Pre-launch · Lifetime tier limited to first 200

Stop Submitting Slop.

AI-generated reports broke bug bounty. Programs are closing. Reputations are tanking. Rapax is the anti-slop workflow that forces verification before you submit — every step, every finding.

Local-first, BYOK AI macOS · Windows · Linux Built by hunters
The Slop Crisis

Bug bounty is breaking. Here's why.

Programs are killing themselves with floods of AI-generated noise. Triagers can't keep up. Hunters with real findings get buried. The whole pipeline is rotting.

!

Curl shut its program

Daniel Stenberg called it: an "AI slop avalanche." Reports that look real, sound real, and waste maintainers' time at scale. The program closed.

!

Nextcloud killed theirs too

Same story. Volunteer security teams burning hours rejecting hallucinated CVEs. Open-source projects are pulling the plug across the board.

!

Platforms are fighting back

HackerOne, Bugcrowd, and Intigriti are tightening rules and penalizing low-quality submissions. Your reputation score now decides what you can even see.

!

Solo hunters get blamed

You wrote the report yourself, ran it through your own pipeline, verified the impact — and still get triaged behind a mountain of generated junk. Signal is dying.

The Workflow

10 modules. Every one enforces verification.

Rapax doesn't generate reports for you. It blocks you from submitting until each finding has been scoped, deduped, evidenced, and proven.

01

Scope Guard

Every command, every payload, every URL is checked against the program scope before it runs. Out-of-scope = blocked. No accidents.

02

Slop Filter

Report drafts run through a hallucination detector before submission. Unverifiable claims, fake CVEs, and AI-tellsmarked and gated.

03

Evidence Vault

Screenshots, requests, responses, payloads — captured automatically with cryptographic timestamps. Nothing in your report that isn't in the vault.

04

Duplicate Detector

Local index of your past findings + public disclosures. Catches dupes before you waste a submission slot or your reputation.

05

Reproducibility Check

Forces a clean second run from a fresh state. If you can't reproduce it on demand, the report doesn't go out.

06

Impact Calibrator

CVSS scoring with prompts that catch the inflation patterns triagers downgrade. No more "Critical" reports that come back as Low.

07

Report Composer

Templates that match each platform's house style. Fields you actually have evidence for. Nothing more, nothing padded.

08

BYOK AI Layer

Use your own Anthropic, OpenAI, or local Ollama key. Models suggest, never decide. You stay the author of every word that leaves the tool.

09

Submission Ledger

Tracks every report you've sent across every platform. Status, payouts, response times, dupe rates — your hunter analytics in one place.

10

Reputation Watch

Monitors your signal score on each platform. Flags when a recent submission is dragging you down so you can course-correct fast.

"Built by bug bounty hunters, for bug bounty hunters. We got tired of being lumped in with the slop pile — so we built the workflow that keeps us out of it."
— The Rapax team
Pricing

Priced for solo hunters.

One-time lifetime deal for the first 200. After that, monthly or annual. Free tier always exists.

Free
$0forever
Get a feel for the workflow.
  • 1 program tracked
  • 5 findings per month
  • Scope Guard + Slop Filter
  • Local Evidence Vault
  • Community access
Join waitlist
Lifetime
$299once
First 200 hunters only.
  • Everything in Pro
  • Lifetime updates
  • Founding-member badge
  • Direct line to the team
  • Vote on roadmap
Reserve a slot

Get the launch invite first.

Beta opens to waitlist members ahead of public launch. Lifetime slots are first-come from this list.

No spam. One launch email, then you decide. Unsubscribe in one click.