Best Software for 2025 is now live!
Save to My Lists
Paid
Claimed
Optimized for quick response

Bugcrowd Reviews & Product Details

Verified User in Financial Services
AF
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

BugCrowd provides an easy to use interface which enables businesses to get their pen-test scope infront of security researchers in-line with thier current appeite/posture.

Wherther that be initially running with a smaller private program with a limited number of researchers, before expaning to larger public scopes.

Support is fantastic with the team always at the end of a slack message, mail or phone call.

Integration and imeplmentation are simple, allowing the customer to shape the pen-test scope. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

There is nothing for me to say here. Please keep up the great work BugCrowd! Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

Affords us continouse pen-test coverage where our products are evolving daily. Review collected by and hosted on G2.com.

Bugcrowd Overview

What is Bugcrowd?

Bugcrowd frees organizations with a low tolerance for risk from chronic talent shortages, noisy tools that breed false positives, and the fear of critical hidden or emerging vulnerabilities. Our SaaS platform provides access to the unlimited capacity and skills of the global ethical hacker/pentester community for deeper, proactive risk reduction and faster regulatory compliance. With 12+ years of experience and 1200+ customers in every industry (including OpenAI, National Australia Bank, Indeed, USAA, Twilio, and CISA), we know what long-term with crowdsourced security looks like.

Bugcrowd Details
Product Website
Show LessShow More
Product Description

By combining a vast and diverse workforce with a results-driven model, crowdsourced security programs outperform traditional methods-every time.

How do you position yourself against your competitors?

Bugcrowd pioneered the fully managed crowdsourced security model. With more experience in this approach (double the industry average), we’re experts in helping customers around the world detect and remediate more vulnerabilities of higher consequence, in less time, with less overhead. Our extensible platform was purpose-built to multiply the impact of our security experts and hackers, and with the ability to readily scale to meet tomorrow’s challenges, we’re #1 crowdsourced security platform to grow with.

Bugcrowd is the only crowdsourced security platform helping our customers actually improve their security operations. We’re focused on helping you reduce repeat findings, and improve your overall security posture. With enhanced crowd analytics, automated security workflows, richer program insights, and industry-first remediation advice and training integrations, we’ve pushed beyond ‘find and fix’ to help customers actually close gaps, mature their programs, and compound ROI year after year.


Seller Details
Seller
Bugcrowd
Company Website
Year Founded
2012
HQ Location
San Francisco, CA
Twitter
@Bugcrowd
176,128 Twitter followers
LinkedIn® Page
www.linkedin.com
2,962 employees on LinkedIn®
Description

We are a crowdsourced security company that safeguards organizations' assets from sophisticated threat actors before they can strike—by uniting our customers with trusted hackers via our AI-powered platform to take back control and stay ahead of attackers. Bugcrowd is backed by Blackbird Ventures, Costanoa Ventures, Industry Ventures, Paladin Capital Group, Rally Ventures, Salesforce Ventures and Triangle Peak Partners.


ML
Overview Provided by:

Recent Bugcrowd Reviews

Kheman G.
KG
Kheman G.Enterprise (> 1000 emp.)
3.0 out of 5
"Review for G2 bugcrowd"
It's it security architecture that I have studied especially the big bounty program
Verified User
U
Verified UserSmall-Business (50 or fewer emp.)
4.0 out of 5
"Using bugcrowd for security research and bug hunting."
The triage response and also the platform itself.
Jitmanyu S.
JS
Jitmanyu S.Small-Business (50 or fewer emp.)
5.0 out of 5
"Collaborative Crowdsourcing for Enhanced Cybersecurity"
What I appreciate most about Bugcrowd is its collaborative approach to cybersecurity. The platform brings together a diverse community of ethical h...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

Bugcrowd Media

Bugcrowd Demo - Programs Dashboard
View program health status and tasks in real time.
Bugcrowd Demo - Penetration Test Dashboard
Get 24/7, real-time access to pen test timelines, methodology checklist progress, analytics, and findings.
Bugcrowd Demo - Submission Details
See complete details about every submission, including validation checks, triage level, and a communications log.
Bugcrowd Demo - Rewards Page
Get insights into rewards history and stats.
Bugcrowd Demo - Insights Dashboard
See a comprehensive view of program and engagement health, impact, and direction across numerous dimensions.
Bugcrowd Platform Quick Tour
Play Bugcrowd Video
Bugcrowd Platform Quick Tour

Official Interactive Demo

Bugcrowd demo available

Try an interactive demo created by the software seller (right here on G2).

