Vulfosec
- Bug bounty marketplace
- Web design
- GSAP

A bug bounty marketplace and corporate site for a cybersecurity firm, with fluid GSAP motion throughout.
Who it was built for
Built for
Vulfosec
A cybersecurity firm running a bug bounty marketplace. Security researchers on one side, companies buying disclosure programmes on the other.
The brief
Enterprise security buyers judge a vendor by its website before they ever see the platform, and researchers judge it by whether it looks like somewhere they will get paid. One site had to do both jobs.
What we delivered
Motion used to explain, not decorate
A corporate surface that reads as senior
A documented design system
Where the growth comes from
Credibility is the first sale
Two audiences, one funnel
The business analysis
A bug bounty marketplace has to be trusted by two populations who do not trust each other. Companies are being asked to invite strangers to attack their systems; researchers are being asked to disclose an exploit before they have been paid for it. Neither decision is made on features. Both are made on whether the organisation looks like it will behave properly — which is why, for this business, the website is not marketing collateral. It is the first underwriting decision either side makes.
- Average award for a critical vulnerability
- $1,923
- Of Forbes Global 2000 lacking a disclosure policy
- 93%
Source · Elazari and colleagues, Journal of Cybersecurity (Oxford)
- Audiences, one funnel
- 2
Model · Structural fact about the marketplace, from this case study.
The market has money in it, and most large companies are not in it yet
Bug bounty is no longer speculative. HackerOne's programmes paid out $81m in bounties over a twelve-month period, a 13% year-on-year increase, with the top ten programmes alone accounting for $21.6m 1. The platform's cumulative researcher earnings passed $300m several years ago 2.
The more useful figure for a new entrant is the gap. Peer-reviewed work on the economics of bug bounties, using HackerOne data, notes that 93% of companies in the Forbes Global 2000 have no vulnerability disclosure policy at all 3 — no stated route by which a researcher can report a flaw without fear of being sued.
Bounties paid across HackerOne programmes, USD millions
- ~$71.7m
- $81m
- Prior year
- Reported year
Model · The $81m and the 13% year-on-year increase are as reported by BleepingComputer; the prior-year figure is our back-calculation from those two numbers.
Two audiences, two entirely different objections
Where the site's persuasive effort has to go
- Fewer, slower, and the ones whose budget makes the marketplace exist. Their objection is competence.
- More numerous and faster to convince. Their objection is whether they will actually get paid, and how quickly.
Model · Our weighting of the two audiences documented in this case study by acquisition difficulty and revenue contribution.
| Audience | The question they arrive with | What the page has to prove |
|---|---|---|
| Enterprise buyer | Is this firm competent enough to hand our attack surface to? | Seniority, rigour, and a triage process that will not waste our engineers' time |
| Researcher | Will I be paid, fairly and soon? | A working payout flow, a real programme list, and a triage stage that is not a black hole |
| Both | What actually happens after a submission? | The bounty lifecycle, explained rather than asserted |
Motion doing explanatory work
GSAP sequences carry the bounty lifecycle: submission, triage, payout. That is the one thing a first-time visitor on either side of the marketplace does not have, and it is genuinely hard to convey in a paragraph. Using motion to explain a process is a different discipline from using it to decorate a hero — the test is whether a visitor could describe the flow afterwards.
The bounty lifecycle, which is what the site has to communicate
Programme published
Researcher submits
Triagedecision
- ↳ Duplicate → the most contested outcome in the industry
- ↳ Out of scope → rejected, and reputational risk sits with the platform
- ↳ Valid → severity determines the award band
Disclosed to the company
Payout, and a fixed vulnerability
The site, by responsibility
Narrative surface
- Next.js
- TypeScript
- Tailwind CSS
Motion
- GSAP
- Framer Motion
Visual system
- Deep Navy
- Primary Blue
- Ice White
- Technical type scale
Design tokens
- Type tokens
- Colour tokens
- Spacing tokens
Component layer
- Aceternity UI
- Shared primitives
What we would watch
| Risk | Why it bites | Early indicator |
|---|---|---|
| Marketplace liquidity | Two-sided cold start with asymmetric acquisition cost. A programme list that looks thin repels both sides simultaneously | Researcher signups rising while published programmes stay flat |
| Triage capacity | Triage quality is the product. It is also labour, and it scales linearly with submissions rather than with revenue | Time-to-triage lengthening as programme count grows |
| Duplicate and dispute handling | Duplicate rulings are the most contested outcome in bug bounty, and researchers discuss them publicly | Disputes appearing in community channels before they appear in support |
References
- 1.HackerOne paid $81 million in bug bounties over the past year · BleepingComputer
- 2.Hackers surpass $300 million in all-time earnings on the HackerOne platform · HackerOne
- 3.Hacking for good: leveraging HackerOne data to develop an economic model of bug bounties · Journal of Cybersecurity, Oxford University Press
- 4.HackerOne report shows bug bounty industry and bounty rewards are on the rise globally · HackerOne
Reference
Recommended case studies
Want the version of this built for your business?
Fifteen minutes with the people who shipped it. No deck, no account manager.




