> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hckrt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackrate for Companies: Ethical Hacking Platform Guide

> Learn how Hackrate helps organizations find vulnerabilities before attackers do, using a global community of ethical hackers and four security services.

Hackrate is an ethical hacking platform that connects your organization with a global community of vetted security researchers. Instead of waiting for malicious actors to discover weaknesses in your systems, Hackrate lets you take a proactive stance: you define what should be tested, researchers find real-world vulnerabilities, and your team receives structured, actionable reports — all within a controlled and transparent environment. Whether you are running a continuous bug bounty program or a time-boxed penetration test, Hackrate centralizes every finding, conversation, and reward in one place.

## What Hackrate offers organizations

Hackrate provides four distinct service types that can be used independently or in combination, depending on your security maturity and compliance requirements.

<CardGroup cols={2}>
  <Card title="Managed Bug Bounty Program" icon="bug">
    Crowdsource continuous security testing by rewarding ethical hackers for valid vulnerability reports. Define your scope, set bounty payouts by severity and asset tier, and receive a steady stream of validated findings as your product evolves.
  </Card>

  <Card title="Penetration Testing as a Service (PTaaS)" icon="shield-halved">
    Commission time-boxed, structured penetration tests conducted by verified researchers. Get deep, methodology-driven assessments with real-time visibility into findings — suitable for compliance audits and pre-release reviews.
  </Card>

  <Card title="Managed Vulnerability Disclosure Policy (mVDP)" icon="envelope-open-text">
    Give security researchers a safe, structured way to report vulnerabilities without offering monetary rewards. Hackrate manages the intake, validation, and communication so you minimize the risk of irresponsible disclosure.
  </Card>

  <Card title="Attack Surface Management" icon="radar">
    Continuously monitor your external attack surface for exposed assets and emerging risks. Identify unknown or forgotten assets before hackers do, and get a clearer picture of your organization's digital footprint.
  </Card>
</CardGroup>

## How the platform is structured

Everything on Hackrate is organized around a clear hierarchy. Understanding this model helps you navigate the platform and delegate the right responsibilities to your team.

**Organization → Program → Target → Report**

* **Organization** — Your company's top-level workspace on Hackrate. It holds one or more programs and allows you to manage team members, permissions, and billing in one place.
* **Program** — A security engagement with its own scope, rules, budget, and lifecycle. A program can be a bug bounty, a PTaaS engagement, or a VDP. Programs can be public (listed in the Hackrate catalog) or private (invite-only).
* **Target** — An individual asset within a program's scope, such as a web application, API, or mobile app. Each target has a type, a severity expectation, and a tier that determines its bounty payout level.
* **Report** — A vulnerability submission from a researcher. Reports are linked to a specific target, triaged by severity, and tracked through resolution.

<Note>
  Hackrate's managed service means that a dedicated team reviews incoming reports for validity and accuracy before they reach your inbox, reducing noise and false positives.
</Note>

## Getting started quickly

<CardGroup cols={2}>
  <Card title="Quickstart" icon="rocket" href="/companies/quickstart">
    Register your account, create your organization, and launch your first program in minutes.
  </Card>

  <Card title="Programs Overview" icon="list-check" href="/companies/programs/overview">
    Understand program types, lifecycle stages, and key configuration options.
  </Card>

  <Card title="Targets & Scope" icon="crosshairs" href="/companies/programs/targets-scope">
    Learn how to define in-scope assets, assign tiers, and manage out-of-scope items.
  </Card>

  <Card title="Account Setup" icon="gear" href="/companies/account-setup">
    Configure your organization, invite team members, and set up notification preferences.
  </Card>
</CardGroup>

## Why organizations choose Hackrate

Automated vulnerability scanners provide a useful baseline, but they cannot replicate the creativity and business context that skilled human researchers bring. Ethical hackers discover logic flaws, chained attack paths, and business-impact vulnerabilities that no scanner will catch. Hackrate's platform gives you full transparency into who is testing, what they found, and what it would cost to remediate — without requiring you to expand your in-house security headcount.

Hackrate is also designed for compliance. Structured vulnerability reports, severity-based prioritization, and audit-ready documentation make it straightforward to demonstrate continuous security testing for ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, and NIS2 frameworks.
