Bug bounty and vulnerability management platform for enterprises
YesWeHack operates a crowdsourced security platform connecting organizations to ethical hackers for vulnerability discovery and triage. The tech stack is security-native (Burp Suite, Metasploit, Kali, nmap) paired with standard web frameworks (Django, FastAPI, Vue), reflecting a mature platform built on established security tooling. Active hiring across sales (6 roles), security (5), and engineering (3) signals commercial expansion—UK/Ireland market entry and partnership buildout are live projects—while pain points center on helping customers adopt bug bounty workflows and reduce remediation cycles.
YesWeHack is a bug bounty and vulnerability management platform founded in 2015 by ethical hackers. The company sells to mid-to-large enterprises, governments, and critical infrastructure operators—clients include Tencent, Swiss Post, Orange France, and the French Ministry of Armed Forces. The platform spans six integrated services: bug bounty crowdsourcing, vulnerability disclosure policy management, pentest report aggregation, attack surface mapping, and ethical hacking training (Dojo). Operations are EU-based with GDPR-compliant private hosting certified under ISO 27001, 27017, 27018, 27701, and SOC II Type 2. The company itself operates under a public bug bounty program and holds CREST accreditation.
Security tooling (Burp Suite, Metasploit, Kali, nmap, SQLMap) paired with Python, Go, JavaScript, and web frameworks (Django, FastAPI, Vue). Frontend uses Vue; task management runs on Jira; design on Figma.
Paris, France. The company operates EU-based private hosting and maintains GDPR compliance across all infrastructure and operations.
Other companies in the same industry, closest in size