Good consolidation and frees up my time
Use Cases and Deployment Scope
We've been using HackerOne for a couple of years. It's a good collection point for bugs and discovered vulnerabilities. Having something to help screen and vet but bounty and security researchers is nice, especially with all the fake reports you can get when you publish an external bug bounty program.
Pros
- Filter for spammy bug reports
- Nice central interface
- Payment/reward system is nice
Cons
- I'd like to see a way for the end-user to set a minimum standard so those reporting are better vetted
Likelihood to Recommend
Our security team will never scale like we'd like to do having this had been extremely helpful to manage, address, and payout vulnerabilities reported. I like having one "door" for this and not multiple ways to report stuff
