Edge Rewrite
// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a445b2b9acab227c

Jump to content

YesWeHack

From Wikipedia, the free encyclopedia
YesWeHack
IndustryCybersecurity
Founded2015; 11 years ago (2015)
HeadquartersParis, France
Websitewww.yeswehack.com

YesWeHack is a global security company headquartered in Paris, France.[1] Founded in 2015, it operates a crowdsourced platform for bug bounty programs[2] through which organisations invite ethical hackers to identify and report security vulnerabilities.[3][4] The company has subsequently expanded its activities into vulnerability management, exposure management and AI-assisted penetration testing.[5]

History

[edit]

YesWeHack was founded in 2015. Its co-founders are Guillaume Vassault-Houlière, Manuel Dorne and Romain Lecoeuvre.[6]

In 2019, the company raised €4 million from Open CNP, the corporate venture program of CNP Assurances, and Normandie Participations.[7] In 2021, YesWeHack raised €16 million in Series B funding. The second round was led by the Series A investors as well as Banque des Territoires and Eiffel Investment Group.[8]

In June 2024, it raised €26 million ($28 million) in a Series C funding round, led by Wendel, with participation from Adelie, Seventure Partners, Bpifrance, Open CNP and Eiffel Investment Group.[9] The round brought the company's total funding to €46 million ($52 million).

In September 2025, YesWeHack made its first acquisition, purchasing French cybersecurity auditing company Sekost.[10]

Later that month, YesWeHack became a CVE Numbering Authority (CNA), allowing it to assign CVE identifiers and publish CVE records for vulnerabilities within its defined scope. It became the eight CNA based in France.[11]

In October 2025, the company was selected as the first-ranked provider under a European Commission framework agreement for bug bounty services. The four-year framework contract has a maximum potential value of approximately €7,6 million.[12][13]

In June 2026, YesWeHack launched Agentic Pentest, an on-demand penetration-testing service using autonomous artificial intelligence agents. Dassault Systèmes and Sanofi were among the first companies reported to have deployed the service.[5][14]

Operations

[edit]

YesWeHack initially focused on crowdsourced security testing through bug bounty programmes. It later expanded into a broader offensive security and exposure management platform, incorporating vulnerability management, exposure management and AI-based penetration testing.[5]

Following the acquisition of Sekost in 2025, YesWeHack employed approximately 150 people across seven countries. The company said at the time that it served nearly 1,000 customers in around 50 countries and generated approximately half of its revenue outside France.[10]

Among the organisations mentioned by the press as customers or users of YesWeHack's services are Louis Vuitton[15], Decathlon[16],Doctolib[17], Ferrero[18], Ooredoo[19], TeamViewer[20], Swiss Post[21], and the Quebec Ministry of Cybersecurity and Digital Affairs[22].

By 2026, the platform's community had grown to more than 150,000 registered ethical hackers.[23]

References

[edit]
  1. ↑ "Covid: White hat bounty hackers become millionaires". BBC News. 2021-03-10. Retrieved 2021-07-01.
  2. ↑ "Top 5 Bug Bounty Platforms to Watch in 2021". The Hacker News. Retrieved 2021-07-01.
  3. ↑ "When YesWeHack's "ethical hackers" profit from the revival of telework". Web24. 2020-03-27.
  4. ↑ JDD, Le (17 February 2021). "YesWeHack, l'arme anti-pirates informatiques". lejdd.fr (in French). Retrieved 2021-07-02.
  5. 1 2 3 "YesWeHack automates penetration testing with AI-powered agents". Help Net Security. 2026-06-25. Retrieved 2026-09-25.
  6. ↑ and Helen O'Reilly-Durand (2024-06-25). "The Big Deals 💣 : Mistral AI, YesWeHack, C12, Omi & More!". The French Tech Journal. Retrieved 2026-09-25.
  7. ↑ Loritz, Mary (2019-02-15). "French startup YesWeHack raises €4 million with plans to disrupt Europe's cybersecurity market". EU-Startups. Retrieved 2021-07-01.
  8. ↑ Guarin, Anto (2021-07-22). "Paris-based cybersecurity startup YesWeHack lands €16 million to accelerate its international expansion". EU-Startups. Retrieved 2021-10-28.
  9. ↑ Arghire, Ionut (2024-06-13). "French Bug Bounty Platform YesWeHack Raises $28 Million". SecurityWeek. Retrieved 2026-09-25.
  10. 1 2 Armand, Johann (2025-09-10). "YesWeHack s'ouvre vers le channel avec le rachat de Sekost". ChannelNews (in French). Retrieved 2026-09-25.
  11. ↑ "YesWeHack Added as CVE Numbering Authority (CNA)". www.cve.org. Retrieved 2026-09-25.
  12. ↑ "On n'arrête plus YesWeHack, qui signe le contrat de sa vie avec la Commission européenne". clubic.com (in French). 2025-10-02. Retrieved 2026-09-25.
  13. ↑ "YesWeHack Won the European Commission's Latest Bug Bounty Tender". 2025-10-02.
  14. ↑ Meliss@11 (2026-06-26). "YesWeHack révèle son Pentest Agentique". INCYBER NEWS (in French). Retrieved 2026-09-25.{{cite web}}: CS1 maint: numeric names: authors list (link)
  15. ↑ "Avec YesWeHack, Louis Vuitton cherche des failles et sensibilise - Le Monde Informatique". LeMondeInformatique (in French). 2024-04-12. Retrieved 2026-09-25.
  16. ↑ "Decathlon éprouve sa sécurité par un bug bounty". www.cio-online.com (in French). 2022-06-24. Retrieved 2026-09-25.
  17. ↑ "FIC 2021 : Doctolib et Yes We Hack à la chasse aux bugs". www.linformaticien.com. 2021-09-09. Retrieved 2026-09-25.
  18. ↑ Marco, Andrea De (2024-10-07). "YesWeHack e Ferrero inaugurano il primo evento di live hacking in Italia". 01net (in Italian). Retrieved 2026-09-25.
  19. ↑ Doha (2023-02-26). "Ooredoo launches new cybersecurity programme". Gulf Times. Retrieved 2026-09-25.
  20. ↑ "Bug Bounty Program". TeamViewer (in French). Retrieved 2026-09-25.
  21. ↑ swissinfo.ch, S. W. I. (2021-04-15). "La Poste invite les hackers à rechercher ses failles de sécurité". SWI swissinfo.ch (in French). Retrieved 2026-09-25.
  22. ↑ ICI.Radio-Canada.ca, Zone Politique- (2023-10-12). "Québec veut tester tous ses sites web avec des pirates informatiques". Radio-Canada (in Canadian French). Radio-Canada.ca. Retrieved 2026-09-25.
  23. ↑ "Les géants de l'IA estiment que les cyberdéfenses actuelles ne tiendront bientôt plus". clubic.com (in French). 2026-08-28. Retrieved 2026-09-25.