Skip to content
GAdvisory

Compared with VDP platforms

HackerOne and Bugcrowd solve the problem of receiving vulnerability reports. GAdvisory solves the problem of publishing the record afterwards. Those are different jobs, and this page exists mostly to say so plainly rather than to claim a contest.

What they are

Intake, triage and the researcher relationship

A vulnerability disclosure platform gives you an address researchers already know, a pipeline for reports, triage staff who filter the noise, a reputation system that motivates good submissions, and where there is a bounty, the mechanism for paying it.

Both are CNAs. The CVE Program lists HackerOne's scope as providing CVE ids for its customers as part of its bug bounty and coordination platform, and Bugcrowd's as vulnerabilities found by researchers working with Bugcrowd, with the client's approval, that fall in no other CNA's scope.

Concessions

What they do that nothing here does

The researcher side of the market is their product and it is not something a self-hosted tool can substitute. A researcher who has an account, a reputation and a payout history on a platform will report through it. Being where they already are is most of the value, and GAdvisory has no equivalent to offer.

Triage capacity is the other half. Somebody separating the twenty duplicate reports and the automated scanner output from the one real finding is labour, and buying it is a legitimate answer that no amount of software replaces.

Limits

Where they stop

They end at the report. The published advisory, on your domain, with affected version ranges a machine can parse, in a feed your customers subscribe to and a format a regulator recognises, is not what they produce, and a disclosure page on a platform's domain is not a security page on yours.

The record also stays with them. If you leave the platform, what you take is an export rather than a live history, and the advisories you published under their identifiers stay where they are.

Together

They run alongside, not instead

The natural arrangement is intake there and the record here: reports arrive through the platform, and the advisory that results is authored, given an identifier and published from your own instance. GAdvisory's own intake covers the reporters who come to you directly, which is most of them once you have published a security page saying where to write.

Nothing about running one prevents running the other, and for an organisation with both a bounty programme and a compliance obligation, both is usually the answer.

Next

Related

The other comparisons, and what it takes to run this yourself.

© 2026 Gelhaus Solutions