Bug bounty programmes
The team reports on HackerOne, Bugcrowd and YesWeHack. The same team runs your audit, and no part of the work is subcontracted.
ABOUT
A specialist company, not a generalist consultancy. The same team agrees the scope, runs the audit and signs the report. It also reports vulnerabilities to international bug bounty and responsible disclosure programmes.
The team's work on those programmes covers corporate applications and networks at international organisations. Every finding was reported through the programme's own channel.
The confidentiality agreement signed before each engagement prevents us from naming clients or showing their logo. The same agreement sets out how evidence is held, how long it is kept and how it is destroyed.
Lapsor provides references on request, as part of a procurement process and with the client's prior approval.
The technical analyses on this site cover real findings, anonymised: none is published before the fix is closed.
The team reports on HackerOne, Bugcrowd and YesWeHack. The same team runs your audit, and no part of the work is subcontracted.
The team works with the most established tooling in the field and keeps it current as attack techniques change. Tooling speeds the review up, it does not replace it: every finding is exploited and validated by hand before it reaches the report.
COMPANY
Tell us which assets you want tested. We reply within 24 hours.