Yogosha
Yogosha is a Paris-based offensive security testing platform, founded in 2015, that runs Pentest-as-a-Service, Bug Bounty, VDP, and Live Hacking Event programs for 300+ enterprise and government clients across 12 countries, powered by a private community of 1,100+ vetted security researchers and an AI-assisted triage layer.
- Company typePrivate
- Founded2015
- HeadquartersParis, France
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Yogosha does
Yogosha is a Paris-based offensive security testing platform founded in 2015 that helps organizations continuously discover and remediate vulnerabilities in their digital assets. The company operates a portfolio of complementary security testing services — Pentest as a Service (PtaaS) for periodic expert-led penetration tests at fixed cost, Bug Bounty for continuous crowdsourced vulnerability discovery on a pay-per-valid-finding basis, Vulnerability Disclosure Programs (VDP) for open-ended disclosure intake, Live Hacking Events for intensive event-based testing, and Special Operations covering red teaming, hardware pentesting, social engineering, digital forensics, and CTFs. At the center of the offering is the Yogosha Strike Force, a private community of 1,100+ vetted security researchers (10% acceptance rate) holding certifications such as OSCP, OSEP, and eWPTXv2, supported by a central platform with real-time risk dashboards, CVSS-scored reporting, remediation guidance, and retest tracking. An AI-assisted triage layer, running on self-hosted private LLM infrastructure, pre-qualifies vulnerability submissions for scope and duplicates.
The company serves 300+ customers across 12 countries and 6 industries, with particular depth in banking and financial services (BNP Paribas, Swiss Life), government and defense (French Ministry of Armed Forces, French Ministry of the Interior), telecommunications (Bouygues Telecom), aviation (Groupe ADP), energy (Terega), e-commerce (Veepee, leboncoin), retail (Zadig & Voltaire), and cloud (Scalingo, Dataiku, Stormshield). Revenue is generated through a mix of recurring subscriptions (PtaaS, VDP), transaction-based fees (bug bounties), professional services (live events, special operations), and white-label licensing to Telcos, MSSPs, and SOC operators through a Strategic Partner Alliance. Go-to-market combines direct enterprise field sales, a self-serve platform for mid-market adoption, and a two-tier partner channel. The company has raised approximately €15M cumulatively across rounds from 2016 to 2022, including a €10M Series A in January 2022 led by Tikehau Ace Capital with participation from OneRagtime and BNP Paribas Développement. Headcount is reported in the 11–50 range.
Yogosha firmographics
Firmographics- Name
- Yogosha
- Legal name
- YOGOSHA
- Website
- https://yogosha.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Yogosha is a Paris-based offensive security testing platform, founded in 2015, that runs Pentest-as-a-Service, Bug Bounty, VDP, and Live Hacking Event programs for 300+ enterprise and government clients across 12 countries, powered by a private community of 1,100+ vetted security researchers and an AI-assisted triage layer.
- Ownership category
- akta.pro rank
Yogosha industry classification
Industry- Product category
- Offensive Security Testing Platform
- NAICS
- Investigation and Personal Background Check Services (561611)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK)
Keywords
Where Yogosha is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices2 records
Markets served
Yogosha business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Pentest as a Service (PtaaS): Deploy small team of skilled security researchers for point-in-time or periodic security testing at fixed cost. Coverage guaranteed with vetted researchers and fully documented vulnerability reports.
- Bug Bounty: Deploy large team of security researchers for continuous testing where customers pay only when valid vulnerabilities are submitted. Access to private community of 800+ researchers with pay-per-finding model.
- Vulnerability Disclosure Program (VDP): Allow anyone to securely submit potential vulnerabilities following organization instructions, typically lower-cost entry-level service for continuous monitoring.
- Live Hacking Events: Real-time hacking events for conventions and corporate events where invited hackers participate in competitive security testing.
- Strategic Partner Licensing: Self-hosting licensing model for partners (Telcos, MSSPs, SOCs) to offer their own crowdsourced security services, with subscription and wallet-based consumption model for end customers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Pentest as a Service - Fixed cost deployment |
| Transaction based/ take rate | Pay-as-you-go | Bug Bounty - Pay-per-valid-vulnerability |
| Subscription | Annual | VDP - Vulnerability Disclosure Program |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels7 records
Yogosha product offering
Product offeringCore offering
Yogosha is an offensive security testing platform that enables organizations to launch and manage penetration tests, bug bounty programs, vulnerability disclosure programs (VDP), and live hacking events. The platform connects organizations with a vetted community of 1,100+ security researchers (Yogosha Strike Force) to continuously identify and remediate vulnerabilities in digital assets, augmented by AI-assisted triage.
Product overview
Yogosha is an offensive security platform offering a portfolio of security testing services centered around its Offensive Security Testing Platform. The core offerings include Pentest as a Service (PtaaS) for periodic expert-led penetration testing, Bug Bounty for continuous crowdsourced vulnerability discovery, Vulnerability Disclosure Program (VDP) for open-ended disclosure, and Live Hacking Events for intensive event-based testing. These services are powered by the Yogosha Strike Force, a private community of 1100+ vetted security researchers with professional certifications. The platform itself provides end-to-end orchestration including real-time risk dashboards, vulnerability triage, CVSS scoring, remediation guidance, and retest tracking.
Differentiator
Problem solved
Functional benefit
Products and services
- Pentest as a Service (PtaaS) Subscription-based, agile penetration testing service that provides continuous, on-demand security assessments of an organization's digital assets. Delivered through the Yogosha platform by vetted researchers (Yogosha Strike Force) targeting infrastructure, web, mobile, and cloud environments.
