We take the security research community seriously and appreciate the valuable time spent participating in Bugcrowd engagements. As each submission is thoroughly reviewed, we maintain our commitment to set hackers up for success as reports move through the review process. This entails understanding the submission review process, respecting bounty guidelines, and effectively communicating with engagement owners and the Bugcrowd Application Security Engineering (ASE) team.
Our standard is that submissions are typically triaged within 7 business days on Bugcrowd-managed engagements. Depending on complexity, this process may take less time. As a hacker, you can help minimize processing time by providing clear, concise and informative reports. Check out our Submission Templates as an option to aid in writing the most actionable reports possible.
In the event that this process is taking longer than expected and to avoid a breakdown in communication, we encourage hackers to take the following actions:
When communicating with the Bugcrowd ASE team, or with engagement owners, always remember to put your best foot forward and interact with respect. Please do not repeatedly message on a daily/every other day cadence. This takes away valuable time on the triage side from replicating and validating submissions.
From the ‘triaged’ state, we encourage our engagement owners to move the submission to a finalized status (Unresolved/Resolved/Not Applicable/Duplicate) within 14 days.
Again, in the event that this does not occur as expected, take the following action:
Occasionally, you may disagree with how a report has been classified. The following escalation path will keep your interactions professional and headed towards a positive resolution. If a submission is marked as ‘Not Applicable:’
Throughout the submission review, triage and closing processes, we expect hackers to adhere to best practices, avoiding these unproductive communication behaviors:
In general, it’s important to remember that there is a human on the other side of the keyboard, and for a variety of reasons, all communications should be handled reasonably and respectfully.
We are always available through our designated support channels to facilitate fair and respectful mediation and communication. If you have any further questions, don’t hesitate to reach out to [email protected].