YesWeHack
- Company typePrivate
- Founded2015
- HeadquartersParis, France
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
YesWeHack firmographics
Firmographics- Name
- YesWeHack
- Legal name
- YesWeHack
- Website
- https://yeswehack.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Ownership category
- akta.pro rank
YesWeHack industry classification
Industry- Product category
- Offensive Security and Exposure Management
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where YesWeHack is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
YesWeHack business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Bug Bounty Program Management: YesWeHack charges organizations to run Bug Bounty programs where they pay rewards only for valid, actionable vulnerability reports. The platform facilitates program creation, hunter management, triage, and reward distribution. Revenue is generated through program management fees and transaction-based bounty payouts.
- Autonomous & Continuous Pentesting: Subscription-based pricing for continuous and autonomous pentesting services. Organizations pay for ongoing security testing coverage with automated and human-led assessments.
- Pentest Management Platform: Platform fees for managing pentest engagements, consolidating findings, and generating compliance reports. May be bundled with testing services or offered as standalone.
- Triage Services: Optional add-on service where YesWeHack's in-house triage team validates, reproduces, and enriches vulnerability reports. Part of the fully managed service offering.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Annual | Custom enterprise pricing based on program scope, asset count, and service level |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
YesWeHack product offering
Product offeringCore offering
YesWeHack operates a Continuous Offensive Security and Exposure Management platform that combines crowdsourced Bug Bounty programs leveraging a community of 150,000+ ethical hackers, AI-driven Autonomous and Agentic Penetration Testing, human-led Continuous Pentesting, and a Vulnerability Disclosure Policy (VDP) service. The unified platform aggregates findings from all sources and provides in-house triage, AI-augmented vulnerability management, and compliance-ready reporting for enterprise and government customers.
Product overview
YesWeHack is a Continuous Offensive Security and Exposure Management platform that operates as a unified platform-plus-modules architecture. The core platform unifies vulnerability management across five integrated products: Bug Bounty Programs (crowdsourced vulnerability discovery via 150,000+ ethical hackers), Continuous Pentesting (human-led ongoing testing with zero false positives), Autonomous Pentest (automated attack surface monitoring against actively exploited CVEs), Agentic Pentest (on-demand AI-agent-driven penetration testing), and Vulnerability Disclosure Policy (passive coordinated disclosure). Supporting modules include Pentest Management (orchestrating external pentest engagements), Live Hacking Events (in-person bug bounty competitions), and AI Vulnerability Management (AI-augmented triage, prioritisation, and reporting across all solutions). The platform is EU-hosted with full GDPR compliance, ISO 27001 certified and CREST accredited.
Differentiator
Problem solved
Functional benefit
Products and services
- Bug Bounty Program Crowdsourced vulnerability discovery platform giving organisations access to a global community of 150,000+ skilled ethical hackers to continuously audit and test their attack surface for high-impact vulnerabilities, with financial rewards (bounties) paid for valid findings. Supports private (invited hunters) and public (open to all) programs, plus Live Hacking Events.
- Continuous Pentesting Human-led, ongoing security testing service that combines real-time attack surface visibility with targeted security checkpoints and agentic pentesting guided by experienced researchers. Provides two layers of human validation (hunters and triagers) ensuring zero false positives, with automated audit-ready reporting aligned to SOC2 and ISO 27001.
- Autonomous Pentest Continuous, automated penetration testing platform providing real-time discovery and monitoring of internet-facing assets combined with targeted security checkpoints assessing the attack surface against vulnerabilities actively exploited in the wild. Supports the full CTEM cycle across five phases: Scoping, Discovery, Prioritisation, Validation, and Mobilisation.
- Agentic Pentest On-demand offensive security solution using autonomous AI agents to test web applications, mobile apps, APIs, and internet-facing assets for vulnerabilities, delivering same-day findings. Supports black box, grey box, and white box testing methodologies. Integrated into the unified platform alongside Bug Bounty and Continuous Pentesting. Built on frontier AI models including open-weight models and shaped by YesWeHack's bug hunting experience.
- Vulnerability Disclosure Policy (VDP) A secure, public, passive mechanism allowing any good-faith researcher to report vulnerabilities in an organisation's internet-facing assets, compliant with ISO 29147 and ISO 30111 standards and advocated by NIST, ENISA, and CISA. Provides a branded, customisable template with end-to-end encrypted reporting channel and optional in-house expert triage.
- Pentest Management Centralised platform for orchestrating and managing all penetration testing engagements through a unified interface. Consolidates findings from multiple pentest sources into a single reporting format, enables real-time collaboration with pentesters, automates report generation for compliance, and integrates with ticketing systems and the YesWeHack API.
- Live Hacking Events Time-bound bug bounty competitions, typically attended in person by hunters, offering organisations access to some of the world's top security researchers. YesWeHack assists with feasibility evaluation, planning, budgeting, and hunter selection for focused, high-intensity testing events.
- Sekost Cybersecurity Audit Services Cybersecurity audit services provided through Sekost, a company acquired by YesWeHack in 2025. Sekost customers gain access to Agentic Pentest and other offensive security solutions following the acquisition, extending YesWeHack's platform to cybersecurity audit customers.
