Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
The Evidence Platform is a vulnerability management system that employs evidence-based methods to assist organizations in identifying their external attack surface, pinpointing vulnerabilities that can lead to significant financial ramifications, demonstrating the benefits of remediation efforts, and providing financial protection for the outcomes. Utilizing the Evidence Graph, which serves as a dynamic model of the internet, the platform effectively maps an organization's publicly accessible assets prior to configuration, capturing infrastructure that may have been overlooked by traditional seed-based discovery methods. It clarifies the ownership of each asset, monitors the emergence of new assets through certificate logs and passive DNS, and enables searches based on technology, ports, certificates, geography, and associated risks. The Evidence Scan feature conducts daily assessments of each asset against the FIRE list, Known Exploited Vulnerabilities (KEVs), and personalized Common Vulnerability and Exposure (CVE) lists via non-intrusive external scanning. FIREs refer to externally accessible CVEs linked to verified losses documented in insurance claims, forensic records, reinsurer databases, or public disclosures, making this platform an invaluable tool for proactive vulnerability management. In addition, organizations can leverage this platform to stay ahead of potential threats and ensure their defenses are continuously optimized.
Description
The Open Bug Bounty initiative provides a platform for website owners to receive insights and assistance from security experts worldwide in a manner that is transparent, equitable, and organized, ultimately enhancing the security of web applications for the collective good. This platform facilitates coordinated vulnerability disclosures, allowing any legitimate security researcher to report vulnerabilities on various websites, provided the findings are obtained without using invasive testing methods and adhere to responsible disclosure practices. Open Bug Bounty's involvement is strictly to verify the reported vulnerabilities independently and to ensure that website owners are informed through all available channels. After the notification process, the website owner and the researcher can communicate directly to address the vulnerability and manage its disclosure effectively. At all stages of this process, we do not serve as a middleman between the website owners and the researchers, fostering a direct line of communication to promote a smoother resolution. This approach ultimately enhances trust within the cybersecurity community, encouraging more researchers to participate in improving web application security.
API Access
Has API
No
API Access
Has API
Yes
Integrations
Bugzilla
No
Jira
No
MantisBT
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
Root Evidence
Founded
2025
Country
United States
Website
www.rootevidence.com
Vendor Details
Company Name
Open Bug Bounty
Founded
2014
Website
www.openbugbounty.org
Product Features
Vulnerability Management
Asset Discovery
No
Asset Tagging
No
Network Scanning
No
Patch Management
No
Policy Management
No
Prioritization
No
Risk Management
No
Vulnerability Assessment
No
Web Scanning
No
Vulnerability Scanners
Asset Discovery
No
Black Box Scanning
No
Compliance Monitoring
No
Continuous Monitoring
No
Defect Tracking
No
Interactive Scanning
No
Logging and Reporting
No
Network Mapping
No
Perimeter Scanning
No
Risk Analysis
No
Threat Intelligence
No
Web Inspection
No