Try our new research platform with insights from 80,000+ expert users

Bugcrowd vs Cymulate comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Bugcrowd
Ranking in Attack Surface Management (ASM)
16th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
4
Ranking in other categories
Managed Security Services Providers (MSSP) (14th), Bug Bounty Platforms (1st), Penetration Testing Services (3rd)
Cymulate
Ranking in Attack Surface Management (ASM)
11th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
6
Ranking in other categories
Threat Intelligence Platforms (TIP) (10th), Breach and Attack Simulation (BAS) (1st), Continuous Threat Exposure Management (CTEM) (2nd)
 

Mindshare comparison

As of October 2025, in the Attack Surface Management (ASM) category, the mindshare of Bugcrowd is 6.0%, up from 3.3% compared to the previous year. The mindshare of Cymulate is 2.9%, up from 2.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Attack Surface Management (ASM) Market Share Distribution
ProductMarket Share (%)
Cymulate2.9%
Bugcrowd6.0%
Other91.1%
Attack Surface Management (ASM)
 

Featured Reviews

George Devasia - PeerSpot reviewer
Efficient reports simplify tracking and feedback for cybersecurity submissions
I am a developer working in cybersecurity, and I use Bugcrowd to help companies remove vulnerabilities from their websites. I report vulnerabilities found in applications or customer platforms through Bugcrowd's cloud platform. This allows the cloud team to track submissions, and then the client…
Ondrej Kováč - PeerSpot reviewer
Advanced cybersecurity solution for attack based vulnerability mng. and upskill platform for SOC.
While Cymulate's technology shows great promise and delivers excellent results, their approach to positioning the solution appears to overlap with other companies like Tenable, making them both direct and indirect competitors. Cymulate must refine their messaging and manage expectations effectively. In my experience, they need to be more attentive internally and mindful of potential negative impacts on customers. They exhibit a high degree of flexibility, which can result in sudden changes without adequate alerting. Communicating with them via phone for business matters can be challenging. On a scale from one to ten, I would rate Cymulate's technology level at eight, but their business level at four out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable aspect of Bugcrowd is that it provides a long list of different websites or web applications where I can report vulnerabilities."
"Working on Bugcrowd has made me a better security engineer since it provides a competitive environment to report successful vulnerabilities."
"Bugcrowd has programs that disclose rewards and invite researchers to new programs."
"I would rate Bugcrowd a ten out of ten."
"Bugcrowd's support team is very active and supportive."
"One of the features I like most about Bugcrowd is the ability to create a report in a very easy way."
"I believe Bugcrowd is highly stable."
"Cymulate has positively impacted our organization by helping us to take care of the efficacy and reviewing the policies and configuration."
"With Cymulate, the best features are the capacity to test the EDR or malware, anti-malware solution."
"The security validation feature helps my organization in assessing our security posture."
"The reporting capabilities are very good."
"The most valuable feature for us is the zero-day."
"Cymulate is easy to set up, install, and configure."
 

Cons

"There is room for improvement in Bugcrowd's response time when customer input is needed for resolving tickets. If this time could be minimized, it would be very helpful."
"Bugcrowd should provide more access to the reports, similar to HackerOne, allowing for full disclosure once a bug is resolved, so researchers can learn from them. They should improve the responsibility type and response time of their customer support, especially when the issue is urgent."
"Bugcrowd should provide more access to the reports, similar to HackerOne, allowing for full disclosure once a bug is resolved, so researchers can learn from them."
"The triaging process has slowed down compared to three years ago. It now takes more time to resolve a reported vulnerability and receive the payout."
"The triaging process has slowed down compared to three years ago."
"There is room for improvement in Bugcrowd's response time when customer input is needed for resolving tickets."
"The reporting process requires significant improvement as it often takes longer than expected and the quality is lacking."
"The cost can be quite high, and it impacts scalability as more simulations require additional expenses."
"We have had some trouble with the agents."
"I will be honest, we have it, but in the last year, I didn't maintain the system until a month ago."
"The way Cymulate works for EDR could be improved, as it drops payload and requires action from the EDR console for remediation, which can block the whole process of Cymulate execution."
"The product must provide consultancy for initial setup."
 

Pricing and Cost Advice

Information not available
"The product is affordable."
"Cymulate's services are expensive."
report
Use our free recommendation engine to learn which Attack Surface Management (ASM) solutions are best for your needs.
869,566 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
9%
University
8%
Financial Services Firm
17%
Computer Software Company
11%
Manufacturing Company
8%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business4
Large Enterprise3
 

Questions from the Community

What is your experience regarding pricing and costs for Bugcrowd?
I understand the pricing, and it involves rewards of at least one thousand dollars.
What needs improvement with Bugcrowd?
The tool itself could be improved. I hope to improve next time and perform better.
What is your primary use case for Bugcrowd?
I use Bugcrowd ( /products/bugcrowd-reviews ) for finding bugs and vulnerabilities. I have been using it for two years. Besides Bugcrowd ( /products/bugcrowd-reviews ), I also use HackerOne ( /prod...
What do you like most about Cymulate?
The most valuable feature for us is the zero-day.
What is your experience regarding pricing and costs for Cymulate?
I don't currently recall the specific pricing details as I last reviewed them two years ago. I initially thought it would be more expensive, but I found it reasonable because you can purchase modul...
What needs improvement with Cymulate?
The way Cymulate works for EDR could be improved, as it drops payload and requires action from the EDR console for remediation, which can block the whole process of Cymulate execution. They should ...
 

Comparisons

 

Overview

 

Sample Customers

Zephyr Health, Barracuda Networks, Western Union, Instructure, Aruba Networks, Pinterest, CARD.com, WINK, (ISC)2, StatusPage, WHMCS, Movember
Euronext, YMCA, Telit, Nemours 
Find out what your peers are saying about Bugcrowd vs. Cymulate and other solutions. Updated: September 2025.
869,566 professionals have used our research since 2012.