
Bounty Security
Bounty Security is a Spanish publisher of four offensive security scanners sharing one profile format. Its AI Scanner lets a large language model decide which vulnerability types to test, serving pentesters, red teams and bug bounty hunters.
What is Bounty Security?
Bounty Security S.L., based in Valencia, Spain, publishes an ecosystem of four web vulnerability scanners that all read and write the same profile format, the .bb file. The site sums it up as “Four tools. One ecosystem. Every profile you build works across the entire suite.”
Burp Bounty Pro is the flagship: an extension for Burp Suite Professional shipping 254 ready-made vulnerability profiles, 27 Smart Scan rules, multi-step scanning with cookie reuse for authenticated workflows, and more than 30 insertion point types. Detection can key on plain strings, regular expressions, HTTP status codes, time delays or Blind Host interactions.
The AI is functional rather than decorative. Since v3.1.0 (March 2026), an AI Scanner has a large language model read each request and response, map the attack surface, correlate parameters with vulnerability classes and recommend which profiles to launch; Auto-Scan then fires the matching ones. A programmatic routine runs first, extracting parameter reflections and their contexts — HTML body, JavaScript, CSS, attributes, event handlers, URL, comments — along with security headers, so the model works on prepared evidence. Its output follows a twelve-field schema covering parameter, type, insertion point index, reflected status, contexts, content type, attack types, confidence, priority, detected technology, reasoning and recommended profiles. Users bring their own key for OpenAI, Anthropic, Google Gemini, OpenRouter or a local model through Ollama.
Burp Bounty Go moves the engine to Golang, claiming over 10,000 requests per second, distributed scan servers on localhost or a remote VPS, and a built-in Blind Host for out-of-band testing. GBounty is a free, open-source standalone Golang scanner with native Linux, Windows and macOS binaries and no dependencies. Bounty Prompt, also free and open source, wires Burp’s HTTP traffic to Burp AI and Groq Cloud with pre-configured prompts and automated Burp issue creation.
The extensions require Burp Suite Professional and Java 14 or later, and installation is advertised in under three to five minutes. Bounty Security also sells web, API and LLM penetration testing services. The intended audience is stated plainly: pentesters, red teams, bug bounty hunters and AppSec teams.
What it does
- Extend Burp Suite with 254 ready-made vulnerability profiles without writing code
- Let a large language model decide which tests to run against each request
- Chain passive detection into active attacks through IF-THEN rules
- Test authenticated workflows with multi-step scans that reuse cookies
- Scan at more than 10,000 requests per second from distributed servers
- Detect out-of-band vulnerabilities with a built-in Blind Host
- Share a single .bb profile across all three scanners
When to use Bounty Security / When not to
A quick filter to help you decide if Bounty Security is the right fit.
When to use Bounty Security
- Penetration testers and security consultancies automating the repetitive part of an engagement
- Red teams chaining multi-step profiles and scaling across distributed scan servers
- Bug bounty hunters aiming to cover more attack surface in less time
- AppSec and development teams folding automated scanning into their security workflow
- Burp Suite Professional users who specifically need authenticated scanning beyond the login screen
When not to use Bounty Security
- Anyone without Burp Suite Professional and Java 14 or later, since three of the four tools run as Burp extensions and only GBounty is standalone
- Users expecting a push-button scanner with no security knowledge, as most of the value comes from customising profiles
- Teams that want a mobile app or a web console, because these are desktop and command-line tools
- Organisations needing a product API to wire scanning into a third-party pipeline, since none is published
- Environments that forbid sending HTTP context to a third-party LLM, unless a local model is run through Ollama
How to use Bounty Security
A typical end-to-end flow, from setup to results.
