Skip to content
Services

You don't need all five services. You need the one that fits you.

VDP, pentest, crowdsourced pentest, bug bounty and live hacking solve different problems. Compare them here and leave knowing which one to ask for.

More than 100 companies, of all sizes and sectors, already test their security with us

Comparison

All five, side by side

The seven questions that really tell one service from another. No adjectives: duration, who gets in, how you pay and what you take away.

Comparison of VDP, pentest, crowdsourced pentest, bug bounty and live hacking by duration, who tests you, cost, validity for compliance, deliverable, legal agreements and confidentiality.
Feature VDP Vulnerability disclosure Pentest Targeted audit Crowdsourced Pentest with many hackers Bug bounty Pay for results, all year round Live hacking Live event
When to choose it You have nothing yet You want to stop flying blind without opening a budget Someone is asking you for it A client, an audit or a regulation requires a report The pentest falls short Same depth, more surface and less time You ship often Your product changes every week; one snapshot a year is not enough You are after a milestone Maximum rigour and visibility at a specific moment
Duration Continuous Always open, with no end date One-off A closed window, with a start and an end One-off or continuous You decide the window Continuous Always open, with no end date Intensive event From a few hours to a few days
Who tests you Anyone Open and unverified. The report can be anonymous Secur0's in-house team Our own pentesters, under contract, with verified certifications and background checks A curated group, tailored to you You set the bar: identity, country, certifications, background checks, strict KYC Configurable From public with no KYC to private with strict KYC Identified participants Registration and verification before the event
How you pay Triage only You do not pay per vulnerability found Fixed fee Agreed per project, before starting Per validated vulnerability Based on severity Per validated vulnerability Based on severity, with a defined pot and a maximum cap Per vulnerability and event Rewards plus the cost of running it
Validity for compliance Complementary Good practice, and mandatory under the CRA and some certifications. It does not replace an audit Valid for certification Widely accepted by auditors and by your clients Valid for certification A compliant report is issued Complementary It does not replace the pentest for certification Complementary It is not aimed at certification
What you take away Reports on the platform Individual and exportable to PDF Full formal report Methodology, evidence and retest Formal report and real time Findings arrive as they are discovered Continuous reports One per finding, plus a tracking dashboard Event summary Plus the report for each finding
Legal agreements Minimal A public disclosure policy with safe harbor Full NDA, detailed contractual scope and explicit authorisation NDA per researcher Defined scope and safe harbor, adjustable to what you ask for Full NDA, scope, programme terms and safe harbor Event terms Rules and NDA, with safe harbor during the window
Confidentiality Public The policy is visible to anyone Private Confidential by nature Private or invite-only You decide who gets in and on what terms Configurable Public, private or invite-only Public or private Public if what you are after is brand visibility
More information See VDP See pentest See crowdsourced See bug bounty

They are not mutually exclusive The usual path is to start with a VDP, add a pentest when someone requires one, and move to bug bounty when the product changes faster than your audits. You can have several running at once.

New

Is your company already using AI agents? We put those to the test too

Agents open up an attack surface that traditional audits do not cover: prompt injection, data leaks and unauthorised actions. It can be added to the scope of any of the five services.

Test your AI
Real CTO stories

“At first, we weren't sure how much impact Secur0 could have. With the first reports we realised there were vulnerabilities with the potential to put our customers' trust at risk.”

GBTC Finance Crypto · Finance · Web platform
Read the full case
Frequently asked questions

What people ask us before deciding

We have never done any of this. Where do we start?

With the VDP. It opens a channel to receive reports in an orderly way, it has no cost per vulnerability and it lets you see what is coming in before committing any budget. From there you will know whether you need a pentest or something continuous.

Can I have several services at once?

Yes, and that is the norm. The most common combination is a VDP always open, an annual pentest for the compliance side and a bug bounty on the product that changes the most. Each one covers a different gap.

I need to pass a certification. Which one works for me?

The pentest and the crowdsourced pentest, because they end in a formal report with methodology, evidence and retest. Bug bounty and live hacking add a lot to your real security, but they do not replace that report. The VDP is a requirement under the CRA and in several certifications, although it does not replace the audit either.

How much does it cost?

It depends on the model. The pentest is a fixed fee agreed before starting. Bug bounty and crowdsourced pentest are paid per validated vulnerability, with a rewards pot defined by you and a maximum cap, so the spend cannot run away. The VDP has no cost per vulnerability: only triage.

Who gets into my systems and how do I control it?

You define the scope: which assets are in, which are out and what can be done to them. You decide the level of verification for the hackers, from open to strict KYC with identity, country and background checks, and you can revoke anyone's access at any moment. In a pentest, the people testing you are Secur0's in-house team.

I do not have a security team. Who handles the reports?

We do. Triage is done by our in-house team: we discard duplicates, false positives and noise, and only what is real and prioritised by impact reaches you. That is the difference between an unmanaged security inbox and a programme that works.

Still not sure?

Tell us what product you have, who is asking you for what and what team you have. We will tell you which of the five fits, even if it is the cheapest one.

No commitment and no jargon. A specialist gets back to you within 24-48 hours.