Informer
Bugcrowd is a private crowdsourced cybersecurity platform connecting enterprise security teams with a global community of vetted ethical hackers via bug bounty, PTaaS, RTaaS, VDP, and attack surface management, augmented by an applied AI layer (Savant, CrowdMatch, AI Pen Test).
- Company typePrivate
- Founded2014
- HeadquartersBrighton, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Informer does
Bugcrowd is a private crowdsourced cybersecurity company that operates a two-sided marketplace connecting enterprise security buyers with a global community of vetted ethical hackers and penetration testers. Its core platform supports bug bounty programs (pay-for-results), Penetration Testing as a Service (PTaaS) with specialized variants across web, mobile, network, API, IoT, cloud, and social engineering, Red Team as a Service (RTaaS), Vulnerability Disclosure Programs (VDP), and Attack Surface Management. The platform is augmented by an applied AI layer — including the Savant strategy, Savant Vista dashboard, CrowdMatch researcher-matching engine, AI Pen Test, and AI Bias Assessment — and by a proprietary Vulnerability Rating Taxonomy used to standardize severity classification.
Bugcrowd's business model combines outcome-based revenue (customers pay only for verified vulnerability findings in bug bounty programs) with subscription-based revenue on PTaaS and VDP engagements and managed-service pricing on RTaaS. All pricing is quote-based and not publicly disclosed, distributed through a direct enterprise field-sales motion targeting CISOs and security leadership and supported by self-service platform capabilities, integrations with Slack and JIRA, and a partner ecosystem. Buyer segments span Technology (the primary vertical, including Atlassian, OpenAI, Pinterest, Indeed, HP, Motorola), Telecommunications (T-Mobile), Financial Services (Mastercard), Government (NASA), Cybersecurity (Sophos), and SaaS (ActiveCampaign), with additional solutions tailored to Healthcare, Retail, and Automotive.
The company differentiates through its crowdsourced community moat — a curated, trained, and ranked researcher base built via Bugcrowd University, leaderboards, Discord, and CrowdStream — and through operational services such as Triage that reduce internal security team workload. Customer-reported outcomes include 30% reduction in breach risk, 7x more critical vulnerabilities found versus traditional testing, 268% ROI, 60%+ triage-workload reduction (Rubrik), $60M in savings (Motorola), and $158M in estimated impact from remediated vulnerabilities (enterprise banking customer). The company is privately held with no public listing or ticker disclosed, and no parent company, M&A history, headquarters, founding date, headcount, or funding-round data were disclosed in the source material.
Informer firmographics
Firmographics- Name
- Informer
- Website
- https://informer.io
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Bugcrowd is a private crowdsourced cybersecurity platform connecting enterprise security teams with a global community of vetted ethical hackers via bug bounty, PTaaS, RTaaS, VDP, and attack surface management, augmented by an applied AI layer (Savant, CrowdMatch, AI Pen Test).
- Ownership category
- akta.pro rank
Informer industry classification
Industry- Product category
- Crowdsourced Cybersecurity Platform
- NAICS
- Computer Systems Design and Related Services (54151), Other Computer Related Services (541519)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
Keywords
Where Informer is headquartered
LocationHeadquarters
- HQ city
- Brighton
- HQ country
- United Kingdom
- HQ region
- Europe
Markets served
Informer business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Bug Bounty Programs: Outcome-based model where customers pay for verified vulnerability findings. Continuously hunt for hidden, unknown vulnerabilities with payment tied to results.
- Penetration Testing as a Service (PTaaS): Subscription-based penetration testing with agile, transparent testing informed by Attack Surface Management. Meet compliance goals and reduce risk faster.
- Red Team as a Service: Continuous simulation of real-world threats to uncover tactical, operational, and strategic risks.
