SecurityBoat

TriNetra · Opportunities

A blind-bid marketplace for pentest work.

Sanitized engagement scope summaries for researchers — customer identity is revealed only after your bid is accepted. You're bidding on the shape of the work: asset type, testing style, duration, payout — before you ever learn whose environment you'd be testing.

How it works

Five steps from sanitized listing to tracked engagement.

  1. 01

    Browse sanitized listings

    Every open opportunity shows an engagement summary stripped of anything that would identify the client — no company name, no domain, no logo.

  2. 02

    Read the real terms on the card

    Each listing expands into the actual bid terms you'd be committing to — nothing is negotiated after the fact.

  3. 03

    Submit your bid

    Once you apply, the card updates to show your status — the platform's own applied-state copy reads “✓ You have already applied for this opportunity.”

  4. 04

    Get accepted, then get the reveal

    Customer identity — company name, environment access, and full scope detail — unlocks only once your bid is accepted. Until then, you're evaluating the work on its merits, not its logo.

  5. 05

    Move into a tracked engagement

    Accepted bids convert into a real PTaaS engagement with its own state stepper, team, and coverage tracking — the same instrumentation the client sees on their side.

Step 2 — the full terms
Sanitized listing██████████.com

Web Application Pentest

Pentest Type
Web Application
Testing Type
Grey Box
Pentest Duration
10 business days
Testing Hours
40 hours
Fixed Payout
₹1,20,000 (illustrative)
Source-access badge
Source access included
Step 4 — before acceptance
Sanitized listing██████████.com

Web Application Pentest

Grey box · 10 business days · Fixed payout ₹1,20,000 (illustrative)

Step 4 — after acceptance
Client revealedyourcompany.com

Web Application Pentest

Grey box · 10 business days · Fixed payout ₹1,20,000 (illustrative)

What an accepted bid becomes

Pentest Engagements

Total 20Active 14Completed 6
Movies Network Penetration TestLive6 findings
Mobile Banking API — Grey BoxReport review11 findings
Partner Gateway — Black BoxClosed4 findings

Anatomy of a bid card

Every listing carries the same six fields.

So comparing two opportunities is a like-for-like read, not guesswork.

Pentest Type
The category of engagement — web app, mobile, network, cloud, and so on.
Testing Type
Black box, grey box, or white box — how much access and source visibility you'll be given.
Pentest Duration
The engagement's total calendar window.
Testing Hours
The effort budget you're bidding to deliver within.
Fixed Payout
A flat amount for the engagement, shown up front — e.g. INR 120,000 (illustrative; actual payout varies by engagement). No negotiating after you've started.
Source-access badge
Whether source-code access is included, which changes how deep grey/white-box testing can go.
The full bid card, expanded
Sanitized listing██████████.com

Web Application Pentest

Pentest Type
Web Application
Testing Type
Grey Box
Pentest Duration
10 business days
Testing Hours
40 hours
Fixed Payout
₹1,20,000 (illustrative)
Source-access badge
Source access included

Why blind-bid

Signal, not noise — applied to who gets the work.

For clients

Sanitizing the client side first lets buyers post real, sensitive scope without broadcasting which of their systems is under test.

For researchers

You get to evaluate opportunities purely on testing type, duration, and payout — without unconscious bias toward big-name logos or against unfamiliar ones. The same “signal, not noise” principle the platform applies to findings, applied to how work gets assigned in the first place.

FAQ

Common questions.

Yes — nothing is final until the client accepts and identity is revealed.

The pool

Not in the pool yet?

Apply to the researcher pool first — opportunities open up once you're vetted.