TrustRadius: an HG Insights company

Bugcrowd

Score10 out of 10

2 Reviews and Ratings

What is Bugcrowd?

Bugcrowd connects companies' security and dev teams to vetted and talented security researchers worldwide to run crowd-powered private and public bug bounty programs.

Categories & Use Cases

Media

the Bug Bounty Summary Page
the Pen Test Dashboard
the Insights Dashboard

1 / 3

Great results for a great price.

Pros

  • Having a pool of security researchers helps keep the penetration tests broad, getting the most bang for your buck.
  • The integration with Slack makes it easy to keep tabs on the program and when new findings are submitted.
  • The interface is pretty simple to use and fairly intuitive.

Cons

  • The success of your program highly depends on the moderator that is assigned to your project. A good moderator will continue to find researchers until the quota is full. Less than stellar moderators will send out one invite and sees what sticks.
  • Not all researchers are as professional as one might hope. This can ruin the experience.

Return on Investment

  • We have received some great results for a great price. We've also received some poor results at the same price.
  • Bugcrowd is not always recognized as a "real" penetration test, but for the most part, we have not had any problems with customer accepting our reports.
  • Overall, Bugcrowd has been an overall good experience, but we have had a poor moderator from time-to-time that has resulted in less than ideal results.

Alternatives Considered

HackerOne

Other Software Used

Atlassian Confluence, JIRA Software, Slack, G Suite, Splunk Cloud, Lever, Expensify, Egencia