Official Downloads

Answer a few questions to help the Bugcrowd community
Have you used Bugcrowd before?
Yes

45 out of 46 Total Reviews for Bugcrowd

4.3 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
45 out of 46 Total Reviews for Bugcrowd
4.3 out of 5
45 out of 46 Total Reviews for Bugcrowd
4.3 out of 5

Bugcrowd Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for BugcrowdQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Jitmanyu S.
JS
Software Developer
Small-Business(50 or fewer emp.)
Validated Reviewer
Review source: G2 invite
What do you like best about Bugcrowd?

What I appreciate most about Bugcrowd is its collaborative approach to cybersecurity. The platform brings together a diverse community of ethical hackers and security professionals, empowering them to contribute to real-world security challenges. This collective intelligence not only enhances the security posture of organizations but also creates a dynamic environment where continuous learning and skill development are encouraged. Additionally, Bugcrowd's focus on transparency, fairness in rewards, and providing a platform for both experienced and novice hackers to contribute makes it a unique and impactful leader in the field of crowdsourced security. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

One area of improvement for Bugcrowd could be enhancing the communication and feedback loop between researchers and program owners. At times, the response times or clarity of feedback can be inconsistent, which may lead to frustration for researchers who are seeking more timely or detailed guidance on their submissions. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

Bugcrowd addresses the challenge of identifying and mitigating security vulnerabilities by leveraging a global network of skilled ethical hackers. This crowdsourced approach allows organizations to detect and resolve security issues more efficiently than traditional methods. For me, it provides access to diverse security expertise, ensuring a more comprehensive and robust security posture, ultimately reducing the risk of breaches and enhancing overall system resilience. Review collected by and hosted on G2.com.

Jack E.
JE
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

Their account team helped us grow our discoosure program over time into something that we aim to evolve even further into an eventual Bug Bounty program. They help identify and engage the right researchers to get disclosures, without creating duplicate submissions via their triage team.

The account team are flexible and generous in their pricing in order to foster a good partnership, and to remain our vendor of choice for the long term. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

Their integrations are somewhat difficult to set up for things like Jira, and could do with an overhaul to the more modern toolchain service in Jira.

Initial engagement on our program was very slow, and required a lot of convincing of product owners to move to a public program without much evidence of eengagement beforehand. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

Initially our organisation received bug disclosures via our public facing customer service inbox. This lead to a lot of confusion within our customer service team as to what to do about these disclosures. Often these disclosures were also low quality, and often the output of an automated script that targets high-traffic web applications for bugs and a contact email, prospecting us for a financial reward with little to no remediation advice or proof of exploit.

Bugcrowd provides a layer of filtration away from these submissions, their traige team ensure that we do not see low quality or repeat findings, thanks to their knowledge of previous disclosures that we already were dealing with before onboarding them. They put an onus on researchers to provide remediation advice, evidence to support their disclosures and discretion when submitting bugs.

The platform itself also allows us to integrate crowd based testing into our productivity processes, via Jira tickets that are created for findings, that are programatically added to the correct queue and status for prioritisation by agile delivery managers in development teams. Their slack integration also allows for a natural conversation to occur within our organisation whenever a new finding is submitted, keeping both the development and security teams talking about application security. Review collected by and hosted on G2.com.

PP
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

As a client been consistently impressed by the caliber of security submissions and the overall effectiveness of the Bugcrowd community.

A key strength lies in Bugcrowd's capacity to assemble a diverse and highly proficient group of ethical hackers and security experts.

The impressive feature is the submission process is a standout feature, characterized by its streamlined and efficient nature.

The platform's user-friendly interface further enhances this experience, enabling transparent communication, smooth collaboration, and constructive feedback throughout the entirety of the security testing process. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

The payment rule, when a submission hasn't been reviewed by the client for a certain period, is a point of concern. The client may still be in the process of reviewing, and the issue might not be critical for them. Unfortunately, There are few times when Bugcrowd missess to intervene or prompt the client to take action; instead, it automatically processes payment.

On the flip side, it's noteworthy that Bugcrowd does ensure researchers get paid, demonstrating a commitment to compensating their community promptly. However, striking a balance between ensuring timely payments for researchers and allowing clients sufficient time to assess submissions might be an area for improvement in Bugcrowd's process. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

Identifying vulnerabilites in the applications.