- Check the prerequisites first: Burp Suite Professional and Java 14 or later for the extensions, while GBounty needs neither
- Request a free trial through the try-for-free form, choosing the product you want; the details then arrive by email
- Or buy from the store on a monthly or yearly plan; each licence is user-based and allows three device activations
- Install Burp Bounty Pro as a Burp Suite extension and load the default profiles, a step advertised at under five minutes
- Right-click a request in Burp Suite to launch a scan, selecting the profiles you want by tag
- Open Settings and add an API key for your chosen LLM provider to enable the AI Scanner; a warning popup appears if the key is missing
- Adjust the system and user prompts through the Edit Prompts dialog if you want to steer the model
- Write Smart Scan IF-THEN rules to chain passive detection into active attacks
- For Burp Bounty Go, start one or more scan servers on localhost or a VPS, then drive them from Burp Suite
- Export your profiles as .bb files to reuse them across all three tools, and run the GBounty binary from the command line when you need a standalone scan
Pros & Cons
Pros
- 254 profiles and 27 Smart Scan rules usable straight out of the box
- Two of the four tools, GBounty and Bounty Prompt, are entirely free and open source
- One .bb profile format shared by all three scanners, so work invested once is reusable everywhere
- Free choice of LLM provider, including a local model through Ollama for sensitive engagements
- Fast Golang engine with distributed scanning and a built-in Blind Host, removing the need for Burp Collaborator or an external out-of-band service
- Low entry price for a professional tool at EUR 14.95 per month, with a free trial on request and a 15-day money-back guarantee
- Public and detailed changelog
Cons
- Three of the four tools depend on Burp Suite Professional, a paid third-party licence that is not included
- No product API, so scanning cannot be wired into a CI/CD pipeline
- No postal address published on the site: the privacy policy stops at a registered address in Spain
- No published support email; support runs exclusively through a contact form
- No pricing page as such, the amounts living inside the Shopify product pages
- Terms and conditions for the three products are dated 29 April 2021, more than a year before the company was incorporated on 3 June 2022
- No published DPA, no product subprocessor list and no named security certification, neither ISO nor SOC 2
Pricing & Plans
A free tier exists within the ecosystem: GBounty and Bounty Prompt are open source and free to use with no time limit. The paid range starts at EUR 14.95 per month for Burp Bounty Pro, or EUR 145.00 per year against a EUR 179.00 list price; Burp Bounty Go is EUR 24.95 per month or EUR 245.00 per year against a EUR 299.00 list price. Both are sold as subscriptions rather than one-off purchases, and each licence is user-based with three device activations. Burp Suite Professional, required by the extensions, is a separate third-party licence and is not included in these amounts. A 15-day money-back guarantee applies, with the licence to be deactivated and the refund issued within five to seven business days; requests made after 15 days, and products bought on sale or with a discount, are excluded. Prices are charged in euros.
- EUR 14.95 per month
- EUR 145.00 per year
- against a EUR 179.00 list price
- EUR 24.95 per month
- EUR 245.00 per year
- against a EUR 299.00 list price
- GBounty — free and open source
- Bounty Prompt — free and open source
Data, GDPR & hosting
A consolidated view of how Bounty Security handles your data.
GDPR overview
The privacy policy applies the GDPR without ever claiming, in so many words, to be GDPR compliant. Bounty Security S.L., established in Spain, is named as the data controller. The document lists the legal bases relied on — performance of a contract, legal obligations, vital interests, public interest, legitimate interests and consent — and sets out the rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. The competent supervisory authority is named: “In Spain, the competent authority is the Agencia Española de Protección de Datos (AEPD)”. Transfers outside the EEA are covered by standard contractual clauses or an adequacy decision, and consent is collected through a banner before non-essential cookies fire. CCPA and CPRA rights are handled separately for California residents. No Article 27 representative is designated, which is consistent with a controller established inside the EU. Last updated 17 March 2026.
Who owns the data?
The privacy policy names Bounty Security S.L. as the data controller for the personal data the site and the store collect, and describes third-party providers as data processors under the GDPR. Ownership of submitted content stays with the user: the terms state that “You retain any and all of Your rights to any Content You submit, post or display on or through the Service.” The publisher also claims its tools “conduct scans locally, without sending sensitive data to external servers”, a statement to weigh against the AI features, which forward HTTP context to whichever LLM provider the user configures. No data processing agreement is published or announced as available on request.
Reuse rights
Because the terms leave ownership of submitted content with the user, scan results, findings and custom profiles produced with the tools can be reused, exported and shared without asking the publisher for permission; profiles are explicitly designed to be exported as .bb files and passed between the three scanners and across a team. On the publisher’s side, the privacy policy lists account data, usage data and cookies, used to provide and maintain the service, manage accounts, perform the contract, contact users, send offers, and analyse usage trends and campaign effectiveness. That data may be shared with service providers for analytics, advertising, payment and contact, with affiliates and business partners, and in the course of a corporate transaction. Nothing in the documents describes training AI models on customer data. Separately, the AI Scanner and Bounty Prompt send HTTP context to the LLM provider the user chooses, under the user’s own API key; running a local model through Ollama keeps that traffic in-house. Transfers outside the EEA rely on standard contractual clauses or an adequacy decision.
