YesWeHack joins G-Cloud framework for UK public-sector procurement after clearing rigorous evaluation

September 8, 2026

YesWeHack JOINS G-CLOUD: UK PUBLIC SECTOR PROCUREMENT PATH

YesWeHack, the continuous offensive security and exposure management platform, has been selected for the G-Cloud 15 framework, which lets UK public sector organisations procure cloud computing services without running time-consuming tenders.

The G-Cloud marketplace of pre-vetted providers is open to government departments, the National Health Service (NHS), local councils, charities and other public sector bodies.

From Monday 7 September, YesWeHack is listed among the selected G-Cloud 15 suppliers, with public-sector buyers able to access the framework through the Contract Award Service.

‘Most comprehensive supplier evaluation to date’

YesWeHack joins G-Cloud as part of what the government describes as the “biggest upgrade” since its 2012 inception. G-Cloud’s 15th iteration has streamlined the procurement process and “features the most comprehensive supplier evaluation to date, assessing every supplier against quality, technical capability and price”, according to a government press release. “This means public sector buyers can call off services with greater assurance and without needing to conduct lengthy individual assessments.”

The government estimates that the public sector will spend £3 billion annually via the framework.

The G-Cloud 15 framework currently covers YesWeHack’s Bug Bounty and Continuous Pentest solutions. As a supplier on both G-Cloud 15 and Cyber Security Services 3, YesWeHack can offer public-sector organisations and organisations that primarily serve public-sector customers established routes to procure any of its services.

The Continuous Pentest solution is now powered by Agentic Pentest capabilities. As a result, the solution delivers on-demand penetration testing through a unique combination of human expertise and AI agents, enabling organisations to rapidly identify exploitable vulnerabilities, generate audit-ready reports, maintain end-to-end traceability, and integrate natively with their security ecosystem.

Trusted by governments worldwide

YesWeHack has considerable experience in managing Bug Bounty Programs for public-sector organisations around the world. Clients include the European Commission; France’s Ministry of the Armed Forces and Veterans Affairs, Interministerial Digital Directorate (DINUM), National Public Health Agency and National Health Insurance Fund; Singapore’s Ministry of Defence (MINDEF), Cyber Security Agency and Government Technology Agency (GovTech); Switzerland’s publicly-owned national postal service, Swiss Post; and government bodies in Germany, Catalonia, Finland and Canada.

Guillaume Vassault-Houlière, YesWeHack CEO and co-founder, comments: “We’re delighted that UK public sector organisations now have a much simpler way to access YesWeHack’s offensive security and exposure management platform.

“As experts warn of unprecedented cyber threats to critical infrastructure and vital government services, our platform delivers real-time attack-surface awareness, continuous and flexible testing, and rapid validation of the threats that matter most.”

About YesWeHack

YesWeHack is a leading continuous Offensive Security and Exposure Management platform. It provides a comprehensive suite of integrated, API-based solutions designed to secure organisations’ growing attack surfaces.

The YesWeHack platform comprises:

  • Bug Bounty: Crowdsourced vulnerability discovery leveraging a global community of 160,000+ skilled ethical hackers through a cost-efficient, platform-driven model.
  • Agentic Pentest: AI-driven campaigns that scale your testing by deploying agents to discover and validate exploitable attack paths on demand, delivering same-day, audit-ready results.
  • Exposure Management: Comprehensive asset discovery combined with ongoing exposure validation to secure your attack surface against the most exploited vulnerabilities.
  • Vulnerability Management: Unified workflows to aggregate and manage findings from external sources.

This multi-layered approach to offensive security empowers organisations to deploy agile, continuous and exhaustive testing strategies across their entire digital footprint.

All YesWeHack solutions are built with a human-in-the-loop philosophy, ensuring that critical decisions remain firmly in human hands.

Trusted by organisations worldwide, YesWeHack serves a diverse portfolio of industry leaders and public institutions, including Louis Vuitton, Ferrero, the European Commission, TeamViewer, Tencent, L’Oréal Groupe and GovTech Singapore.

YesWeHack is ISO 27001- and ISO 27017-certified and CREST-accredited. Its EU-hosted infrastructure meets ISO 27001/27017/27018/27701 and SOC 2 Type II standards, with full GDPR compliance and financial traceability built in.