Listing Thumbnail

    Hackrate Managed Vulnerability Disclosure Program (mVDP)

     Info
    Sold by: Hackrate 
    Managed vulnerability disclosure services for receiving, assessing, validating, and coordinating externally reported security vulnerabilities affecting customer applications, APIs, AWS-hosted workloads, and other eligible digital assets. Scope, duration, covered assets, service levels, and commercial terms are defined individually for each customer through a private offer.

    Overview

    Security vulnerabilities are often discovered by external security researchers, customers, partners, and other third parties. Without a clear vulnerability disclosure process, these reports may be sent through inappropriate channels, remain unresolved, or create unnecessary security and communication risks.

    Hackrate’s Managed Vulnerability Disclosure Program (mVDP) provides organizations with a structured and professionally managed process for receiving, validating, and handling externally reported security vulnerabilities.

    This professional service supports organizations operating applications, APIs, cloud environments, and digital assets on Amazon Web Services (AWS). Hackrate mVDP can be used as a coordinated vulnerability disclosure channel for customer-controlled applications and workloads built on AWS services such as Amazon EC2, Amazon API Gateway, Amazon CloudFront, Elastic Load Balancing, Amazon S3, and other AWS services used to host, operate, or deliver customer applications.

    Hackrate provides the vulnerability disclosure infrastructure and security expertise required to establish a clear communication channel between organizations and external security researchers. Submitted vulnerabilities are assessed and validated by Hackrate before actionable findings are communicated to the customer.

    How It Works

    1. Program Setup: Hackrate works with the customer to establish the Vulnerability Disclosure Program, define eligible applications and digital assets, determine the program scope, and establish vulnerability disclosure rules.

    2. Disclosure Channel: A dedicated vulnerability disclosure interface enables security researchers and other external parties to securely report potential vulnerabilities affecting the customer’s applications and AWS-hosted workloads.

    3. Vulnerability Triage and Validation: Hackrate security experts review submitted vulnerability reports, assess their technical validity and severity, request additional information from the reporter when necessary, and filter invalid or irrelevant submissions.

    4. Coordinated Communication: Hackrate acts as an intermediary between the customer and the vulnerability reporter, helping maintain structured communication throughout the vulnerability handling process.

    5. Reporting and Remediation: Validated findings are provided to the customer with technical information required to reproduce and understand the vulnerability. Hackrate can provide additional assistance during assessment and remediation.

    Key Benefits

    • Centralized Vulnerability Disclosure: Provide a dedicated and structured channel for reporting security vulnerabilities affecting your applications and digital assets.
    • Professional Vulnerability Triage: Hackrate security experts assess, validate, and classify incoming vulnerability reports before they reach your internal teams.
    • Reduced Security Team Workload: Filter spam, duplicate, invalid, and irrelevant submissions so internal security teams can focus on actionable vulnerabilities.
    • Researcher Communication: Hackrate manages communication with external security researchers when additional information or clarification is required.
    • AWS Workload Coverage: Use the disclosure program for customer-controlled applications, APIs, and digital assets hosted on or using AWS.
    • Structured Reporting: Receive validated vulnerability information with technical details, severity assessment, and supporting evidence through the Hackrate platform.
    • Enterprise-Ready Process: Establish a consistent vulnerability disclosure workflow that can support organizational security governance and vulnerability management processes.

    Managed Vulnerability Disclosure

    Unlike a bug bounty program, a Vulnerability Disclosure Program does not require organizations to actively incentivize security researchers to search for vulnerabilities. Instead, it establishes a secure and responsible process for vulnerabilities discovered independently by external parties to be reported and handled.

    Organizations can use Hackrate mVDP as a standalone vulnerability disclosure capability or as a foundation before introducing more proactive security testing models such as private or public bug bounty programs.

    Hackrate mVDP helps organizations establish a professional vulnerability disclosure process for their AWS-hosted applications and digital services while maintaining control over scope, communication, validation, and remediation.

    Highlights

    • Managed Vulnerability Triage: Hackrate security experts assess, validate, and classify externally reported vulnerabilities before delivering actionable findings to your internal teams.
    • Structured Disclosure Process: Establish a secure, centralized vulnerability disclosure channel for applications, APIs, and AWS-hosted workloads, with coordinated communication between reporters and your organization.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Hackrate provides customer support throughout the Managed Vulnerability Disclosure Program (mVDP) lifecycle, including program setup and configuration, scope management, vulnerability triage and validation, reporter communication, severity assessment, platform-related questions, and assistance with reported security findings.

    Customers receive ongoing support for the duration of their contracted service. The specific service levels, response times, and additional support requirements may be defined in the applicable private offer or service agreement.

    Support contact: Email: support@hckrt.com  Website: