With SevHunt's Internal Bug Bounty platform your coworkers act as security researchers, reporting security issues for points that can be exchanged for exclusive rewards. Trust us, your employees know about some wild stuff - SevHunt gives them a place to speak up, collaborate, and become honorary members of your security team.
No reviews yetBe the first to leave a review for SevHunt
Maker
📌
I created SevHunt after realizing there was no clear path to launching an Internal Bug Bounty program at my company. Lots of people blogged about the concept, but never revealed how much leg work it takes to get something up and running. Security teams should focus on making their program successful, not making it work - SevHunt is my attempt to offer everything teams need to get their coworkers excited about finding security bugs.
Report
Curious how you handle the point system when reports turn out to be duplicates or non-issues, do those still count toward rewards or is there some kind of review gate first?
Report
Maker
@nurettinaybcmd Similar to an external program, it's up to the triage (security) team! They can choose to just close issues without a point reward or give a small amount for the effort. In an external program your payouts aren't reversible, which is why I went with this behavior - however I want to add an "accounting" page where you can arbitrarily (with good intention) correct employee point balances.
Curious how you handle the point system when reports turn out to be duplicates or non-issues, do those still count toward rewards or is there some kind of review gate first?
@nurettinaybcmd Similar to an external program, it's up to the triage (security) team! They can choose to just close issues without a point reward or give a small amount for the effort. In an external program your payouts aren't reversible, which is why I went with this behavior - however I want to add an "accounting" page where you can arbitrarily (with good intention) correct employee point balances.