- Bug Bounty Private and public bug bounty programs that invite vetted security researchers to discover and report vulnerabilities on a pay-per-finding basis, with triage, severity scoring, and remediation tracking built into the platform.
- Vulnerability Disclosure Program (VDP) Structured disclosure program enabling external security researchers to report vulnerabilities safely and legally, providing organizations a continuous intake channel for vulnerability reports outside of paid bounty engagements.
- Live Hacking Events Time-bounded, focused hacking engagements that bring together vetted Yogosha Strike Force researchers to test specific scopes or product launches, producing concentrated vulnerability findings over a short window.
- Yogosha Offensive Security Testing Platform The underlying SaaS platform used to scope, launch, run, and triage offensive security engagements; integrates with customer workflows and provides AI-assisted triage, scope management, asset coverage, and vulnerability lifecycle reporting.
- Special Operations Bespoke offensive engagements including Red Teaming, Threat Intelligence, Hardware Pentesting, Social Engineering, Digital Forensics, and Capture-The-Flag exercises, delivered by Strike Force researchers for high-assurance or specialized scenarios.
Quantifiable outcome
- Launch and manage security tests in 48 hours
- +4 more outcomes
Companies that use Yogosha
Customer profileNamed customers10 records
Segments6 records
Ideal customer profiles4 records
Yogosha technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability6 records
Feature5 records
Yogosha partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- OctopiancoreStrategic partner logo displayed on the Strategic Partner Alliance page, indicating a partner that self-hosts Yogosha technology to offer crowdsourced security services.
Scale indicators6 records
Recent moves5 records
Expansion highlights6 records
Yogosha competitors and assessment
Company assessmentDirect peers
- HackerOne: Market-leading bug bounty and vulnerability disclosure platform with the largest global hacker community and enterprise customer base. Closest direct competitor to Yogosha in offensive security testing services.
- Cobalt: Pentest as a Service platform connecting customers with a vetted global researcher community for on-demand penetration testing. Direct competitor in the PtaaS segment that overlaps with Yogosha's core offering.
- YesWeHack: French/European bug bounty platform offering crowdsourced security programs with a strong European researcher community. Direct competitor with overlapping geography, customer base (large French/European enterprises), and product portfolio.
- Bugcrowd: Global crowdsourced cybersecurity platform offering bug bounty, vulnerability disclosure, and pentest programs backed by a large researcher community. Direct head-to-head competitor to Yogosha across all service lines and customer segments.
- Synack: Hybrid crowdsourced pentest platform combining a vetted researcher network with proprietary technology for enterprise security testing. Comparable model in combining vetted talent pool with a managed platform targeting large enterprises.
- Intigriti: Belgium-based bug bounty and crowdsourced security platform serving European enterprises. Direct competitor focused on the same European mid-market and enterprise segments as Yogosha, with similar product lineup.
Broad incumbents
- NCC Group: Global cybersecurity consultancy offering traditional penetration testing, red teaming, and managed security services. Broader incumbent competing for the same enterprise pentest and red team budgets as Yogosha.
- Outpost24: European cybersecurity vendor offering vulnerability management, attack surface monitoring, and penetration testing services. Broader incumbent with overlapping offensive security services for enterprise customers.
Emerging players
- Pentera: Automated security validation platform for continuous penetration testing using automated attack simulations. Adjacent competitor addressing similar pentest budgets with a different (automated) approach.
- Detectify: Crowdsourced vulnerability scanning and asset monitoring platform with a researcher community feeding detection content. Adjacent competitor in the offensive testing space, primarily via external attack surface testing.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
Yogosha social profiles
Digital presenceYogosha compliance and trust
Trust signalCompliance2 records
Yogosha financial estimates
Financial estimateRevenue estimate
Valuation estimate
Yogosha leadership team
Management profileNumber of profiles
Profiles5 records
Yogosha funding detail
Funding detailFunding overview
Funding rounds4 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Yogosha M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Yogosha
What does Yogosha do?
Yogosha is an offensive security testing platform that enables organizations to launch and manage penetration tests, bug bounty programs, vulnerability disclosure programs (VDP), and live hacking events. The platform connects organizations with a vetted community of 1,100+ security researchers (Yogosha Strike Force) to continuously identify and remediate vulnerabilities in digital assets, augmented by AI-assisted triage.
Is Yogosha a public or private company?
Yogosha is a private company. It is classified as venture growth investor backed and is currently operating.
When was Yogosha founded?
Yogosha was founded in 2015. It employs 11 to 50 people.
Where is Yogosha based?
Yogosha is headquartered in Paris, France, in the Europe region.
How does Yogosha make money?
Five revenue lines are on record. Pentest as a Service (PtaaS) is the primary driver. The others are bug Bounty, vulnerability Disclosure Program (VDP), live Hacking Events and strategic Partner Licensing.
Who are Yogosha's main competitors?
Direct peers on record are HackerOne, Cobalt, YesWeHack, Bugcrowd, Synack and Intigriti. Broad incumbents are NCC Group and Outpost24. Emerging players are Pentera and Detectify.
Does Yogosha have an API?
No public API is recorded for Yogosha.
What industry is Yogosha in?
Yogosha's product category is Offensive Security Testing Platform. Its primary akta.pro industry code is FSAPAJAK, Security Testing Tooling (SAST/DAST for smart contracts, fuzzing). Its NAICS code is 561611 and its SIC code is 8734.