What Hackrate offers organizations
Hackrate provides four distinct service types that can be used independently or in combination, depending on your security maturity and compliance requirements.Managed Bug Bounty Program
Crowdsource continuous security testing by rewarding ethical hackers for valid vulnerability reports. Define your scope, set bounty payouts by severity and asset tier, and receive a steady stream of validated findings as your product evolves.
Penetration Testing as a Service (PTaaS)
Commission time-boxed, structured penetration tests conducted by verified researchers. Get deep, methodology-driven assessments with real-time visibility into findings — suitable for compliance audits and pre-release reviews.
Managed Vulnerability Disclosure Policy (mVDP)
Give security researchers a safe, structured way to report vulnerabilities without offering monetary rewards. Hackrate manages the intake, validation, and communication so you minimize the risk of irresponsible disclosure.
Attack Surface Management
Continuously monitor your external attack surface for exposed assets and emerging risks. Identify unknown or forgotten assets before hackers do, and get a clearer picture of your organization’s digital footprint.
How the platform is structured
Everything on Hackrate is organized around a clear hierarchy. Understanding this model helps you navigate the platform and delegate the right responsibilities to your team. Organization → Program → Target → Report- Organization — Your company’s top-level workspace on Hackrate. It holds one or more programs and allows you to manage team members, permissions, and billing in one place.
- Program — A security engagement with its own scope, rules, budget, and lifecycle. A program can be a bug bounty, a PTaaS engagement, or a VDP. Programs can be public (listed in the Hackrate catalog) or private (invite-only).
- Target — An individual asset within a program’s scope, such as a web application, API, or mobile app. Each target has a type, a severity expectation, and a tier that determines its bounty payout level.
- Report — A vulnerability submission from a researcher. Reports are linked to a specific target, triaged by severity, and tracked through resolution.
Hackrate’s managed service means that a dedicated team reviews incoming reports for validity and accuracy before they reach your inbox, reducing noise and false positives.
Getting started quickly
Quickstart
Register your account, create your organization, and launch your first program in minutes.
Programs Overview
Understand program types, lifecycle stages, and key configuration options.
Targets & Scope
Learn how to define in-scope assets, assign tiers, and manage out-of-scope items.
Account Setup
Configure your organization, invite team members, and set up notification preferences.