For security teams

Thousands of researchers. One program to write.

Run a bug bounty program on EncryptSec: publish your scope and reward tiers, and let vetted researchers test what your last pentest only saw for two weeks. Reports arrive triaged and reproducible. You pay for valid findings, not for hours.

  • Free to set up
  • Pay only for valid findings
  • Public or invite-only
274
Researchers
37
Live programs
70
Rewarded findings

How it works

From signing up to your first report, with nothing hidden in between.

1.Create your company account

Sign up with a work email. No sales call, no contract to sign before you can look around.

2.Write your program

List your in-scope targets, set the rules of engagement and disclosure policy, and publish what each severity pays. Start from our template and edit it.

3.We review it

Our team reads every program before it goes live — scope, rules and reward tiers — and checks the assets belong to you. Usually within two business days.

4.Go live and get reports

Your program appears in the directory and researchers start testing. Each report arrives triaged, reproducible and rated, in your dashboard.

What you get

The parts of running a bounty program that are tedious to build yourself.

Public or invite-only

Run your program in the open, or keep it private and invite the researchers you want. Private programs are never listed and never named — not even in our own headline figures.

Human triage, not a queue

Every report is validated by the EncryptSec research team against your scope and rules before it reaches you. Duplicates and noise are closed on our side.

You set the reward tiers

Publish what critical, high, medium and low pay — or run a recognition-only VDP. Researchers decide which programs to spend a weekend on by reading exactly this.

A response target you publish

State the triage SLA you are committing to. Your measured response time is shown next to it, so researchers see the target and the reality.

Rewards with a paper trail

Bounties are approved, paid and receipted against the finding they belong to, so what you paid and why is answerable months later.

Safe harbour, in writing

Commit not to pursue good-faith research within your rules. It is the single thing that most changes how many researchers engage with a program.

What it costs

Creating an account and building a program is free, and stays free while it is in review. You pay the bounties you decide to award — nothing is deducted from a researcher's reward, and there is no per-report fee for anything you reject as invalid.

For managed triage, private cohorts or a retained engagement, talk to us and we will quote against your scope.

Ask for a quote

Need a pentest instead?

A bounty program is always on; an audit is a point in time with a signed report at the end. EncryptSec does both, on one platform, so the findings from each live next to each other rather than in a spreadsheet and a PDF.

  • A scoped assessment by OSCP-certified testers
  • Findings, evidence and retests on the same platform
  • A report you can hand to an auditor
Request a scope

What a report looks like

Every submission arrives in the same shape, whoever filed it.

Reproducible

Steps, affected target, and the evidence to confirm it — screenshots, requests, or a proof of concept.

Rated

Severity assigned against CVSS and the vulnerability taxonomy, not by how alarming the title sounds.

Tracked

One thread from filing to retest to payout, with the status a researcher sees matching the one you do.

Write your program this afternoon.

Create an account, start from our template, and submit it when it reads right. We will come back to you within two business days — and if something needs changing, we will tell you exactly what.