Buying a pentest
1 · Pick a gig and tier
Browse gigs by category — web, API, network, mobile, cloud, social engineering. Each gig is published by a vetted researcher and has Basic, Standard and Premium tiers. The price and delivery time are on the card. There is no quote, no discovery call, no SOW to sign before you get a number.
2 · Prove you own the target
Before anything runs against your systems, you prove control of the hostname: a DNS TXT record, a file at /.well-known/pentestmarket-verify/, or a <meta> tag. The backend does the lookup itself — it can't be faked from the browser. This is what keeps testing scoped to assets you actually control.
3 · Pay into escrow
Payment is USDT or USDC on Tron (TRC20) or Ethereum (ERC20). You submit the transaction hash; the backend confirms on-chain that it's a settled transfer of the right token, to the platform wallet, for at least the order amount. Until you accept the delivery, the funds sit in escrow.
4 · Accept the Rules of Engagement
A short, explicit RoE: what's in scope, testing windows, rate limits, what to do on contact with real data. Work cannot start until it's accepted. Every state transition in the order is guarded — an illegal one returns a 409 with the reason, never a silently broken order.
5 · The researcher works and delivers
You can see the order move through in-progress and in-review. The deliverable is a report where every finding has a reproduction in five steps or fewer and a suggested patch surface — not a 300-line tool dump.
6 · Review, then release or dispute
You review the delivery. Accept and escrow releases to the researcher (minus the 20% platform fee, taken from their side). Raise a dispute and the funds are held pending resolution. Reviews are public and can only be left on completed orders.
The bug bounty side
Companies run programs
A program has ownership-verified scope assets and a published severity → amount reward table. It can't go active until every asset is verified and the reward table exists.
Researchers submit reports
Reports use a structural key up front — endpoint, precondition, observable, likely patch surface — so triage and dedup happen in seconds. The full write-up follows.
Triage is a state machine
new → triaged → resolved, with needs-more-info, duplicate, informative, not-applicable and spam as explicit outcomes. The bounty is paid from the program's own reward table on resolution.
Payouts settle on-chain
Resolved reports pay out in USDT/USDC. The researcher's payout wallet is snapshotted at resolution, so a later wallet change can't rewrite where a past payout went.
Common questions about the flow
Do I need a crypto wallet to buy a pentest?+
Yes, for now. Payment is USDT/USDC on Tron or Ethereum. Card payments are on the roadmap.
What if I can't add a DNS record?+
There are three verification methods — DNS TXT, an HTTP file at /.well-known/, or a meta tag. One of them almost always fits.
Can I test something I don't own with the owner's permission?+
The person placing the order must be able to prove control of the target. If that's you acting for a client, you complete verification with access they grant you.
How long does a test take?+
Delivery time is on each tier — typically 3 to 18 days depending on scope. Retest tiers are shorter.
Two ways in
The marketplace has a buyer side and a researcher side. Both are self-serve.