Vulfosec

  • Bug bounty marketplace
  • Web design
  • GSAP
Vulfosec — Cybersecurity platform

A bug bounty marketplace and corporate site for a cybersecurity firm, with fluid GSAP motion throughout.

Who it was built for

The business, and what they came with.

Built for

Vulfosec

A cybersecurity firm running a bug bounty marketplace. Security researchers on one side, companies buying disclosure programmes on the other.

The brief

Enterprise security buyers judge a vendor by its website before they ever see the platform, and researchers judge it by whether it looks like somewhere they will get paid. One site had to do both jobs.

What we delivered

What Vulfosec has now that they did not have before.

  • Motion used to explain, not decorate

    GSAP sequences carry how a bounty programme works — submission, triage, payout — because that flow is the part a first-time visitor does not have.

  • A corporate surface that reads as senior

    Deep navy and technical typography set against a marketplace that has to feel safe to submit a vulnerability to.

  • A documented design system

    Type, colour and spacing tokens published with the build, so marketing pages and product surfaces stay one thing.

Where the growth comes from

Why each piece of the build pays for itself.

  • Credibility is the first sale

    In security the site is a competence signal. Losing an enterprise buyer at the homepage costs the same as losing them at the demo.

  • Two audiences, one funnel

    Researchers and companies want different proof from the same pages, and the marketplace is worthless if only one side signs up.

The business analysis

Market, model and architecture. Every figure is either cited or labelled as a model.

A bug bounty marketplace has to be trusted by two populations who do not trust each other. Companies are being asked to invite strangers to attack their systems; researchers are being asked to disclose an exploit before they have been paid for it. Neither decision is made on features. Both are made on whether the organisation looks like it will behave properly — which is why, for this business, the website is not marketing collateral. It is the first underwriting decision either side makes.

Paid in bug bounties in one year
$81m
Across HackerOne programmes, up 13% year on year, with the top ten programmes accounting for $21.6m of it.

Source · HackerOne figures, as reported by BleepingComputer

Average award for a critical vulnerability
$1,923
With 88 individual rewards above $10,000 in a twelve-month period. The top of the market is thin and the middle is modest.

Source · HackerOne, bug bounty industry report announcement

Of Forbes Global 2000 lacking a disclosure policy
93%
No stated route for a researcher to report a vulnerability without legal risk. This is the unserved demand the category exists on.

Source · Elazari and colleagues, Journal of Cybersecurity (Oxford)

Audiences, one funnel
2
Researchers and companies want different proof from the same pages, and the marketplace is worthless if only one side signs up.

Model · Structural fact about the marketplace, from this case study.

The market has money in it, and most large companies are not in it yet

Bug bounty is no longer speculative. HackerOne's programmes paid out $81m in bounties over a twelve-month period, a 13% year-on-year increase, with the top ten programmes alone accounting for $21.6m 1. The platform's cumulative researcher earnings passed $300m several years ago 2.

The more useful figure for a new entrant is the gap. Peer-reviewed work on the economics of bug bounties, using HackerOne data, notes that 93% of companies in the Forbes Global 2000 have no vulnerability disclosure policy at all 3 — no stated route by which a researcher can report a flaw without fear of being sued.

Bounties paid across HackerOne programmes, USD millions

The reported year and the implied prior year. The earlier figure is derived from the stated 13% increase, so it is arithmetic rather than a published number.

  • ~$71.7m
  • $81m
  • Prior year
  • Reported year

Model · The $81m and the 13% year-on-year increase are as reported by BleepingComputer; the prior-year figure is our back-calculation from those two numbers.

Two audiences, two entirely different objections

Where the site's persuasive effort has to go

Our apportionment of the homepage's job across the two sides of the marketplace, weighted by how hard each side is to acquire rather than by how many of them there are.

60%of the persuasion budget goes to the enterprise buyer
Enterprise security buyer60%
Fewer, slower, and the ones whose budget makes the marketplace exist. Their objection is competence.
Security researcher40%
More numerous and faster to convince. Their objection is whether they will actually get paid, and how quickly.