Quantifiable outcome
- 30% of reports filtered by triage team as duplicates, out-of-scope, or missing PoC
- +3 more outcomes
Companies that use YesWeHack
Customer profileNamed customers15 records
Segments4 records
Ideal customer profiles4 records
YesWeHack technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability12 records
Feature6 records
YesWeHack partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- SekostcoreYesWeHack acquired Sekost, a cybersecurity audit company, in 2025. The acquisition expands YesWeHack's capabilities to serve Sekost customers with Agentic Pentest and other offensive security solutions. Sekost's customer base will gain access to YesWeHack's integrated platform.
- AWS MarketplacecoreYesWeHack is available on AWS Marketplace, enabling AWS customers to purchase and deploy YesWeHack solutions through their existing AWS accounts. This marketplace listing expands distribution reach to enterprise buyers preferring cloud marketplace procurement.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
YesWeHack competitors and assessment
Company assessmentEmerging players
- Pentera: Automated security validation platform that simulates adversary techniques against enterprise infrastructure. Comparable to YesWeHack's Autonomous and Agentic Pentest offerings, though focused on internal rather than external attack surface validation.
- Detectify: Automated external attack surface monitoring and vulnerability scanning platform. Adjacent to YesWeHack's Autonomous Pentest product; competes for the same attack-surface-management buyer but with a more automated, less human-touched model.
Broad incumbents
- Mandiant (Google Cloud): Large-scale threat intelligence and incident response provider (now part of Google Cloud) with offensive security capabilities. Adjacent incumbent with broader portfolio including IR and threat intel that complements offensive testing use cases YesWeHack addresses.
- NCC Group: Global cybersecurity services provider with a sizable offensive security and assurance practice. Comparable to YesWeHack's enterprise services portfolio but delivered as a broad consultancy rather than a focused crowdsourced/AI platform.
- Bishop Fox: Established offensive security services firm offering traditional pentesting, red team, and attack surface services. Overlaps with YesWeHack's continuous and agentic pentest offerings but delivers via consulting engagements rather than a self-serve platform.
Direct peers
- Synack: Offensive security platform offering on-demand penetration testing via a curated researcher network (Synack Red Team). Comparable to YesWeHack's Continuous Pentesting and Bug Bounty offerings, particularly for regulated enterprise buyers.
- Cobalt: Pentest-as-a-service platform connecting enterprises to a vetted community of testers. Directly comparable to YesWeHack's Continuous Pentesting and Pentest Management products in workflow, buyer profile, and use case.
- Bugcrowd: Crowdsourced cybersecurity platform combining bug bounty, vulnerability disclosure, and pentest-as-a-service. Directly comparable to YesWeHack's combined bug bounty, VDP, and pentest management offerings across similar enterprise buyer segments.
- HackerOne: Largest global bug bounty and vulnerability disclosure platform with the broadest enterprise customer base. Most direct competitor to YesWeHack's core bug bounty product; differs primarily by being US-headquartered with stronger North American enterprise penetration.
- Intigriti: European-headquartered bug bounty and crowdsourced security platform headquartered in Belgium. Closest geographic and product overlap with YesWeHack; competes head-to-head for European enterprise and public-sector programs.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
YesWeHack social profiles
Digital presenceYesWeHack compliance and trust
Trust signalCompliance5 records
YesWeHack financial estimates
Financial estimateRevenue estimate
Valuation estimate
YesWeHack leadership team
Management profileNumber of profiles
Profiles5 records
YesWeHack subsidiaries and ownership
Company hierarchySubsidiaries1 record
YesWeHack funding detail
Funding detailFunding overview
Funding rounds3 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
YesWeHack M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about YesWeHack
What does YesWeHack do?
YesWeHack operates a Continuous Offensive Security and Exposure Management platform that combines crowdsourced Bug Bounty programs leveraging a community of 150,000+ ethical hackers, AI-driven Autonomous and Agentic Penetration Testing, human-led Continuous Pentesting, and a Vulnerability Disclosure Policy (VDP) service. The unified platform aggregates findings from all sources and provides in-house triage, AI-augmented vulnerability management, and compliance-ready reporting for enterprise and government customers.
Is YesWeHack a public or private company?
YesWeHack is a private company. It is classified as venture growth investor backed and is currently operating.
When was YesWeHack founded?
YesWeHack was founded in 2015. It employs 101 to 250 people.
Where is YesWeHack based?
YesWeHack is headquartered in Paris, France, in the Europe region.
How does YesWeHack make money?
Four revenue lines are on record. Bug Bounty Program Management is the primary driver. The others are autonomous & Continuous Pentesting, pentest Management Platform and triage Services.
Who are YesWeHack's main competitors?
Emerging players on record are Pentera and Detectify. Broad incumbents are Mandiant (Google Cloud), NCC Group and Bishop Fox. Direct peers are Synack, Cobalt, Bugcrowd, HackerOne and Intigriti.
Does YesWeHack have an API?
Yes. YesWeHack offers a public API with OAuth and Personal Access Token (PAT) authentication methods. The platform provides API endpoints for integrating vulnerability management, bug bounty report processing, and security testing workflows. Documentation is available at both https://apps.yeswehack.com/doc (OAuth) and https://api.yeswehack.com/doc (PAT). An MCP (Model Context Protocol) server is available, specifically a Burp Suite MCP Server extension that exposes HTTP history and request replay to AI models for LLM-assisted bug bounty hunting workflows. Developer documentation is at api.yeswehack.com/doc.
What industry is YesWeHack in?
YesWeHack's product category is Offensive Security and Exposure Management. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services. Its NAICS code is 561621 and its SIC code is 7372.