Bugcrowd

Overview

Reviews

Reviewer Pros & Cons

View all pros & cons

Pricing

View all pricing
N/A
Unavailable

What is Bugcrowd?

San Francisco-based Bugcrowd offers a bug bounty platform, for vulnerability management.

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://bugcrowd.com/how-it-works

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting / Integration Services

Would you like us to let the vendor know that you want pricing?

Alternatives Pricing

What is KeepSolid VPN Unlimited?

Nowadays, Privacy is a Luxury! Whenever we pay our bills, manage our bank accounts, or log in to our favorite social networks, our credentials, account numbers, billing address, and other private data may end up in the crosshairs of identity thieves. Trust your security and privacy to professionals …

What is Hootsuite?

HootSuite Enterprise provides a centralized platform for managing streams from different social media channels and posting/ engaging across channels simultaneously. It also has strong team / workflow features and good mobile apps.

Features Scorecard

No scorecards have been submitted for this product yet..

Product Details

What is Bugcrowd?

Bugcrowd connects companies' security and dev teams to vetted and talented security researchers worldwide to run crowd-powered private and public bug bounty programs.

Companies like Tesla Motors, Barracuda Networks, and Western Union have teamed up with Bugcrowd to augment their security efforts and quickly realize clearer insights into fixing their application vulnerabilities.

Bugcrowd Features

  • Supported: Private Programs: Invitation-only program partnering you with 50 of our most winning, background-checked security researchers - and our industry veterans who direct the triage and validation of vulnerabilities. This kind of program is best if you're testing new products and apps that are harder to access. Depending on your security needs, private programs can be ongoing or one-time engagements.
  • Supported: Public Programs: Through our crowd-powered platform, engage the collective ingenuity of thousands of security researchers. Simply define your scope of testing, and we will match your needs with the right researchers to find the biggest, baddest vulnerabilities. Similar to private programs, public programs can be ongoing or one-time engagements.
  • Supported: Managed Triage and Validation Service: Add-on service that bolsters your security and dev teams' bandwidth during your program's flight.

Bugcrowd Integrations

Bugcrowd Competitors

Bugcrowd Technical Details

Deployment TypesSaaS
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesUS, Canada, Australia, New Zealand, UK
Supported LanguagesEnglish

Alternatives

View all alternatives

Frequently Asked Questions

What is Bugcrowd?

San Francisco-based Bugcrowd offers a bug bounty platform, for vulnerability management.

Who uses Bugcrowd?

The most common users of Bugcrowd are from Mid-size Companies and the Computer & Network Security industry.

Reviews and Ratings

(3)

Ratings

Reviews

(1-2 of 3)
Companies can't remove reviews or game the system. Here's why
Peter Paccione | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Review Source
We both use bug crowd for crowd testing and income. It is used by the whole organization at large. Our employees have accounts so they can test other applications, report, improve their skills and also submit applications that are hosted by our company. The bug crowd team is experienced and professional. They also offer reasonable prices and schemes to allow a wide range of testers to test your site or to allow experienced testers only to test the site
  • Crowd testing
  • mitigation efforts
  • Liaison triage
  • Allow for more feedback when liaising with company
  • Work with company to better help them understand issue
  • Allow for more feedback
Bug Crowd is well suited if you do not have the resources to hire someone to test a site, do not have a team of recruiters that can find qualified testers and maybe do not have the budget to hire said employees. They are also good if you are only running short tests on a site and need quick feedback. Since you can set the bounty levels, you can decide what you want to pay
Chase Palmer, CISSP | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Review Source
We use Bugcrowd for their on-demand crowd-sourced penetration test to test our SaaS application. This allows us to get a number of security researchers involved in looking at our product to find potential vulnerabilities.
  • Having a pool of security researchers helps keep the penetration tests broad, getting the most bang for your buck.
  • The integration with Slack makes it easy to keep tabs on the program and when new findings are submitted.
  • The interface is pretty simple to use and fairly intuitive.
  • The success of your program highly depends on the moderator that is assigned to your project. A good moderator will continue to find researchers until the quota is full. Less than stellar moderators will send out one invite and sees what sticks.
  • Not all researchers are as professional as one might hope. This can ruin the experience.
Bugcrowd is great for bug bounty programs and as a cheaper alternative to a full-blown penetration test. Small to medium-sized companies who are serious about security, but don't have the budget for a $40,000 penetration test, this is a great solution. Bugcrowd isn't going to be able to do much of the white-box penetration testing (code reviews), as they are more suited for grey-box and black-box. A program like this will need at least one dedicated person to work with the moderator, verify findings, and decide on the severity of the finding.