
Your surface
Against your product
We run against your APIs, agents, and models — not a generic CTF box.

Stress-test your AI stack
Put your product in front of builders who will try to break it, hire from the ones who succeed, and train your models and agents on what they find.
Pick your seat — company, builder, campus, expert, or partner.

Hackathons, CTFs, bug bounties, and the events around them — one product scoped to cyber resilience, talent, and model training. Open Source Track is one program inside this umbrella.
Your product, APIs, and agents as the brief. Teams ship exploits, patches, and evals — production mechanisms, not pitch decks.
A scoped capture-the-flag against your threat model. The scoreboard is a resilience report your board can read.
Rules, triage, payouts, disclosure. Continuous pressure on the same surface the hackathon and CTF already mapped.
Breakfasts and a closed debrief. The CISO/CTO room meets the operators. Hiring happens while findings are warm.
Your stack is how the world actually runs — models, agents, deps, infra. A tabletop is not a test. Scorton Hack is: live attackers, live bounties, live training signal for the models and agents you ship.
Request a scoping call
Run by Scorton
Paris · San Francisco
Scorton designs, audits, and secures hybrid AI infrastructures. We deploy agents and skills with control over data, models, and dependencies — then measure operational and financial impact.
Scorton Hack is how that assurance shows up live: we design the challenge, run the room, and hand you evidence — findings, hires, and eval sets. Co-founded by Bacely YoroBi and Dr Florent Pasquier. Paris · San Francisco.
« There is only one thing stronger than all the armies of the world: and that is an idea whose time has come. »

Your surface
We run against your APIs, agents, and models — not a generic CTF box.

Operator bases
One operator network. You pick the city; Scorton runs the format.

Along the way
Breakfast, soirée, and briefings are where CISOs hire and CROs debrief.
One challenge, four results. Scorton Hack is useful to builders, visible to risk leaders, and scoped to the stack you ship.
Real attempts on your threat model, with a report you can take upstairs.
Hire from the scoreboard, not a résumé pile.
Traces, write-ups, and patches become training signal for models and agents.
Verified work produced by the challenge — the moat, not the event itself.
Find
Before production, or before the next customer security review.
Find
The person who won the CTF is already trained on your stack.
Find
Bounty + hackathon output becomes the next red-team and the next fine-tune.
Before
Threat-model alignment, rules of engagement, prize and bounty table.
Asset pack, brief sign-off, and operator invite list.
Onsite
Hackathon, CTF, and live events. Scorton runs ops; your team watches the board.
After
Triage, bounty continuity, talent intros, and training-set handoff.
Outcome-named packs — not medal tiers. Co-design the surface under attack. Private enterprise challenges from $10K.
Full Track
Full loop: hackathon, CTF, bounty, both events, and evidence pack.
Campaign
CTF and bounty with one operator event and a focused debrief.
Challenge
One format — CTF or hackathon — plus a scoping briefing.
| Workstream | Proposed role | Working delivery | Success signal |
|---|---|---|---|
| Hackathon | Challenge owner | Brief + judging | Artifacts / hires |
| CTF | Threat-model owner | Flags + scoreboard | Findings |
| Bug bounty | Program owner | Triage + payouts | Closed vulns |
| Breakfast | Operator host | Day-2 gathering | Conversations |
| Soirée | Closed room | Invite-only debrief | Intros |
| Content | Evidence pack | Recap + evals | Assets |
A morning gathering for CISOs, CTOs, Chiefs of Risk, and the people who just scored on your CTF. Coffee, demos, and hiring conversations while findings are still warm — not a generic networking slot.


A private, invitation-only evening for findings, talent intros, and next bounty scope. Founders, CISOs, CTOs, and operators — curated conversations beyond the scoreboard. Attendance is limited and reserved for approved guests.
your CISO or CRO owns the threat model before day one.
hackathon, CTF, and bug bounty — alone or as one campaign.
Scorton fills it; you own the brief and the follow-up.
Hackathons, CTFs, bug bounties, and the events along the way — scoped for teams that need resilience, talent, and training signal.