Ask HN: Should an early stage startup pay for a bug bounty platform (HackerOne)?
We looked into a platform like HackerOne but were quoted 60-70K per year to run a bug bounty program. Since we're new and our profits are still small, our budget is closer to 10% of that.
What are our options for a security audit? Is this even something worth pursuing when we're still deciding whether we have product-market fit?