AdvisoryCloud & infrastructure
What our bug bounty programme actually cost us this year
Every report we received, what we paid, how long we took, and the things we got wrong. Published because a programme nobody can audit is marketing.
Write-ups from the researchers who found the bugs, guides on how they work, and advisories from the companies that fixed them. A write-up is tied to a real report, published under that program’s own disclosure policy.
Every report we received, what we paid, how long we took, and the things we got wrong. Published because a programme nobody can audit is marketing.