AXUM SEC Beta Launches in 10 Days

Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.

AI Agents Coming Soon— AXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.AI Agents Coming Soon— AXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.
Axum SEC Logo
One platform

Crowdsourced security and PTaaS, together

Every security test. One platform.

Run bug bounty, disclosure and expert-led penetration testing side by side — one scope model, one triage pipeline, one remediation trail, one payment rail, one audit history.

Some capabilities are plan-dependent. Enterprise and Professional availability is labelled throughout the platform pages.

Platform viewLive
  • Submittednew
  • Triagedvalid
  • Duplicate checkclear
  • Rewardapproved

What the platform operates

Not a submission queue with a dashboard on top: scope, testing, triage, remediation, payment and disclosure share one source of truth.

Testing models
Two engines

Crowd-sourced discovery and expert-led engagement on one control plane.

Source of truth
One scope

Targets, tiers and rules defined once and used by every model.

Program types
Nine models

Disclosure, bounty, contests, crowdsourced testing and PTaaS engagements.

Integrations
Six systems

Jira, GitHub, GitLab, Azure DevOps, Slack and Microsoft Teams.

How it fits together

Crowd-sourced depth. Expert-led rigour.

The two models close each other’s gaps: the crowd provides continuous breadth, experts provide scheduled depth and defensible evidence.

Crowd-sourced engine

Continuous, wide testing by a global researcher community, priced by validated finding rather than by the hour.

  • Program types: Public, private and hybrid, plus ad hoc, time-limited and challenge formats.
  • Vetting: Invitation control and vetting for sensitive targets.
  • Coverage: Testing continues between scheduled engagements rather than pausing.
  • Economics: Custom severity bands so payout follows your risk model.
Bug bounty programs

Expert-led engine

Structured engagements with certified testers: formal scope, enforced rules of engagement, and evidence built for review.

  • Scoping: Targets classified and priced by severity tier before testing begins.
  • Access: NDA acceptance, credential locker and controlled network access.
  • Depth: Black-box and white-box testing, including source code review.
  • Proof: Retest, verification and certification artefacts on the same record.
PTaaS engagements

Platform capabilities

The operating layer around both engines

The parts of running a program that are not testing: access control, evidence handling, triage automation, commercial controls and reporting.

AI-assisted triage

Classification, duplicate detection and remediation guidance designed to protect reviewer time rather than replace judgement.

AI assistance

One triage pipeline

Submission, validation, duplicate handling, reward and disclosure as explicit states — visible to the people who need them.

Triage and remediation

Encrypted evidence

Confidential files encrypted before storage, scanned by multiple engines, quarantined when flagged and access-controlled.

Trust and security

Multi-currency budgets

Wallets, per-program budgets, subscription entitlements, usage metering and overage handling on one ledger-backed trail.

Financial operations

Global payouts

Tiered KYC, several payout rails, withholding calculation, digital tax forms and annual reporting workflows.

Payouts and tax

Enterprise access control

OAuth or token sign-in, TOTP MFA, fine-grained roles, audit trails and administrative IP allowlisting.

Identity and access

Documentation

Want the detail?

The marketing pages stay short on purpose. Architecture, data model and operating detail live in the documentation library.

Platform overview

Two engines, one control plane, and which service backs which capability.

Read the doc

Program models

All nine models, what each is for, and how to choose between them.

Read the doc

Identity and access

Authentication, MFA, the expert access gates and the role model.

Read the doc

Common questions

Before you talk to us

The questions that come up most often when teams evaluate the platform.

Is crowd-sourced testing too noisy to be useful?
Noise is a scope and triage problem rather than an inherent one. The platform addresses both: precise scope boundaries, structured engagement rules, assisted classification and semantic duplicate detection that flags likely repeats before review effort is spent.
Can we use this alongside our existing pentest vendor?
Yes. PTaaS engagements are structured, scheduled, scoped and staffed deliberately — the same model your current vendor follows, with the evidence trail and reporting produced inside the platform rather than assembled afterwards.
Do we have to move our whole process onto the platform?
No. Findings sync into Jira, GitHub, GitLab, Azure DevOps, Slack and Teams, so engineering keeps working where it already works while security operations consolidate in one place.
Where does vulnerability data live?
Evidence is held in an encrypted store using AES-256-GCM, scanned by multiple malware engines with automatic quarantine, and reachable only through authenticated, permission-checked operations. Access to the platform itself is governed by MFA, fine-grained roles and audit trails.

Create your next security program in minutes, not weeks.

Start with a disclosure program, open a bounty, or book a scoped expert engagement — and add the other models to the same scope whenever you are ready.

We will walk through scope, models and commercials before anything is switched on.