logo

Scaling & Prioritizing Product Security with Zendesk

ID: d3b0dfb8-988e-570c-a5ed-f9da9dc9eb03

STIX ID: report--d3b0dfb8-988e-570c-a5ed-f9da9dc9eb03

Feed Name: HackerOne Blog

Date Published: 2024-11-19

Date Updated: 2026-06-12

...
...

Zendesk's Senior Manager of Product Security outlines the company's five-year bug bounty program on HackerOne, explaining its evolution from a responsible disclosure process, methods for scaling security (the "golden path", triage services, automation), and key metrics such as SLA-driven vulnerability remediation times. The piece offers operational advice—start private, ensure vulnerability management and developer tooling—and highlights a notable SSRF report that was escalated by a researcher to remote code execution, underscoring positive researcher engagement and program value.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.