Sydney-based Bugtri uses AI to triage the flood of AI-generated vulnerability reports.
When Jacob Riggs was granted Australia’s subclass 858 National Innovation visa earlier this year, he joined a small cohort of individuals the Australian Government deems to have an internationally recognised record of exceptional achievement. The visa is invitation-only, you cannot apply unless Canberra asks you to.
Six months after landing in Sydney, the British cybersecurity professional has delivered on the program’s premise. His new company, Bugtri, launched this week – an AI-powered platform built to solve one of the security industry’s most talked-about headaches of 2026: the tidal wave of low-quality, AI-generated vulnerability reports burying security teams in slop.
“Vulnerability disclosure is entering an AI arms race”, Riggs says.
The problem is when the bug reports become the bug
The timing is hard to argue with. Generative AI has collapsed the cost of producing a plausible-looking vulnerability report to near zero, while the cost of verifying one (an analyst’s time and attention) has stayed exactly where it was. The result is an asymmetry that has been breaking disclosure programs across the industry all year.
In January, the curl open-source project made headlines by shutting down its paid bug bounty program, citing an explosion of AI-generated junk submissions. GitLab’s security team reported receiving roughly 2,500 reports in the first four months of 2026, which is more than it received in all of last year. Even Apple has felt the squeeze after capping researcher submissions to stem the flood, its portal reportedly turned away a legitimate exploit chain, which was only patched after the researchers were contacted directly.
The problem has become serious enough that the Open Source Security Foundation’s Vulnerability Disclosures Working Group launched dedicated work this year examining the impact of AI-generated reports and developing guidance for organisations trying to cope.
“We’re now in a situation where AI is amplifying the problem at scale, and the old human-only response model is fundamentally broken”, Riggs says. “Manual human triage worked when every report was written by a human who had to think about what they were submitting. Now the only way to fight the AI-generated noise is with purpose-built AI on the triage side.”
Fighting fire with fire
Bugtri’s pitch is deliberately narrow. It is not a vulnerability management suite, not a bug bounty platform, and not a scanner. It sits in one specific, painful place – between the researcher’s email and the analyst’s attention.
The platform connects to an organisation’s shared security mailbox via OAuth, with support for Google Workspace and Microsoft 365. Incoming reports are read, assessed by AI, and returned to the inbox as a structured triage summary. This includes a decision badge (Auto-Decline, Queue, Fast-Track or Urgent), a risk score out of ten, a confidence rating, an executive summary and the key factors behind the assessment, with the original report appended for context.
Setup, the company claims, takes under two minutes. “No agents, no infrastructure, no passwords stored” says Bugtri CTO Harry Coles.
For a product asking security teams to pipe their vulnerability reports through a third-party AI, the privacy architecture is doing a lot of the persuading. Before any report text reaches an AI provider, Bugtri tokenises sensitive data such as URLs, IP addresses, email addresses, and domains, replacing them with placeholders that are only restored in the final email back to the customer.
“Privacy for us was non-negotiable” Coles says. “The AI only ever sees a tokenised version of the report, and we never use customer data to train models.”
Notably, the platform is designed not to replace analysts. Duplicates are detected, non-vulnerability emails are filtered, and more crucially, when the AI’s self-assessed confidence drops below a configurable threshold, auto-decline decisions are overridden and routed to a human queue instead. Teams can also tune scoring weights and thresholds to match their own risk appetite, or override any decision with one click.
That human-in-the-loop safety net matters, because the industry’s cautionary tales cut both ways. Genuine vulnerabilities dismissed as noise have preceded multi-million-dollar losses in the DeFi world, and Apple’s submission caps show what happens when the filter itself becomes the failure point.
Built for the teams that can’t hire their way out
Bugtri is aimed squarely at small and medium organisations, namely the companies that receive vulnerability reports but don’t have a dedicated triage function to handle them. Riggs puts a number on the value proposition: “For a team receiving 80 reports a week, we’re cutting triage time from roughly 33 hours down to about 3. That’s real, measurable ROI, often paying for itself in the first month.”
Early signals suggest the pain point is real. Bugtri opened early-access applications three weeks ago and received 27 in that window, with 11 organisations are now actively using the platform.
The venture is entirely bootstrapped and self-funded. A notable choice in a security market where AI-adjacent startups have had little trouble attracting capital.
The founder
If the product feels unusually specific, that’s because Riggs has spent more than a decade on the sending end of these emails. “After responsibly disclosing vulnerabilities to thousands of organisations over the past decade and observing the friction in their processes, I’m simply reconnecting with those teams and offering the automated triage solution they now need” he says, describing his go-to-market strategy as “rather ironic”.
That track record includes a disclosure made during his visa application period itself after finding a critical vulnerability in a live Australian Government system, subsequently acknowledged by the Department of Foreign Affairs and Trade.
The Australian angle runs deeper more. Bugtri has been accepted into the Australian Signals Directorate Partner Program, and Riggs says he intends to offer the platform’s capabilities on a not-for-profit basis where they can support Australia’s cybersecurity interests.
“Australia welcomed me through the National Innovation Visa program, and I’ve tried to contribute back by creating an innovative Australian company that now aims to solve a global cybersecurity problem” Riggs says.
There is an obvious circularity to Bugtri’s premise. AI created the mess, and AI is being sold as the mop. Riggs doesn’t shy away from this, the company’s own framing is that Bugtri “uses AI to solve the very problem AI is creating.” Whether purpose-built triage AI can reliably out-filter mass-produced report-generation AI is the open question the whole industry is now wrestling with, and it’s one Bugtri’s confidence thresholds and human-review queues are explicitly designed to hedge.
For the small and medium organisations that make up Bugtri’s target market, an automated first pass may soon stop being a luxury and start being table stakes.
More information is available at bugtri.com
The Australian financial sector has a rather strong history when it comes to the rise…
Not everyone reaches success. Despite putting unending hours of effort, sweat and tears, millions of…
The Philippines offers several great qualities for those looking to outsource their telemarketing. The workforce…
David Unaipon (1872-1967) was an Indigenous Australian man who was an inventor, author and preacher.…
Australia has produced some of the most exceptional acting talents the world has seen, with…
Australia has had a plethora of successful writers and authors throughout its brief history as…