You don't need all five services. You need the one that fits you.
VDP, pentest, crowdsourced pentest, bug bounty and live hacking solve different problems. Compare them here and leave knowing which one to ask for.
More than 100 companies, of all sizes and sectors, already test their security with us
What each one is, in a single line
They are ordered by how demanding they are, not by price. Almost everyone starts with the first and moves up when they need to.
VDP
A legal, orderly channel so that whoever finds a flaw tells you about it, and not Twitter.
What a VDP is 02Pentest
A targeted audit, with a formal report, when you have a milestone, a client or a regulation that demands it.
See pentest 03Crowdsourced pentest
The depth of a pentest, but with many hackers at once: more coverage in less time.
Understand the approach 04Bug bounty
Your systems put to the test all year round. You pay per validated vulnerability, with a set pot and a cap.
See bug bountyLive hacking
The best hackers focused on a single live challenge. Results and brand visibility within hours.
All five, side by side
The seven questions that really tell one service from another. No adjectives: duration, who gets in, how you pay and what you take away.
| Feature | VDP Vulnerability disclosure | Pentest Targeted audit | Crowdsourced Pentest with many hackers | Bug bounty Pay for results, all year round | Live hacking Live event |
|---|---|---|---|---|---|
| When to choose it | You have nothing yet You want to stop flying blind without opening a budget | Someone is asking you for it A client, an audit or a regulation requires a report | The pentest falls short Same depth, more surface and less time | You ship often Your product changes every week; one snapshot a year is not enough | You are after a milestone Maximum rigour and visibility at a specific moment |
| Duration | Continuous Always open, with no end date | One-off A closed window, with a start and an end | One-off or continuous You decide the window | Continuous Always open, with no end date | Intensive event From a few hours to a few days |
| Who tests you | Anyone Open and unverified. The report can be anonymous | Secur0's in-house team Our own pentesters, under contract, with verified certifications and background checks | A curated group, tailored to you You set the bar: identity, country, certifications, background checks, strict KYC | Configurable From public with no KYC to private with strict KYC | Identified participants Registration and verification before the event |
| How you pay | Triage only You do not pay per vulnerability found | Fixed fee Agreed per project, before starting | Per validated vulnerability Based on severity | Per validated vulnerability Based on severity, with a defined pot and a maximum cap | Per vulnerability and event Rewards plus the cost of running it |
| Validity for compliance | Complementary Good practice, and mandatory under the CRA and some certifications. It does not replace an audit | Valid for certification Widely accepted by auditors and by your clients | Valid for certification A compliant report is issued | Complementary It does not replace the pentest for certification | Complementary It is not aimed at certification |
| What you take away | Reports on the platform Individual and exportable to PDF | Full formal report Methodology, evidence and retest | Formal report and real time Findings arrive as they are discovered | Continuous reports One per finding, plus a tracking dashboard | Event summary Plus the report for each finding |
| Legal agreements | Minimal A public disclosure policy with safe harbor | Full NDA, detailed contractual scope and explicit authorisation | NDA per researcher Defined scope and safe harbor, adjustable to what you ask for | Full NDA, scope, programme terms and safe harbor | Event terms Rules and NDA, with safe harbor during the window |
| Confidentiality | Public The policy is visible to anyone | Private Confidential by nature | Private or invite-only You decide who gets in and on what terms | Configurable Public, private or invite-only | Public or private Public if what you are after is brand visibility |
| More information | See VDP | See pentest | See crowdsourced | See bug bounty |
They are not mutually exclusive The usual path is to start with a VDP, add a pentest when someone requires one, and move to bug bounty when the product changes faster than your audits. You can have several running at once.
Is your company already using AI agents? We put those to the test too
Agents open up an attack surface that traditional audits do not cover: prompt injection, data leaks and unauthorised actions. It can be added to the scope of any of the five services.
Test your AI“At first, we weren't sure how much impact Secur0 could have. With the first reports we realised there were vulnerabilities with the potential to put our customers' trust at risk.”
What people ask us before deciding
We have never done any of this. Where do we start?
Can I have several services at once?
I need to pass a certification. Which one works for me?
How much does it cost?
Who gets into my systems and how do I control it?
I do not have a security team. Who handles the reports?
Still not sure?
Tell us what product you have, who is asking you for what and what team you have. We will tell you which of the five fits, even if it is the cheapest one.
No commitment and no jargon. A specialist gets back to you within 24-48 hours.