Bugcrowd Reviews

2 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.0 out of 101

Do you work for this company?

Overall Rating

Reviewer's Company Size

Last Updated

By Topic

Industry

Department

Experience

Job Type

Role

Reviews (1-1 of 1)

Chase Palmer, CISSP profile photo
Score 8 out of 10
Vetted Review
Verified User
Review Source
We use Bugcrowd for their on-demand crowd-sourced penetration test to test our SaaS application. This allows us to get a number of security researchers involved in looking at our product to find potential vulnerabilities.
  • Having a pool of security researchers helps keep the penetration tests broad, getting the most bang for your buck.
  • The integration with Slack makes it easy to keep tabs on the program and when new findings are submitted.
  • The interface is pretty simple to use and fairly intuitive.
  • The success of your program highly depends on the moderator that is assigned to your project. A good moderator will continue to find researchers until the quota is full. Less than stellar moderators will send out one invite and sees what sticks.
  • Not all researchers are as professional as one might hope. This can ruin the experience.
Bugcrowd is great for bug bounty programs and as a cheaper alternative to a full-blown penetration test. Small to medium-sized companies who are serious about security, but don't have the budget for a $40,000 penetration test, this is a great solution. Bugcrowd isn't going to be able to do much of the white-box penetration testing (code reviews), as they are more suited for grey-box and black-box. A program like this will need at least one dedicated person to work with the moderator, verify findings, and decide on the severity of the finding.
Read Chase Palmer, CISSP's full review

Bugcrowd Scorecard Summary

About Bugcrowd

Bugcrowd connects companies' security and dev teams to vetted and talented security researchers worldwide to run crowd-powered private and public bug bounty programs.

Companies like Tesla Motors, Barracuda Networks, and Western Union have teamed up with Bugcrowd to augment their security efforts and quickly realize clearer insights into fixing their application vulnerabilities.
Categories:  Bug Bounty

Bugcrowd Features

Has featurePrivate Programs: Invitation-only program partnering you with 50 of our most winning, background-checked security researchers - and our industry veterans who direct the triage and validation of vulnerabilities. This kind of program is best if you're testing new products and apps that are harder to access. Depending on your security needs, private programs can be ongoing or one-time engagements.
Has featurePublic Programs: Through our crowd-powered platform, engage the collective ingenuity of thousands of security researchers. Simply define your scope of testing, and we will match your needs with the right researchers to find the biggest, baddest vulnerabilities. Similar to private programs, public programs can be ongoing or one-time engagements.
Has featureManaged Triage and Validation Service: Add-on service that bolsters your security and dev teams' bandwidth during your program's flight.

Bugcrowd Integrations

Bugcrowd Competitors

Pricing

Has featureFree Trial Available?Yes
Does not have featureFree or Freemium Version Available?No
Has featurePremium Consulting/Integration Services Available?Yes
Entry-level set up fee?No

Bugcrowd Support Options

 Free VersionPaid Version
Phone
Email
Forum/Community
FAQ/Knowledgebase
Social Media
Video Tutorials / Webinar
Live Demo Request
Live Chat

Bugcrowd Technical Details

Deployment Types:SaaS
Operating Systems: Unspecified
Mobile Application:No
Supported Countries:US, Canada, Australia, New Zealand, UK
Supported Languages: English