The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring.
A formalized bug bounty program would enable the software producer to have secure software.
Why exactly is HackerOne drawing a distinction with this software producer? I read the whole article and still miss what the controversy with this producer is.
Is all monitoring software now banned from HackerOne under the guise of a moral high ground HackerOne just created?