nowfound

Alternatives

Products that do what DISCLOSURE does

Liberating Security Research

  1. 1
    Federacy203

    Bug bounty and security testing platform.

    2018

  2. 2

    List of Bug Bounty Programs and Responsible Disclosures

    Nov 2025 · bugbountydirectory.com

  3. 3GB
  4. 4

    Affordable, expert-led vulnerability management for startups

    2025

  5. 5

    Publish agent-generated HTML behind company auth

    May 2026 · display.dev

  6. 6
    tul:si95

    A web2 & web3 bug bounty platform

    2023

  7. 7MU

    Most feedback tools are built like people actually want to report bugs. They don’t. Unless you make it dead-simple, or better yet - a little fun. After shipping a few SaaS products, I noticed a pattern: Bugs? Yes. Bug reports? No. Not because users didn’t care but because reporting bugs is usually a terrible experience. Most tools want users to: * Fill out a long form * Enter their email * Describe a bug they barely understand * Maybe sign in or create an account * Then maybe submit it Let’s be real: no one’s doing that. Especially not someone just trying to use your product. So I built…

    2025

  8. 8
    BountyHub344

    Monetizing GitHub issue resolution through bounties

    2024

  9. 9

    Capture bugs contextually & collab better with developers

    2024

  10. 10

    Vulnerability intelligence for real-time threat analysis

    2024

  11. 11
    wallarm151

    Reveal security flaws in web apps and APIs

    2016

  12. 12
    HackGATE128

    Empowering ethical hacking with visibility and control

    2024

  13. 13

    Detect secrets in source code, public and private!

    2018

  14. 14
    Owltics125

    Report bugs directly from your product

    2024

  15. 15

    Security for modern teams running software

    2017

  16. 16IB

    I built this because I wanted my own directory of public companies running bug bounty programs — where I could see their infrastructure in one place and have a real idea of where to start poking holes. Neobotnet collects intel data from companies on HackerOne and Bugcrowd — subdomains, DNS records, web servers with status codes, indexed/crawled URLs, JS files, and exposed secrets/paths (still building this last part). The data is already there when you need it. No scans to run. Currently tracking 41 companies, 63,878 web servers, and 1.8M+ URLs. Long term I want to expand this to…

    Mar 2026 · neobotnet.com

  17. 17

    Open sourced application to detect security vulnerabilities.

    2020

  18. 18

    A simple way for your users to report bugs

    2023

  19. 19

    Reward your employees for reporting security bugs

    Jul 2026 · sevhunt.com

  20. 20NI

    Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware

    2022 · github.com

  21. 21BC
  22. 22RO

    Finally open sourced an internal tool we've been using for managing secrets. It's similar to SOPS, but more opinionated, easier to configure/use correctly, and produces nicer git diffs. It also supports one-way encryption, so you don't have to know the private key to add secrets.

    2023 · github.com

  23. 23FS
  24. 24

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →