Comment by imroot
1 year ago
I run a bug bounty program and I pay upon successful triage: while our engineering teams do have security SLA’s, it’s not fair to whomever reported the vulnerability to wait for our (sometimes broken) processes in order to be paid.
No comments yet
Contribute on Hacker News ↗