Bugcrowd connects companies with cybersecurity experts to identify and report vulnerabilities, enhancing the security posture of web applications through crowdsourced vulnerability discovery.



| Product | Mindshare (%) |
|---|---|
| Bugcrowd | 2.1% |
| Secureworks Taegis Managed XDR / MDR | 4.9% |
| IBM Managed Security Services | 2.3% |
| Other | 90.7% |
Bugcrowd functions as a platform enabling direct interaction between companies and skilled hackers to discover and report vulnerabilities. With a focus on ensuring security, it offers guaranteed payments, a robust reporting process with markdown support, and direct bank transfers. Crowdsourced hackers enhance security by unearthing unique vulnerabilities. Collections allow companies to design their security programs, and top-tier pen testers improve application security.
What are Bugcrowd's key features?Implemented across industries, Bugcrowd facilitates secure application environments by allowing enterprises such as Facebook and Twitter to connect with a global community of ethical hackers. Acting as a mediator between organizations and cybersecurity professionals, it helps discover vulnerabilities and secure web platforms effectively, with platforms like HackerOne used in conjunction for a comprehensive security strategy.
Zephyr Health, Barracuda Networks, Western Union, Instructure, Aruba Networks, Pinterest, CARD.com, WINK, (ISC)2, StatusPage, WHMCS, Movember
| Author info | Rating | Review Summary |
|---|---|---|
| Senior Engineering Manager - Platform Team at eTender Inc | 4.0 | I've found Bugcrowd effective for uncovering vulnerabilities, especially with its triage process, though frequent account manager changes hurt communication. Despite a high cost, it adds value, and setup was straightforward, though integrating with Jira was challenging. |
| dApp Auditor at Hacken | 4.0 | I use Bugcrowd to report security vulnerabilities, benefiting from its extensive list of websites and guaranteed payments. While it has slowed in triaging, it enhances my skills. I've also tried HackerOne and Integrity, but Bugcrowd remains unmatched. |
| DevOps Team Lead at Tata Consultancy | 4.0 | I am a developer in cybersecurity who uses Bugcrowd to report platform vulnerabilities efficiently through their easy-to-use cloud platform. However, I find there is room for improvement in their response time when customer input is necessary. |
| Security Researcher at HackerOne | 4.0 | As a security researcher using Bugcrowd, I find vulnerabilities, report them, and receive bounties for valid findings. Bugcrowd offers valuable features like program collections, but needs improvement in report access and customer support response time. I also work with HackerOne. |
| Bug bounty hunter at HackerOne | 5.0 | I have been using Bugcrowd for two years to find bugs and vulnerabilities. I like the high bounties, hall of fame, and stickers. Although it's helpful and user-friendly, I feel there is room for improvement in the tool itself. |

Positive

I use Bugcrowd for reporting security vulnerabilities on different websites. Bugcrowd acts as a middleman between ethical hackers and websites. I report vulnerabilities and Bugcrowd ensures they are communicated to the relevant website, such as Facebook or Twitter, and pays me a reward if the reported vulnerability is valid.
The most valuable aspect of Bugcrowd is that it provides a long list of different websites or web applications where I can report vulnerabilities. Bugcrowd ensures that if vulnerabilities are reported through their platform, payment is guaranteed.
Additionally, the platform aids in transferring money directly into my bank account, making the entire process smooth. Working on Bugcrowd has made me a better security engineer since it provides a competitive environment to report successful vulnerabilities.
The triaging process has slowed down compared to three years ago. It now takes more time to resolve a reported vulnerability and receive the payout.
Also, the platform can be challenging for new users who might find it difficult to get invitations to private programs.
I started using Bugcrowd in 2020, so it's been over four years.
Bugcrowd is very stable. I have never experienced any outages or stability problems.
There is another platform called HackerOne which is a competitor. HackerOne is bigger and better in terms of scalability as they have more programs and clients. Bugcrowd is also significant, however, it could improve in this area.
Currently, I would rate Bugcrowd's customer service and support as a seven out of ten. They need to be quicker in responding to tickets.
Neutral
Before Bugcrowd, I did not use a different solution. I started using Bugcrowd and HackerOne simultaneously.
The initial setup is very straightforward, and I would rate it a ten out of ten.
There was no investment from my side, so the return in terms of money is all positive. I receive rewards as bounties, which is excellent.
From the perspective of security researchers like myself, Bugcrowd is very inexpensive. It's almost free for me, as there are no fees or commissions. However, I am not familiar with what they charge websites.
I have also worked a bit on a platform called Integrity, however, it's not as big as Bugcrowd.
Working on Bugcrowd can improve one's skills as a security engineer due to its competitive nature.
Overall, I would rate Bugcrowd an eight out of ten.

I am a developer working in cybersecurity, and I use Bugcrowd to help companies remove vulnerabilities from their websites. I report vulnerabilities found in applications or customer platforms through Bugcrowd's cloud platform. This allows the cloud team to track submissions, and then the client provides feedback.
One of the features I like most about Bugcrowd is the ability to create a report in a very easy way. I can drag and drop images and write reports using markdown, which makes report submission and creation very efficient. Bugcrowd serves as a platform for finding cybersecurity vulnerabilities.
There is room for improvement in Bugcrowd's response time when customer input is needed for resolving tickets. If this time could be minimized, it would be very helpful.
I have been using Bugcrowd for the past four years.
I encountered some minor issues such as broken links in engagements, but these were resolved quickly after raising a ticket. Overall, Bugcrowd has minor stability issues.
The scalability of Bugcrowd is pretty easy according to me.
Bugcrowd's support team is very active and supportive. However, there are delays when tickets require customer response.
Positive
The initial setup is easy. You create an account using your email and password, add your bank account, and wait for verification from the Bugcrowd team. Once verified, you can accept payments.
Currently, Bugcrowd is free. Public engagements can be viewed by anyone, while private ones require invites from Bugcrowd.
I would rate Bugcrowd an eight out of ten.
I recommend it to others who are good in the cybersecurity domain. For newcomers, I advise having a depth of knowledge in cybersecurity to effectively help companies through Bugcrowd.

As a security researcher, I log in to Bugcrowd, look for a program, choose it, and then start security auditing it. If I find vulnerabilities, I write a report to them. The customer evaluates my report, and if it is valid, they reward me with a bounty.
Bugcrowd has programs that disclose rewards and invite researchers to new programs. There is a pen test feature for top hackers on the platform, and they have a new feature called Collections, which provides multiple programs in one collection. This collection feature is beneficial for targeting specific companies like Cisco, allowing easy identification of targets.
Bugcrowd should provide more access to the reports, similar to HackerOne, allowing for full disclosure once a bug is resolved, so researchers can learn from them. They should improve the responsibility type and response time of their customer support, especially when the issue is urgent.
I have been working for Bugcrowd as a researcher for three years.
I believe Bugcrowd is highly stable. I rate the stability as ten out of ten. There's high availability. I have not experienced any issues.
I think Bugcrowd's scalability could be improved by adding more programs, unlike HackerOne where I have access to a significantly higher number of programs.
The availability of the support team can be improved. Sometimes, they take one to seven days to reply, especially in case of report mediation.
Neutral
Setting up Bugcrowd is very easy. I would initially rate it as ten out of ten, however, with the consideration of having to fill out a tax form for receiving bounties, I rate it eight.
For researchers, the pricing and bounty table scale are good. However, I don't have information about customer pricing.
I work for HackerOne as well.
I rate Bugcrowd eight out of ten.
For new users evaluating Bugcrowd, the platform has good programs where you can earn money. Work hard and engage with Bugcrowd.
Positive