is organised. They do not by themselves constitute legal advice on disclosure policy — that should be reviewed by your counsel.
Related docs
- Scope and rules of engagement — what to write into the policy
- Triage pipeline — how submissions are handled once a program is live
- Payouts and KYC — what rewarding researchers involves
- PTaaS engagement lifecycle — the expert-led model end to end