Skip to main content
MANAGED SECURITY PROGRAMS

Security programs built for startups, teams & enterprises

Choose a vulnerability disclosure, bug bounty, direct email relay, or analyst-reviewed self-managed workflow that matches your organization’s security and reporting requirements.

✓ Secure intake
✓ Human review
✓ Controlled disclosure
HX HACNEX
Security Programs
PROGRAM ROUTING
01
VDP Structured disclosure
→
02
BBP Managed researcher program
→
03
DIRECT Secure company relay
→
04
REVIEWED Analyst approval workflow
→
Controlled report delivery Visibility and routing depend on the selected program.
PROGRAM MODELS

Choose the security workflow that fits your organization.

Every HACNEX program uses a secure intake foundation while giving organizations different levels of validation, delivery, communication, and researcher management.

01 VDP

Managed Vulnerability Disclosure Program

For organizations that need a structured disclosure channel with safe-harbor language, secure submissions, validation, and managed triage.

$79 per cycle

Up to 15 valid reports included.

INCLUDED
  • ✓ Public vulnerability disclosure page
  • ✓ Safe-harbor disclosure policy
  • ✓ Secure report submission workflow
  • ✓ HACNEX validation and triage
  • ✓ Researcher and HACNEX Security Team email notifications
  • ✓ Company access after HACNEX Security Team validation
Start VDP →
03 SELF MANAGED

Direct-to-Company Email Relay

For organizations that want reports delivered directly to their security email while HACNEX provides secure intake, status tracking, and two-way communication.

Custom workflow based

Immediate company delivery with secure thread tracking.

INCLUDED
  • ✓ Secure report intake through HACNEX
  • ✓ Immediate delivery to company security email
  • ✓ Researcher and HACNEX Security Team confirmation emails
  • ✓ Company email replies shown as portal comments
  • ✓ Researcher comments relayed back by email
  • ✓ Report body removed after confirmed delivery
  • ✓ Researcher sees only status and discussion
Start Self Managed →
04 REVIEWED

Analyst-Reviewed Email Delivery

For organizations that want HACNEX analysts to review and validate each submission before it is delivered to the company security team.

Custom review based

Private intake with company delivery after admin approval.

INCLUDED
  • ✓ Private report intake through HACNEX
  • ✓ Researcher and HACNEX Security Team notifications on submission
  • ✓ HACNEX Security Team review before company delivery
  • ✓ Approved reports sent to company security email
  • ✓ Company replies synchronized with portal comments
  • ✓ Status, decision, and payout tracking
  • ✓ Controlled researcher report visibility
Start Reviewed Plan →
HOW ROUTING WORKS

Each plan follows a different report-delivery workflow.

HACNEX routes vulnerability information according to the organization’s selected program model and review requirements.

01
BBP

Managed Bug Bounty

Researcher and HACNEX Security Team are notified immediately. The company receives access after triage approval.

02
VDP

Vulnerability Disclosure

Researcher and HACNEX Security Team are notified immediately. The company receives access after validation and triage.

03
SELF MANAGED

Direct Company Relay

Researcher, HACNEX Security Team, and the company receive notifications immediately. Communication continues through the secure email relay.

04
REVIEWED

Analyst Approval

Researcher and HACNEX Security Team are notified first. The company receives the report only after analyst approval.

AUTHORIZATION FIRST

Security testing always starts with explicit authorization.

HACNEX does not conduct testing on customer systems without explicit written authorization, approved scope, and permission from the asset owner.

01

Explicit authorization Customer systems require permission before any testing activity.

02

Approved scope Security activity remains within the scope defined by the asset owner.

03

Controlled disclosure Vulnerability information follows the selected report-delivery workflow.

READY TO START?

Choose the workflow that fits your security team.

Launch a HACNEX program or contact us about the security workflow that fits your organization.