The Live Penetration Testing Validation Demo Webinar · Register for the Version 1.0 walkthrough
02 October 2026 : 10am-11am
Find and reduce external security risk with exposure visibility, responsible disclosure and managed researcher testing.
Create Company AccountDiscover programs, submit responsible findings, build your reputation and earn rewards where available.
Join as a ResearcherA Vulnerability Disclosure Program (VDP) gives researchers a clear way to report vulnerabilities to your organisation. Define what they may test, set disclosure rules and review findings before deciding whether to launch a paid bounty program.
View VDP PlansWork with trusted researchers while SternSleuth helps manage scope, submissions, validation and bounty operations. Define Rules of Engagement (ROE), what researchers may test and how, and choose testing windows that protect sensitive production periods.
View Managed Bug Bounty PlansJoin responsible disclosure and managed bug bounty programs. Submit high-quality findings and build a record of responsible research. Rewards depend on each program; VDPs may not pay bounties. Private programs and on-site opportunities have additional eligibility requirements.
Create Researcher AccountSample profiles below illustrate badges, reputation and accepted submissions. These are fictional examples, not live rankings or researcher achievements.
Sample profile
32 example accepted submissions
Sample profile
21 example accepted submissions
Sample profile
18 example accepted submissions
Sample profile
15 example accepted submissions
Discover. Validate. Fix. Measure.
Connect exposure visibility, responsible disclosure and managed researcher testing with the work your team does to reduce risk.
Compare plans for initial exposure visibility, application security testing and managed researcher support.
Initial exposure visibility
R 4 900
/monthly
For teams that want to understand their external exposure before committing to a managed security program.
Continuous validation
R 14 900
/monthly
For security teams reviewing web, API and mobile risks, with Sleuth AI guidance and reports to support remediation.
Managed researcher testing
R 39 900
/monthly
For enterprises that need vetted researchers, managed triage, controlled scope, bounty governance, and developer backlog integration.
Frequently Asked Questions
Clear answers for companies comparing exposure validation, responsible disclosure, managed bug bounty, and participation as a security researcher.
Continuous Exposure Validation brings exposure discovery, security review and remediation tracking together so teams can revisit risk as their external attack surface changes.
A Vulnerability Disclosure Program (VDP) gives researchers a responsible way to report vulnerabilities, with defined scope and disclosure rules. A Managed Bug Bounty Program adds coordinated researcher testing, bounty governance and managed triage. A VDP does not require monetary bounties.
The preview gives you an initial view of publicly visible assets and areas that may need review. It does not confirm exploitability or replace a security assessment. Detailed review depends on the plan you choose after account verification.
Submissions are reviewed for duplicates, supporting evidence and potential business impact. This helps your security team focus on issues that deserve investigation and remediation.
Yes. Define which assets researchers may test and how through Rules of Engagement (ROE). Testing windows specify when testing is allowed, and pause controls protect sensitive production periods.
Create your profile, complete verification, review program scope and accept the rules before testing. Submit findings with clear evidence and track their review. Bounties and stipends depend on program terms and eligibility; responsible disclosure programs may offer no monetary reward.