Data retention & training
Hosting summary
No hosting country or region is named anywhere on the site. The privacy policy goes no further than saying that data is processed at the company’s operating offices and in any other places where the parties involved in the processing are located, which identifies no jurisdiction. Transfers outside the EEA are covered by standard contractual clauses or an adequacy decision, which is a transfer safeguard rather than a statement of where data is stored. The public site is a Shopify store served behind Cloudflare on an anycast address (23.227.38.65), but that describes the hosting of the shop front, not of product data. The distinction matters here: the scanners are desktop and command-line software, so scans execute on the user’s own machine or on scan servers the user provisions on localhost or a VPS. Scan traffic and results therefore stay under the user’s control, except for the HTTP context the AI features send to the LLM provider the user selects. Bounty Security S.L. is established in Spain and names the AEPD as its supervisory authority, which places the controller inside the EU even though the storage location is undisclosed.
Things to keep in mind
Risks and trade-offs to weigh before adopting Bounty Security.
- Internal contradiction on where data goes: the homepage states that the tools “conduct scans locally, without sending sensitive data to external servers”, while the AI Scanner and Bounty Prompt forward HTTP context to third-party LLMs (OpenAI, Anthropic, Google Gemini, OpenRouter, Groq Cloud). Only a local model through Ollama keeps that traffic on your machine. Confirm which mode you are running before scanning a client application.
- Contractual documents that predate the company: the terms of the three products are dated 29 April 2021, more than a year before Bounty Security S.L. was incorporated on 3 June 2022, and the domain was only registered on 11 December 2023. Any contractual fact drawn from those pages should be treated as fragile.
- Unedited store template residue: the refund policy still carries a bracketed support@bountysecurity.com followed by the editing instruction “(or your support email)”, on a .com domain the publisher does not operate, and the Burp Bounty Go page keeps a placeholder paragraph beginning “Use this section to explain a set of product features”.
- The 15-day money-back guarantee excludes items bought “on sale or with a discount”, yet both paid products are permanently displayed with a struck-through price. Get written confirmation that your purchase is refundable before paying.
- Limited corporate transparency for a security vendor: no postal address, no support email, support only through a form, no published DPA and no product subprocessor list. “Our Certified Pentesters” is a section heading with no named certification, number or issuing body, OWASP being cited only as a methodology, and the named testimonials on the homepage are undated quotes with no link to the original post.
- Version inconsistency across the site: the solutions page advertises v3.0 as the latest while the homepage and changelog give v3.1.0 (March 2026). Check which build you are actually installing.
- Offensive tooling carries its own risk. These scanners send real attack traffic: automated profiles can reach out-of-scope hosts, destabilise production systems or break the law if run without written authorisation. An AI-assisted shortlist is also a comfortable thing to over-trust, and a clean report is not evidence that an application is secure, only that the selected profiles found nothing.
Setup & Integrations
Technical difficulty
Moderate, and it varies by tool. GBounty is the easiest: a dependency-free binary you download and run. Burp Bounty Pro is straightforward if you already own Burp Suite Professional and Java 14 or later: installation is advertised at three to five minutes, the default profiles load at once, a scan can run immediately, and customising profiles needs no code. The AI Scanner adds a step: an account with an LLM provider and a configured API key. Burp Bounty Go is the most demanding, since you provision and administer the scan servers yourself, on localhost or a remote VPS.
Deployment
Integrations
Behind Bounty Security
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Do I need Burp Suite Professional to use these tools?
What are the technical requirements?
How many devices does one licence cover?
Which AI providers are supported?
Do I need to be a cybersecurity expert?
Is there a free trial?
Can I get a refund?
Can I share the profiles I build?
Is there a product API?
What is the latest version?
Should you pick Bounty Security?
Bounty Security has built something coherent rather than a scattering of products: four scanners that all speak the same .bb profile format, so work invested in one tool carries into the others. The AI sits where it is genuinely useful, as a routing layer — a language model reads a request, decides which vulnerability classes are worth testing and points at the matching profiles. It shortlists tests; it does not replace the tester’s judgement, and the publisher does not pretend otherwise.
The barrier to trying it is low. Two of the four tools are free and open source, the paid range starts at EUR 14.95 per month, a trial is available on request, and a 15-day money-back guarantee applies — though that guarantee excludes purchases made on sale, while both paid products are permanently displayed at a struck-through price.
Two reservations deserve weight. First, dependency: three of the four tools are Burp Suite Professional extensions, so the real cost includes a third-party licence Bounty Security does not sell, and only GBounty stands alone. Second, corporate transparency is thin for a security vendor — no postal address beyond a registered address in Spain, no support email, support only through a form, no published DPA or subprocessor list, no named certification, and product terms dated more than a year before the company was incorporated. None of that is disqualifying, but a buyer running due diligence will notice.
The suite is most relevant to people who already practise applied web application penetration testing and know what to do with a finding. For them, the profiles, the multi-step authenticated scanning and the distributed Golang engine are real time savers. For anyone hoping a scanner will stand in for the skill, this is not it.
- Choosing a selection results in a full page refresh.
- Opens in a new window.