FAQ

Frequently asked questions

Straight answers about hiring a bug bounty hunter and penetration tester, scoping an engagement, and how AI factors into the work.

What is a bug bounty hunter and how is it different from a penetration tester?

A bug bounty hunter finds vulnerabilities across many organizations' public programs and is paid per validated finding, while a penetration tester is engaged for a fixed-scope, time-boxed assessment of one organization's systems with a contractual report. I do both: bug bounty hunting on platforms like HackerOne, Bugcrowd, and YesWeHack, and scoped penetration testing engagements for direct clients.

How much does a web application penetration test cost?

Cost depends on application size, number of user roles, and testing timeline. Rather than a fixed price list, engagements start with a short scope call so the quote reflects your actual attack surface rather than a generic day rate.

Do you sign NDAs and follow responsible disclosure?

Yes. NDAs are standard for client engagements, and all bug bounty and independent research follows responsible/coordinated disclosure practices — reporting directly to the affected organization or its program before any public discussion.

Can you test production systems, or does it need to be staging?

Both are possible. Testing staging environments avoids any risk to live users and data, while production testing can be scoped with safe-testing constraints (rate limits, read-only actions on sensitive workflows) agreed in advance.

What industries do you have experience testing?

Engagement experience spans SaaS platforms, e-commerce, and fintech-adjacent applications, alongside broad bug bounty exposure across web and API targets on major disclosure platforms.

How does AI fit into your testing process without compromising quality?

AI accelerates recon, fuzzing, and first-pass triage so more engagement time is spent on manual verification. Every finding that reaches the final report is manually confirmed — AI speeds up discovery, it does not replace validation.

Do you offer a retest after vulnerabilities are fixed?

Yes, one retest window is included in standard engagements to confirm that reported findings have been properly remediated.

How quickly can an engagement start?

Availability varies — reach out via the contact page with a rough scope and timeline, and expect a response with next steps within a few business days.

Question not answered here?