HackerOne raises $40M in their C-round of funding
hackerone.com
hackerone.com
Working with h1 is great because they can help you avoid running a program that creates problems during your launch, manage submissions, handle international payouts, etc. Cant say enough positive things about these folks.
I've personally learned a ton from working on bug bounties through HackerOne and am unbelievably excited to see them continue to grow.
The company remained on HackerOne and continued to promise bug bounties (and occasionally even paid some). Meanwhile, since the company hadn't responded to my report, I was not even able to disclose it within the platform.
I wrote it off as a learning experience and concluded that HackerOne was clearly focused on getting companies on board while not really caring about hackers. Business-wise, it's probably a clever practice (because getting companies on board is hard while finding hackers is easy), but I certainly am not very excited about them...
Edit: Said company is still on HackerOne, still offering their bug bounty, with links in the description now pointing to 404s since they changed their product line in the meantime. QED.
Support simply told me to self-close the report because the company seemed inactive, without removing the company from their web site.
I get that they can't force them to pay or triage all issues, but the very least they could do would be letting researchers publish reports if ignored for over 90 days, and remove companies that are inactive. However, HackerOne wants to be able to show off a huge customer list, so they keep them on board, and what the companies want is king, so they don't allow disclosure unless the company allows it. (They also mix bug bounties managed by them with other bug bounties, to make it seem like they have more customers than they really do.)
Good luck with everything!
At my last startup a H1 researcher picked up a few critical flaws. The whole process was incredibly easy to work through. One tip for anyone trying out the service: be prompt when working with researchers. If they find some legitimate bug, pay them the bounty they deserve, and stay in constant contact.
One of the issues I've run across is that virtually all the reports I'm getting are copypasta'd from from other H1 reports by people with marginal communications skills. Couple that with the way researchers are encouraged to find ways to report the same issue multiple times and the way some seem to expect $1k payouts for noting that a WP site doesn't use HSTS, and it becomes difficult to justify the time investment.
:(