Offering support for remediation efforts.

Platform's community consisting skilled ethcical hackers provide diverse perspectives. Review collected by and hosted on G2.com.

AB
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

We are running a bug bounty program with Bugcrowd. It turns out that the technical team triaging incoming submissions is very skilled and helps a lot in efficiently identify and track vulnerabilities in our products so that we can patch them. It is really a pleasure to work with the Bugcrowd team, we have really established a direct, uncomplicated and simple way of working together. It is just fun! Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

Really nothing comes to our mind that we dislike about the service that we have been receiving from Bugcrowd. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

Bugcrowd gives us the opportunity to engage with security researchers around the world that are willing to find vulnerabilities in our products. Not only are we benefitting from it when patching vulnerabilities, we also learn a lot by working together with security researchers and can improve our security development lifecycle. Review collected by and hosted on G2.com.

Kheman G.
KG
Software Engineer
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Bugcrowd?

It's it security architecture that I have studied especially the big bounty program Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

They can have more such incentives and add more bounties that can help people and companies grow Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

It can help me in catching bugs Review collected by and hosted on G2.com.

Verified User in Retail
AR
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

The customer support team goes above and beyond to ensure our bug bounty program is successfully implemented and has a high efficiency and satisfaction rate with researchers, allowing them to hunt for bugs on our platform and strengthen our overall security posture. The system also integrated well with our ticketing platform allowing for seamless distribution of issues to the tech teams to address bugs. The platform is easy to use and intuitive and does not require a steep learning curve to administer. Our rep, Ronelle Green has been a joy to work with as well, Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

Lack of a real time communication platform when attempting to address issues. Communcations are performed via email or messages from the internal platform which can often take time to be seen and addressed. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

BugCrowd helps us identify bugs and logic issues in our products that our testing teams may have missed as part of their testing process. It allows us to strengthen our overall security posture and deliver a robust product to our customers to ensure their information is safeguarded. Review collected by and hosted on G2.com.

Verified User in Entertainment
UE
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

Attack validation and prioritization. Customer support is excellent. The platform is easy to use and provides a number of features that make it easy to integrate with Slack, JIRA, and other platforms. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

The workflow, especially the names of each stage, was not intuitive and required some coaching. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

Bugcrowd platform enabled us to expose multiple platforms/solutions to many ethical hackers to gain a fresh perspective on our security posture and identify issues that we have missed with internal security testing, SAST, and DAST tooling. In a short period, they managed to detect issues that went by unnoticed even by the external penetration testing and we are now in a much better shape. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Organic
What do you like best about Bugcrowd?

We use BugCrowd to run our bug bounty program. The researchers invited to our program have filed reports about a variety of security issues, and it's clear that some of them have really dug into our site's functionality, not just running automated scanners and skimming the surface. We've also been perfectly happy with our CSM and account manager, and BugCrowd's triagers are helpful in rejecting invalid reports. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

Not much negative to say. We do have a recurring issue with not automatically receiving invoices for some reason. Our account manager's always helpful and passes it along quickly when we reach out, but it's a little inconvenient (and odd) that we have to do that. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

We use Bugcrowd to run our bug bounty program. Bugcrowd connects us with researchers who specialize in the relevant area, provides a platform for managing reports and payments, and triages reports. Review collected by and hosted on G2.com.

DS
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

Highly professional triage team. It was easy to integrate with our internal systems. Bugcrowd interface is easy to use. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

Nothing to say for now. No issues or concerns Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

First of all, Bugcrowd helped us look at our current level of security and measure how effective our internal programs are. Findings helped our organization get another look at what we have been missing and helped us close these gaps. Review collected by and hosted on G2.com.

roger k.
RK
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Bugcrowd?

The Bugcrowd team and community is fantastic. I highly recommend using Bugcrowd for bug bounty, vulnerability disclosure and pen testing programs. Review collected by and hosted on G2.com.

What do you dislike about Bugcrowd?

I have no notes. I love the service and the system that's built around it. Review collected by and hosted on G2.com.

What problems is Bugcrowd solving and how is that benefiting you?

Bugcrowd has delivered a managed bug bounty and vulnerability disclosure program that has been maintainable with the help of the Bugcrowd team. Review collected by and hosted on G2.com.