Grab Celebrates 5 Years on HackerOne
ID: ccd93a0f-8a45-5e0a-a764-45e08ab86b80
STIX ID: report--ccd93a0f-8a45-5e0a-a764-45e08ab86b80
Feed Name: HackerOne Blog
Grab’s security team describes the evolution of their bug bounty program—from a private initiative to a public HackerOne program—highlighting operational lessons: fast first-response times, paying full bounties after triage (average time-to-bounty of 5 days), using HackerOne Triage and Human‑Augmented Signal to reduce noise, and instituting team scheduling with API/PagerDuty integrations. The program engaged over 200 researchers, resolved ~450 valid vulnerabilities, and improved security by integrating bug bounty findings into development workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
