Yogosha
A decade-old French bug bounty pioneer that entered receivership in early 2026 and was rescued from liquidation by Rennes-based IT group Creative, which is folding Yogosha's offensive security services into its own client base across seven French regions.
Visit Website ↗ + Add to CompareInnovation Matrix Assessment
Recently added an MCP server and AI-powered vulnerability triage to modernize its bug bounty workflow ahead of a planned AI-augmented offensive security push.
Operated a decade-long curated bug bounty and pentesting practice generating EUR3.3M in 2024 revenue before financial distress.
Entered receivership in early 2026 and was acquired only as a rescue-from-liquidation deal, a negative rather than positive momentum signal.
Curated/private bug bounty platforms are a known model competing against larger open platforms like HackerOne and Bugcrowd; not a novel category.
Reported 2024 revenue (EUR3.3M) is independently sourced, but the receivership undercuts confidence in sustained commercial traction.
Bug bounty and offensive security testing remain a standard, ongoing need, though the company's financial distress raises questions about execution.
Why CISOs Should Care
Yogosha gives CISOs access to a curated, invite-only community of vetted ethical hackers for bug bounty and penetration testing, an alternative to open-crowd platforms for organizations that want tighter control over who tests their systems.
What Makes It Different
Yogosha runs a private, curated hacker community model rather than an open marketplace, and has recently added an MCP server and AI-powered vulnerability triage to speed up how bounty findings get validated and routed to client teams.
The Matrix Verdict
35/100 — EMERGING / UNRANKED
A decade-old French bug bounty pioneer that entered receivership in early 2026 and was rescued from liquidation by Rennes-based IT group Creative, which is folding Yogosha's offensive security services into its own client base across seven French regions.
Editorial Note: Claims vs. Verified Findings
The financial distress (receivership, 2024 revenue of 3.3M EUR) and employee count (~20) are reported directly by French trade press (Le Monde Informatique, Journal des Entreprises); this is a distressed-asset acquisition, not a growth-stage exit.
Sources
Alternatives to Yogosha
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…