No more typing reviews! Try our Samantha, our new voice AI agent.

Bugcrowd vs Cymulate comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Bugcrowd
Ranking in Attack Surface Management (ASM)
11th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
5
Ranking in other categories
Managed Security Services Providers (MSSP) (3rd), Bug Bounty Platforms (1st), Penetration Testing Services (3rd)
Cymulate
Ranking in Attack Surface Management (ASM)
14th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
6
Ranking in other categories
Threat Intelligence Platforms (TIP) (15th), Breach and Attack Simulation (BAS) (2nd), Continuous Threat Exposure Management (CTEM) (5th)
 

Mindshare comparison

As of June 2026, in the Attack Surface Management (ASM) category, the mindshare of Bugcrowd is 3.4%, down from 5.5% compared to the previous year. The mindshare of Cymulate is 2.4%, down from 3.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Attack Surface Management (ASM) Mindshare Distribution
ProductMindshare (%)
Bugcrowd3.4%
Cymulate2.4%
Other94.2%
Attack Surface Management (ASM)
 

Featured Reviews

Ben Gurney - PeerSpot reviewer
Senior Engineering Manager - Platform Team at eTender Inc
Crowdsourced triage has uncovered critical website vulnerabilities and continuously improves our security posture
Bugcrowd could be improved or enhanced as they seem to have a lot of internal churn at the moment, so they could be more stable and more customer-focused. By customer-focused, I mean they are not very good at communicating what is changing on their side to their customers. I am now on my fourth account manager within one year. My latest call with them was with the fourth account manager saying there have been many changes and apologizing that no one I have spoken to in the past is on this call, but going forwards it will be them. With the fourth account manager in a year, it is hard to trust that message.
SB
Deputy Manager at a financial services firm with 10,001+ employees
Experience seamless integration and effective dashboard while considering improved EDR configuration support
The way Cymulate works for EDR could be improved, as it drops payload and requires action from the EDR console for remediation, which can block the whole process of Cymulate execution. They should create some KB articles for the granular exclusion from different platforms and improve their technical assistance support.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable aspect of Bugcrowd is that it provides a long list of different websites or web applications where I can report vulnerabilities."
"One of the features I like most about Bugcrowd is the ability to create a report in a very easy way."
"Bugcrowd's support team is very active and supportive."
"I believe Bugcrowd is highly stable."
"I would rate Bugcrowd a ten out of ten."
"Bugcrowd has programs that disclose rewards and invite researchers to new programs."
"Working on Bugcrowd has made me a better security engineer since it provides a competitive environment to report successful vulnerabilities."
"Bugcrowd's use of crowdsourced hackers has helped in discovering unique vulnerabilities."
"The security validation feature helps my organization in assessing our security posture."
"Cymulate is easy to set up, install, and configure."
"Cymulate has positively impacted our organization by helping us to take care of the efficacy and reviewing the policies and configuration."
"With Cymulate, the best features are the capacity to test the EDR or malware, anti-malware solution."
"The most valuable feature for us is the zero-day."
"The reporting capabilities are very good."
 

Cons

"The triaging process has slowed down compared to three years ago. It now takes more time to resolve a reported vulnerability and receive the payout."
"There is room for improvement in Bugcrowd's response time when customer input is needed for resolving tickets. If this time could be minimized, it would be very helpful."
"Bugcrowd should provide more access to the reports, similar to HackerOne, allowing for full disclosure once a bug is resolved, so researchers can learn from them. They should improve the responsibility type and response time of their customer support, especially when the issue is urgent."
"Bugcrowd could be improved or enhanced as they seem to have a lot of internal churn at the moment, so they could be more stable and more customer-focused."
"We have had some trouble with the agents."
"The product must provide consultancy for initial setup."
"The way Cymulate works for EDR could be improved, as it drops payload and requires action from the EDR console for remediation, which can block the whole process of Cymulate execution."
"The reporting process requires significant improvement as it often takes longer than expected and the quality is lacking."
"I will be honest, we have it, but in the last year, I didn't maintain the system until a month ago."
"The cost can be quite high, and it impacts scalability as more simulations require additional expenses."
 

Pricing and Cost Advice

Information not available
"Cymulate's services are expensive."
"The product is affordable."
report
Use our free recommendation engine to learn which Attack Surface Management (ASM) solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Comms Service Provider
12%
Manufacturing Company
8%
Computer Software Company
7%
Financial Services Firm
14%
Manufacturing Company
10%
Computer Software Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business5
Large Enterprise3
 

Questions from the Community

What is your experience regarding pricing and costs for Bugcrowd?
I think the pricing and licensing of Bugcrowd are expensive, but we do get good value from it, as we find vulnerabilities that we would otherwise be unaware of.
What needs improvement with Bugcrowd?
Bugcrowd could be improved or enhanced as they seem to have a lot of internal churn at the moment, so they could be more stable and more customer-focused. By customer-focused, I mean they are not v...
What is your primary use case for Bugcrowd?
I work with Bugcrowd mostly as a crowdsourcing security platform. I use Bugcrowd by putting a brief on Bugcrowd's website, and then their community of security researchers hunt for vulnerabilities ...
What is your experience regarding pricing and costs for Cymulate?
I don't know if it's expensive. It depends on the modules that you want, or the time, because they give you a tenant. A tenant for you.
What needs improvement with Cymulate?
I don't know if that helped with quick decision making for my security team because I am the security team and you must have a dedicated team to work with this tool. I don't use the analytics modul...
What advice do you have for others considering Cymulate?
With Cymulate, I have experience using the vulnerability management tools. I don't know if I have used the Continuous Security Validation with Cymulate. I don't have that module licensed with Cymul...
 

Comparisons

 

Overview

 

Sample Customers

Zephyr Health, Barracuda Networks, Western Union, Instructure, Aruba Networks, Pinterest, CARD.com, WINK, (ISC)2, StatusPage, WHMCS, Movember
Euronext, YMCA, Telit, Nemours 
Find out what your peers are saying about Bugcrowd vs. Cymulate and other solutions. Updated: May 2026.
900,644 professionals have used our research since 2012.