- Vulnerability Disclosure Programs: Receive, prioritize, and remediate vulnerability submissions from external hackers around the world.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Outcome Based/ Performance | Pay-as-you-go | Enterprise Security Programs |
| Subscription | Annual | Pen Testing as a Service |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels11 records
Informer product offering
Product offeringCore offering
Bugcrowd operates a crowdsourced cybersecurity platform that connects enterprise security teams with a global community of vetted ethical hackers to discover and remediate hidden vulnerabilities. Core offerings include outcome-based Bug Bounty programs, subscription-based Penetration Testing as a Service (with specialized variants for web, mobile, network, API, IoT, cloud, and social engineering), Red Team as a Service, Vulnerability Disclosure programs, and Attack Surface Management. The platform is augmented by AI-powered capabilities including Savant (preemptive security strategy), engineered Triage, CrowdMatch researcher matching, and the Vulnerability Rating Taxonomy.
Product overview
Bugcrowd is a crowdsourced cybersecurity platform offering a comprehensive suite of security testing services. The core Bugcrowd Platform connects organizations with a global community of ethical hackers to discover and remediate vulnerabilities. The platform is enhanced by AI-Powered Security Intelligence features including Triage, CrowdMatch™ for researcher matching, and Savant for preemptive AI-driven security. Services include Bug Bounty programs (continuous vulnerability hunting with pay-for-results model), Vulnerability Disclosure Programs (VDP), and Pen Test as a Service (PTaaS) with specialized variants including Web Application, Mobile App, Network, API, IoT, Cloud, and Social Engineering pen tests. Red Team as a Service provides adversary simulation, while Attack Surface Management enables external asset discovery. The portfolio spans offensive security testing, vulnerability coordination, AI security assessments, and continuous security monitoring.
Differentiator
Problem solved
Functional benefit
Products and services
- Bugcrowd Platform A crowdsourced cybersecurity platform that connects organizations with ethical hackers to discover and remediate vulnerabilities through bug bounty programs, penetration testing, and vulnerability disclosure. Built for enterprise security teams.
- Bug Bounty Crowdsourced vulnerability discovery program where organizations engage ethical hackers to find hidden vulnerabilities and only pay for verified results. Continuously hunts for hidden, unknown vulnerabilities with payment tied to verified findings.
- Vulnerability Disclosure Vulnerability Disclosure Program (VDP) service for receiving, prioritizing, and remediating vulnerability submissions from external hackers around the world.
- Pen Test as a Service (PTaaS) Agile penetration testing service with transparent testing informed by Attack Surface Management, meeting compliance goals and reducing risk faster.
- Web Application Pen Test Specialized penetration testing service focused on web applications to identify vulnerabilities in web-based systems.
- Mobile App Pen Test Security testing service for mobile applications on iOS and Android platforms.
- Network Pen Test Penetration testing service focused on network infrastructure and configurations.
- API Pen Test Security testing service focused on application programming interfaces (APIs) to identify vulnerabilities in API endpoints and integrations.
- IoT Pen Test Penetration testing service for Internet of Things (IoT) devices and embedded systems.
- Cloud Pen Test Security testing service for cloud infrastructure including AWS, Azure, and Google Cloud environments.
- Social Engineering Pen Test Penetration testing service that simulates social engineering attacks to assess organizational vulnerability to human-targeted threats.
- AI Pen Test AI-enhanced penetration testing service leveraging artificial intelligence to identify and assess security vulnerabilities.
- Red Team as a Service (RTaaS) Continuous adversary simulation service that uncovers tactical, operational, and strategic risks through real-world threat simulation.
- AI Bias Assessment Security assessment service focused on identifying and evaluating bias in AI systems and machine learning models.
- Attack Surface Management External Attack Surface Management service to discover, monitor, and manage organizational digital assets and potential entry points for attackers.
- Savant Vista AI-powered security intelligence dashboard providing comprehensive visibility into security posture and vulnerability insights as a standalone product.
Quantifiable outcome
- 30% reduction in risk of a breach
- +5 more outcomes
Companies that use Informer
Customer profileNamed customers11 records
Segments6 records
Ideal customer profiles3 records
Informer technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability2 records
Feature6 records
Informer partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- SlackcoreIntegration with Slack for security team notifications and workflow management. Enables real-time vulnerability alerts and team communication.
