The Live Penetration Testing Validation Demo Webinar · Register for the Version 1.0 walkthrough

See what attackers already see.

company.co.za
Public exposure preview
No install required
Built for security leaders
Upgrade when ready

For Companies

Find and reduce external security risk with exposure visibility, responsible disclosure and managed researcher testing.

Create Company Account

For Researchers

Discover programs, submit responsible findings, build your reputation and earn rewards where available.

Join as a Researcher

Discover exposure. Validate risk. Fix what matters.

Preview your public exposure

Choose disclosure or managed testing

Set scope, rules and testing times

Send validated findings to your team

Track fixes and report progress

Give researchers a responsible way to report vulnerabilities.

A Vulnerability Disclosure Program (VDP) gives researchers a clear way to report vulnerabilities to your organisation. Define what they may test, set disclosure rules and review findings before deciding whether to launch a paid bounty program.

View VDP Plans
  • A clear channel for responsible disclosure
  • Defined program scope and testing rules
  • No bounty required for responsible disclosure
  • Structured submissions for validation and triage
  • Start small before launching a bug bounty

Expand security testing with a Managed Bug Bounty Program.

Work with trusted researchers while SternSleuth helps manage scope, submissions, validation and bounty operations. Define Rules of Engagement (ROE), what researchers may test and how, and choose testing windows that protect sensitive production periods.

View Managed Bug Bounty Plans

Reduce low-quality report noise

Protect production with testing windows

Control private program access

Send findings to Azure DevOps or Jira

Track bounty pool usage

Show progress on remediation

  1. 1Create your profile and complete verification
  2. 2Discover eligible programs
  3. 3Review scope and permitted testing times
  4. 4Accept the Rules of Engagement
  5. 5Test responsibly within the agreed scope
  6. 6Submit a finding with clear evidence
  7. 7Track review and respond to feedback
  8. 8Build your reputation
  9. 9Qualify for rewards and further opportunities

Find vulnerabilities. Build your reputation. Earn rewards.

Join responsible disclosure and managed bug bounty programs. Submit high-quality findings and build a record of responsible research. Rewards depend on each program; VDPs may not pay bounties. Private programs and on-site opportunities have additional eligibility requirements.

Create Researcher Account

See how researcher reputation can grow.

Sample profiles below illustrate badges, reputation and accepted submissions. These are fictional examples, not live rankings or researcher achievements.

#1

Sample profile

ByteSleuth ZA

South Africa
980
API HunterTrusted ResearcherFirst Blood

32 example accepted submissions

#2

Sample profile

CloudNinja BW

Botswana
840
Cloud WatchVerified Researcher

21 example accepted submissions

#3

Sample profile

MobileFox KE

Kenya
790
Mobile LabVDP Contributor

18 example accepted submissions

#4

Sample profile

RedRoot ZM

Zambia
720
Web ResearchFast Reporter

15 example accepted submissions

Discover. Validate. Fix. Measure.

Understand the risk. Give your team a clear next step.

Connect exposure visibility, responsible disclosure and managed researcher testing with the work your team does to reduce risk.

External attack surface preview

See which public domains, web applications and APIs may need closer security review.

Exposure validation

Responsible vulnerability disclosure

Give researchers a clear way to report vulnerabilities, with defined scope, testing rules and structured review.

Responsible disclosure

Testing with trusted researchers

Expand testing with trusted researchers while SternSleuth helps manage submissions, validation and bounty operations.

Managed BBP

Fix issues in your existing tools

Send validated vulnerabilities to Jira or Azure DevOps so your team can track fixes in its existing backlog.

Remediation integration

Review evidence in your workspace

Verify your account and choose a plan to review the detailed evidence included in your subscription.

Account and plan access

Show progress to leadership

Show leadership which risks were discovered, what has been fixed and where remediation still needs attention.

Executive visibility

Start with visibility. Grow your security program.

Compare plans for initial exposure visibility, application security testing and managed researcher support.

Initial exposure visibility

Starter

R 4 900

/monthly

For teams that want to understand their external exposure before committing to a managed security program.

  • Exposure preview follow-up
  • Limited DAST preview
  • No exploit validation
  • No VDP / BBP
  • Workspace access and exposure follow-up
View Plan Details

Continuous validation

Professional

Recommended

R 14 900

/monthly

For security teams reviewing web, API and mobile risks, with Sleuth AI guidance and reports to support remediation.

  • MobSec intake and Mobile Lab access
  • DAST Pro
  • API Scanner Pro
  • Sleuth AI insights
  • Reports and exports
View Plan Details

Managed researcher testing

Enterprise Managed BBP

R 39 900

/monthly

For enterprises that need vetted researchers, managed triage, controlled scope, bounty governance, and developer backlog integration.

  • VDP / BBP program management
  • Threat intelligence overlays
  • Internal triage workflows
  • IAST, coming soon
  • RASP, coming soon
View Plan Details

Frequently Asked Questions

Choose your next step with confidence.

Clear answers for companies comparing exposure validation, responsible disclosure, managed bug bounty, and participation as a security researcher.

What is Continuous Exposure Validation?+

Continuous Exposure Validation brings exposure discovery, security review and remediation tracking together so teams can revisit risk as their external attack surface changes.

What is the difference between a VDP and Managed BBP?+

A Vulnerability Disclosure Program (VDP) gives researchers a responsible way to report vulnerabilities, with defined scope and disclosure rules. A Managed Bug Bounty Program adds coordinated researcher testing, bounty governance and managed triage. A VDP does not require monetary bounties.

What does the exposure preview show?+

The preview gives you an initial view of publicly visible assets and areas that may need review. It does not confirm exploitability or replace a security assessment. Detailed review depends on the plan you choose after account verification.

How does SternSleuth reduce noisy submissions?+

Submissions are reviewed for duplicates, supporting evidence and potential business impact. This helps your security team focus on issues that deserve investigation and remediation.

Can we control testing windows and scope?+

Yes. Define which assets researchers may test and how through Rules of Engagement (ROE). Testing windows specify when testing is allowed, and pause controls protect sensitive production periods.

How do researchers earn through SternSleuth?+

Create your profile, complete verification, review program scope and accept the rules before testing. Submit findings with clear evidence and track their review. Bounties and stipends depend on program terms and eligibility; responsible disclosure programs may offer no monetary reward.