Model · Our weighting of the two audiences documented in this case study by acquisition difficulty and revenue contribution.

AudienceThe question they arrive withWhat the page has to prove
Enterprise buyerIs this firm competent enough to hand our attack surface to?Seniority, rigour, and a triage process that will not waste our engineers' time
ResearcherWill I be paid, fairly and soon?A working payout flow, a real programme list, and a triage stage that is not a black hole
BothWhat actually happens after a submission?The bounty lifecycle, explained rather than asserted

Motion doing explanatory work

GSAP sequences carry the bounty lifecycle: submission, triage, payout. That is the one thing a first-time visitor on either side of the marketplace does not have, and it is genuinely hard to convey in a paragraph. Using motion to explain a process is a different discipline from using it to decorate a hero — the test is whether a visitor could describe the flow afterwards.

The bounty lifecycle, which is what the site has to communicate

The offshoots are where trust is actually won or lost. Both audiences are watching the same three of them for different reasons.

  1. Programme published

    Scope, rules of engagement and reward bands stated up front. For a researcher, out-of-scope work is unpaid work, so ambiguity here costs the marketplace its supply.

  2. Researcher submits

    The moment a researcher gives up their only leverage. Everything after this is a promise the platform has to keep.

  3. Triagedecision

    Validity, severity and duplication assessed. The single most important stage for both sides, and the one the marketing site has to make legible.

    • Duplicate → the most contested outcome in the industry
    • Out of scope → rejected, and reputational risk sits with the platform
    • Valid → severity determines the award band
  4. Disclosed to the company

    With enough detail to reproduce and remediate. This is where the buyer's engineering time is either respected or wasted.

  5. Payout, and a fixed vulnerability

    The researcher is paid and the company is safer. Payout speed and consistency are the marketplace's actual reputation — features are not.

The site, by responsibility

A marketing surface where the visual system is load-bearing. The tokens are published with the build so product screens and marketing pages remain one artefact.

  1. Narrative surface

    Explains the bounty lifecycle to two audiences at once. The hardest content problem in the project.

    • Next.js
    • TypeScript
    • Tailwind CSS
  2. Motion

    Sequences the submission, triage and payout flow. Explanatory, timed to reading rather than to arrival.

    • GSAP
    • Framer Motion
  3. Visual system

    Deep navy and technical typography. In security, restraint reads as seniority and exuberance reads as a startup that will be gone next year.

    • Deep Navy
    • Primary Blue
    • Ice White
    • Technical type scale
  4. Design tokens

    Published with the build so the marketplace product and the corporate site do not drift into two brands.

    • Type tokens
    • Colour tokens
    • Spacing tokens
  5. Component layer

    Composed surfaces built on a shared primitive set, so new pages inherit the visual argument.

    • Aceternity UI
    • Shared primitives

What we would watch

RiskWhy it bitesEarly indicator
Marketplace liquidityTwo-sided cold start with asymmetric acquisition cost. A programme list that looks thin repels both sides simultaneouslyResearcher signups rising while published programmes stay flat
Triage capacityTriage quality is the product. It is also labour, and it scales linearly with submissions rather than with revenueTime-to-triage lengthening as programme count grows
Duplicate and dispute handlingDuplicate rulings are the most contested outcome in bug bounty, and researchers discuss them publiclyDisputes appearing in community channels before they appear in support

References

  1. 1.HackerOne paid $81 million in bug bounties over the past year · BleepingComputer
  2. 2.Hackers surpass $300 million in all-time earnings on the HackerOne platform · HackerOne
  3. 3.Hacking for good: leveraging HackerOne data to develop an economic model of bug bounties · Journal of Cybersecurity, Oxford University Press
  4. 4.HackerOne report shows bug bounty industry and bounty rewards are on the rise globally · HackerOne

Reference

For the technical reader. Everyone else has what they need above.

The closest work to Vulfosec, scored for relevance rather than picked by position.

Want the version of this built for your business?

Fifteen minutes with the people who shipped it. No deck, no account manager.