- JIRAcoreIntegration with JIRA for vulnerability tracking and remediation workflow management. Streamlines security issue ticketing.
Scale indicators8 records
Recent moves6 records
Expansion highlights5 records
Informer competitors and assessment
Company assessmentDirect peers
- Intigriti: Intigriti is a European-headquartered bug bounty and crowdsourced security platform that competes directly with Bugcrowd in continuous vulnerability disclosure and pentesting programs for enterprise buyers.
- HackerOne: HackerOne is the most direct competitor to Bugcrowd, operating a crowdsourced security platform that connects organizations with a global researcher community for bug bounty, vulnerability disclosure, and penetration testing services.
- YesWeHack: YesWeHack is a global bug bounty and vulnerability disclosure platform connecting enterprises with a researcher community, offering a competing dual-sided marketplace model with strong EMEA presence.
- Cobalt: Cobalt provides a Pentest as a Service (PTaaS) platform that connects customers with vetted security researchers for on-demand penetration testing, directly competing with Bugcrowd's PTaaS offering.
- Synack: Synack runs a curated, vetted researcher platform offering crowdsourced penetration testing and vulnerability management, with a similar dual-sided marketplace model and enterprise security buyer focus as Bugcrowd.
Broad incumbents
- Mandiant: Mandiant (now part of Google Cloud) provides threat intelligence, incident response, and offensive security services, overlapping with Bugcrowd's red teaming and vulnerability coordination offerings for large enterprises.
- NCC Group: NCC Group is a broad cybersecurity consulting and services firm offering penetration testing, red teaming, and vulnerability management, competing with Bugcrowd's testing services within larger enterprise managed security engagements.
- Bishop Fox: Bishop Fox is an offensive security services firm offering penetration testing, red teaming, and attack surface management, competing with Bugcrowd's PTaaS and Red Team as a Service lines for enterprise security buyers.
Emerging players
- Detectify: Detectify offers Attack Surface Management and crowdsourced security testing, overlapping with Bugcrowd's ASM and continuous vulnerability discovery capabilities for enterprise security teams.
- Pentera: Pentera provides automated penetration testing technology that competes with portions of Bugcrowd's PTaaS portfolio, particularly for enterprises seeking continuous, hands-off validation versus crowdsourced engagements.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
Informer social profiles
Digital presenceInformer financial estimates
Financial estimateRevenue estimate
Valuation estimate
Informer leadership team
Management profileNumber of profiles
Informer funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Informer M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Informer
What does Informer do?
Bugcrowd operates a crowdsourced cybersecurity platform that connects enterprise security teams with a global community of vetted ethical hackers to discover and remediate hidden vulnerabilities. Core offerings include outcome-based Bug Bounty programs, subscription-based Penetration Testing as a Service (with specialized variants for web, mobile, network, API, IoT, cloud, and social engineering), Red Team as a Service, Vulnerability Disclosure programs, and Attack Surface Management. The platform is augmented by AI-powered capabilities including Savant (preemptive security strategy), engineered Triage, CrowdMatch researcher matching, and the Vulnerability Rating Taxonomy.
Is Informer a public or private company?
Informer is a private company. It is classified as unknown and is currently operating.
When was Informer founded?
Informer was founded in 2014. It employs 11 to 50 people.
Where is Informer based?
Informer is headquartered in Brighton, United Kingdom, in the Europe region.
How does Informer make money?
Four revenue lines are on record. Bug Bounty Programs are the primary driver. The others are penetration Testing as a Service (PTaaS), red Team as a Service and vulnerability Disclosure Programs.
Who are Informer's main competitors?
Direct peers on record are Intigriti, HackerOne, YesWeHack, Cobalt and Synack. Broad incumbents are Mandiant, NCC Group and Bishop Fox. Emerging players are Detectify and Pentera.
Does Informer have an API?
No public API is recorded for Informer.
What industry is Informer in?
Informer's product category is Crowdsourced Cybersecurity Platform. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 54151 and its SIC code is 7372.