What Bugcrowd does, how its bug bounty, PTaaS and attack surface management platform works, current funding and ownership status, pricing model, pros and cons.
Bugcrowd was founded in 2012 on the premise that a single internal security team, or even a single external penetration testing firm, cannot match the breadth of perspective that thousands of independent researchers bring to finding vulnerabilities. The company built a platform, CrowdControl, that manages the entire lifecycle of a crowdsourced security engagement: recruiting and vetting researchers, matching them to a customer's program based on skill and track record through its CrowdMatch technology, triaging and validating submitted vulnerability reports against its Vulnerability Rating Taxonomy, and handling researcher payouts.
Over more than a decade, Bugcrowd has grown from a pure bug bounty broker into a broader security platform. Its program types now span fully public bug bounty programs, private invite-only bounty programs, no-reward vulnerability disclosure programs often used to satisfy compliance requirements, and Penetration Testing as a Service, which packages traditional scoped pentests into the same platform and researcher network rather than a standalone consulting engagement.
Bugcrowd has expanded its product scope through acquisition in recent years. In May 2024 it acquired Informer, an attack surface management company, giving Bugcrowd customers a way to continuously discover and inventory their external-facing assets -- domains, subdomains, cloud services, and exposed endpoints -- as an input into where crowdsourced testing should be focused. In 2025, Bugcrowd acquired Mayhem Security, an AI-driven security testing company, signaling a broader industry push to combine human researcher talent with automated and AI-assisted vulnerability discovery.
These moves position Bugcrowd against a security market that increasingly expects a single platform to cover asset discovery, continuous testing, and structured penetration testing rather than three disconnected vendors and contracts. Bugcrowd has backed this platform strategy with substantial capital: a $102 million strategic growth round in February 2024 led by General Catalyst, on top of an earlier Seed-through-Series-D funding history dating back to 2013, plus later debt financing -- funding that the company has said is earmarked partly for strategic mergers and acquisitions as well as geographic expansion across EMEA and APAC.
Bugcrowd does not publish a public price list, which is standard practice among crowdsourced security platforms because program cost depends heavily on scope, the size of the bounty pool an organization is willing to fund, the volume of assets in scope, and whether a customer wants a public program, a private program, a VDP, or a PTaaS engagement. Third-party industry estimates commonly cited in security procurement research put no-reward VDPs starting around $10,000 per year, managed PTaaS retainers from roughly $25,000 per year, and full private bug bounty programs -- platform fee plus bounty pool -- frequently landing between $80,000 and $150,000 per year for mid-market organizations, though actual contract terms are negotiated directly with Bugcrowd's sales team.
Given this pricing structure, Bugcrowd is realistically aimed at mid-market and enterprise organizations with a mature enough security program to budget for ongoing researcher-driven testing, rather than early-stage startups looking for a free or low-cost vulnerability scanning tool. Organizations already running periodic penetration tests or considering a first formal vulnerability disclosure policy are Bugcrowd's most natural entry points, with the option to expand into full bug bounty and attack surface management as the security program matures.
Bugcrowd operates a crowdsourced cybersecurity platform that connects organizations with independent security researchers to run bug bounty programs, vulnerability disclosure programs, penetration-testing-as-a-service engagements, and attack surface management, all managed through its CrowdControl platform.
Bugcrowd does not publish public pricing. Costs are quoted individually based on program type and scope; third-party estimates suggest VDPs starting around $10,000 per year and full private bug bounty programs often landing between $80,000 and $150,000 per year including bounty pool funding.
Bugcrowd was founded in 2012 in Sydney, Australia, by Casey Ellis, Chris Raethke, and Sergei Belokamen. The company later relocated its primary headquarters to San Francisco.
No, Bugcrowd is a privately held, venture-backed company as of this research. It has raised significant funding, including a $102 million strategic growth round in 2024, but has not gone public.
Bug bounty programs pay a crowd of researchers per validated vulnerability found, typically on an ongoing basis. PTaaS delivers a structured, time-boxed penetration test with a defined scope, similar to a traditional pentest engagement, but coordinated through Bugcrowd's platform and researcher network.
Bugcrowd acquired attack surface management company Informer in May 2024 and AI-driven security testing firm Mayhem Security in 2025, expanding its platform beyond pure crowdsourced bug bounty services.
Both are established crowdsourced security platforms offering bug bounty, VDP, and pentest services with overlapping researcher communities and enterprise customer bases; differences tend to come down to platform tooling, researcher pool composition, and account-specific pricing, so organizations typically evaluate both directly.
Bugcrowd is an enterprise, quote-based security platform rather than a self-serve SaaS product, so there is no standard public free trial; prospective customers typically go through a sales consultation to scope a program.