Innovation Matrix Assessment
Acquired existing bug-bounty technology and team rather than building offensive-security capability organically.
Yogosha's bug-bounty platform and AI-powered vulnerability triage now operate under Creative's regional service umbrella.
Rescue acquisition from receivership, announced June 12, 2026, extends Creative's regional presence across France.
A conventional regional IT services group entering an established category (bug bounty), not a disruptor.
Yogosha's prior financial distress (receivership) raises real questions about commercial traction, even though the technology and team persist.
Crowdsourced offensive security remains relevant to French enterprises, now with Creative's stability behind it.
Why CISOs Should Care
Groupe Creative, a Rennes-based IT services group, now gives French enterprise clients bug-bounty and crowdsourced offensive-security capability by rescuing Yogosha from liquidation and absorbing its ~20-person team.
What Makes It Different
Preserved an established French bug-bounty platform (and its AI-powered vulnerability triage/MCP server tooling) that would otherwise have been lost to receivership, rather than building offensive-security capability from scratch.
The Matrix Verdict
30/100 — EMERGING / UNRANKED
A regional IT services group extending into offensive security via a distressed-asset acquisition; Yogosha's team and technology survive intact under Creative's ownership.
Editorial Note: Claims vs. Verified Findings
Yogosha's prior receivership status and near-full team retention are independently corroborated across multiple French trade outlets (Le Monde Informatique, INCyber News, ChannelNews); financial terms undisclosed.
Sources
Alternatives to Creative
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…