HACKR.GG
// For teams, classes & cohorts

Train your whole team to break the code they ship.

85 hands-on penetration testing modules, each ending in a vulnerable app your people exploit themselves — in the browser, with nothing to install. Buy a pool of seats, share one link, and see exactly who has learned what.

See seat pricing →Talk to us about a rollout
No VMs, no VPN, no install Members join themselves Seats are reusable Invoicing at 25+ seats
// Who it’s for

Four groups get most of the value.

Different problems, one fix: put the person in front of the vulnerability and let them break it.

Engineering teams
Product and platform developers who ship the code an attacker will meet.
The problem
The pen-test report comes back with the same three bug classes every year. Annual slide-deck training changes nothing, because nobody has ever seen the bug fire.
The focus
Injection, access control, authentication and the rest of the OWASP Top 10 — exploited in an app that looks like the one they maintain.
What changes
Developers who catch a vulnerable pattern in code review, because they have exploited it themselves.
Security & AppSec teams
The people triaging findings, running assessments and answering "is this actually exploitable?".
The problem
Scanner output arrives faster than anyone can validate it, and junior analysts escalate everything because they cannot separate a real finding from noise.
The focus
Hands-on exploitation across the full module library, plus recon, methodology and reporting — the whole assessment loop.
What changes
Analysts who prove or disprove a finding themselves instead of forwarding it up.
Universities & colleges
Lecturers running a security module for a cohort of 20 to 500 students.
The problem
Lab infrastructure becomes the whole job. VMs break, VPNs fail on campus wifi, and half of week one goes on setup instead of security.
The focus
A ready-made, sequenced curriculum with a lab in every lesson — nothing to host, nothing to install, nothing for campus IT to approve.
What changes
You spend class time teaching, not setting up labs — and a dashboard shows exactly which student finished which module, so you are not chasing screenshots to grade.
Bootcamps & training providers
Course providers who need a security module their students and hiring employers will take seriously.
The problem
Buying a lab platform per cohort is expensive, and seats bought for last term sit idle this term.
The focus
A rotating seat pool — free a seat when one group of students finishes and give it to the next group.
What changes
You pay for the students learning right now, not for everyone who ever signed up — one bill that follows your real class size.
// How it works

Five steps, and four of them run themselves.

Rollout is a link. Nothing else lands on your plate.

01
Buy a pool of seats
Pick the size (minimum 5) and the billing period. Card checkout is instant; 25+ seats can pay by invoice on net terms.
02
Share one link
Your organisation gets a private invite link and code. Send it to the team or drop it in the course syllabus — that is the entire rollout.
03
People join themselves
Each person signs up with their own account and claims a seat. No accounts to create, no passwords to distribute, no approval queue.
04
Watch the progress
Your dashboard lists every member module by module: what they cleared, where they stalled, and who has taken the certification.
05
Reassign as people move
Someone leaves, or a cohort graduates? Free the seat and give it to the next person. Their account and history stay with them.
// The benefit

What you actually get out of it.

Skills that transfer, evidence you can report on, and no administration.

Zero infrastructure
The vulnerable applications run inside the learner’s browser tab. Nothing to host, no VPN, no VM image to maintain, nothing for IT to sign off.
Nothing to administer
Joining is entirely self-serve, and seats are freed or reassigned in two clicks. There is no ticket queue between buying and learning.
Progress you can report on
Per-person, per-module completion — the evidence an audit, a board slide or a course grade needs, without chasing anyone for screenshots.
Learning that transfers
Every module ends with the learner exploiting the bug themselves. That is the gap between recognising a term and recognising the pattern in a pull request.
Seats that follow headcount
Add seats mid-term and you are only charged for the extra days. Free a seat when someone leaves and reuse it — you pay for who is learning now, not everyone who ever signed up.
A credential at the end
Learners can sit the HJPT certification, and you can buy it for them at the student rate straight from your dashboard.
// Pricing

Per seat, per period. That’s the whole model.

No platform fee, no onboarding fee, no per-lab charge.

Monthly
$6.99/seat/mo
Quarterly
$17.41/seat/qtr
Yearly
$67.10/seat/yr

Minimum 5 seats · seats are reusable · 25+ seats can pay by invoice on net terms.

// Questions

The things buyers ask first.

How many seats do we need?
Buy one seat for each person learning at the same time — the minimum is 5. A seat is not tied to one person forever: when someone finishes or leaves, free their seat and hand it to the next person.
Do our people need their own accounts?
Yes, and that is deliberate. Each learner keeps their own account, progress, XP and leaderboard position. If they leave your organisation the account stays theirs — you only reclaim the seat.
What do we have to install?
Nothing. The vulnerable applications are rendered and exploited inside the browser. There is no VM, no VPN, no agent, and no traffic to a lab network for IT to review.
Can we pay by invoice or purchase order?
Yes. At 25 seats or more you can choose pay-by-invoice at checkout — we email a hosted invoice on net terms and your seats activate immediately.
Can we see how people are doing?
Your organisation dashboard lists every member with the number of tasks completed, broken down per course, plus whether they have taken the certification.
What happens if we cancel?
Seats stop and everyone drops back to a free account. Nobody loses their account or the progress they made — it is simply no longer covered by your subscription.
// Next step

Put your team in front of the vulnerability.

Start with a small pool of seats and grow it as people join. Adding seats, freeing them and buying certifications are all self-serve from your dashboard.

Get seats →Browse the 85 modules