YesWeHack
France · www.yeswehack.com · 7 vendors
YesWeHack is a global Offensive Security and Exposure Management platform. It provides a crowdsourced platform for bug bounty programs, connecting organizations with a community of ethical hackers to identify and remediate security vulnerabilities in their digital assets.
Resilience scores
- Digital Sovereignty: 14
- Digital Resilience: 8
- Financial Resilience: 6
Disruption prediction
YesWeHack has an estimated 11% probability of disruption in the next 6 months.
4 of YesWeHack's 7 vendors monitored for disruptions.
Technology vendors
- Google LLC — Technology — United States
- ProjectDiscovery — Cybersecurity — United States
- Sanity AS — Technology — Norway
- and 4 more
Services catalogue
1 service in catalogue across 1 category; runs on 7 sub-vendors.
- Bug bounty platform
Insights
Last updated 2026-07-09 · revision 2
7 direct vendors, 130 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- United States: 4
- Australia: 1
Subvendors by controlling owner country (sample)
- Taiwan: 1
- Germany: 3
- Canada: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
YesWeHack exhibits high migration readiness, largely due to its modern and cloud-aware internal tech stack. The use of Infrastructure-as-Code (IaC), CI/CD Pipelines, and an OpenAPI-driven REST API platform signifies a highly automated, modular, and agile development and deployment environment, which is ideal for cloud migration. The company's current reliance on SecNumCloud-qualified Private Cloud and European Cloud Providers indicates existing experience with cloud infrastructure. The comprehensive suite of compliance certifications (SecNumCloud, GDPR, ISO 27001, SOC II Type 2) means that robust security and data governance frameworks are already in place, which, while requiring careful planning, provide a solid foundation for migrating compliant workloads. The primary challenges and uncertainties for migration readiness stem from the vendor landscape and financial data. The "Vendor Lock-in Risk: Unknown" is a significant factor, as the total number of distinct vendors for the 8 services is not specified, making it difficult to assess potential complexities in disentangling from existing vendor relationships. While data residency requirements are "Not specified", the company's EU HQ and EU-only hosting strongly imply a requirement for EU data residency, which could constrain migration options if considering non-EU cloud providers. Lastly, the absence of financial stability data (revenue concentration, growth history) prevents a full assessment of the company's capacity to fund a potentially significant migration effort.
Compliance
9 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
NIS2 (Directive (EU) 2022/2555), transposed into French law, applies to entities in listed sectors that meet size thresholds (50+ employees or €10M+ annual turnover). YesWeHack operates in the cybersecurity/digital infrastructure sector. Under NIS2 Annex I and II, 'digital infrastructure' (including managed security service providers and ICT service management) is an in-scope sector. YesWeHack's services — Bug Bounty, Penetration Testing, Vulnerability Management — are directly relevant to cybersecurity and could qualify it as a 'managed security service provider' (MSSP) or digital provider. France transposed NIS2 via the Loi de programmation militaire (LPM) and ANSSI guidance. The risk is Medium because: (a) the sector classification is plausible but requires formal ANSSI determination; (b) YesWeHack's exact employee count and revenue are not publicly confirmed (though global presence in 50+ countries and multiple offices suggests it likely exceeds the 50-employee/€10M threshold); (c) non-compliance with NIS2 in France carries fines up to €10M or 2% of global turnover for essential entities. The company's existing ISO 27001 certification and SecNumCloud qualification are strong NIS2-preparedness indicators.
Evidence: https://www.yeswehack.com/about, https://www.yeswehack.com/product/trust-security, https://www.yeswehack.com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
GDPR (source) — Compliant
YesWeHack is a French company (EU-based) and explicitly self-declares GDPR compliance across its public-facing pages. The company has appointed an external Data Protection Officer (DPO), publishes a detailed Privacy Policy referencing GDPR articles (Art. 6, 7, 15–21), identifies lawful bases for each processing activity, names all data processors including cross-border transfer mechanisms (SCCs, Data Privacy Framework), and provides a CNIL complaints pathway. The platform is hosted exclusively on EU-based infrastructure (OVH in Roubaix, Scaleway in Paris). The risk level is Low because strong structural compliance evidence exists: DPO appointment, documented processing records, EU-only hosting, and explicit GDPR compliance claims backed by ISO 27001/27017 and ISO 27701 certifications on the infrastructure layer. Residual risk relates to third-party processors in the US (HubSpot, Cloudflare, Factors.ai) which rely on the Data Privacy Framework and SCCs — mechanisms that carry some legal uncertainty post-Schrems II, though appropriate safeguards appear to be in place.
Evidence: https://www.yeswehack.com/page/privacy-policy, https://www.yeswehack.com/product/trust-security, https://www.yeswehack.com/about, https://www.cnil.fr/fr/plaintes
French Data Protection Act — Compliant
As a French company, YesWeHack is subject to the French Data Protection Act (as amended to align with GDPR). The Privacy Policy explicitly references 'the French Data Protection Act n°78-17 of 6 January 1978, as amended' and identifies CNIL as the competent supervisory authority. The DPO appointment and GDPR compliance measures also satisfy French national requirements. Risk is Low given explicit acknowledgment and compliance measures documented in the Privacy Policy.
Evidence: https://www.yeswehack.com/page/privacy-policy, https://www.cnil.fr/
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 6/10
YesWeHack is a well-established, VC-backed French cybersecurity scale-up with strong European and APAC market positions. The company benefits from significant venture capital backing, including a €16M Series B round in December 2021 led by Eiffel Investment Group, with cumulative funding estimated at €25-30M. Its enterprise and regulated-sector client base (L'Oréal, Ferrero, TeamViewer, European government/defense entities) provides recurring revenue with long-tenured contracts supporting low churn. The company's sovereignty positioning (ISO 27001/17/18/27701, SOC 2 Type II, SecNumCloud-compliant, CREST-accredited, EU-hosted infrastructure) provides differentiation against US competitors in EU public-sector and regulated-industry markets, aligned with NIS2/DORA/GDPR. Its subscription/platform business model in bug bounty and continuous pentesting offers visibility on ARR. However, as a private SAS with confidential accounts, precise revenue, EBIT, and equity figures are not publicly available, limiting external stakeholders' ability to assess resilience directly. The company faces competitive pressure from larger US-based competitors (HackerOne, Bugcrowd) and European rival Intigriti. Typical of scale-ups in growth mode, cash burn is likely and no public profitability signal is available. Overall resilience score reflects strong strategic positioning offset by disclosure opacity and competitive dynamics.
Key strengths: €16M Series B (Dec 2021) led by Eiffel Investment Group, Cumulative funding of approximately €25-30M, Strong enterprise client base including L'Oréal, Ferrero, TeamViewer, EU sovereignty positioning aligned with NIS2/DORA/GDPR, ISO 27001, SOC 2 Type II, SecNumCloud compliance, Recurring subscription/platform revenue model, Community of 135,000+ ethical hackers, Customers in 50+ countries, Revenue reportedly doubled YoY in 2020 and 2021, Product expansion beyond bug bounty into Autonomous/Agentic Pentest
Risk factors: Competitive pressure from larger US-based competitors (HackerOne, Bugcrowd), Direct European competition from Intigriti, Concentration in Europe/APAC with smaller North America presence, Likely cash burn typical of growth-stage scale-ups, Two-sided marketplace requires continuous investment in both sides, Confidential accounts limit financial transparency, FX and geopolitical exposure across 50+ countries, Consolidation risk in crowdsourced security space
Revenue by geography
- France & Rest of EU: 65%
- APAC: 20%
- Rest of World (Americas, Middle East): 15%
Revenue by product/service
- Bug Bounty Platform: 70%
- Continuous Pentesting: 15%
- Autonomous & Agentic Pentest: 8%
- VDP (Vulnerability Disclosure Policy): 7%
Workforce by country
- France: 105
- Rest of EMEA: 25
- Singapore (APAC): 25
- North America: 10
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.