# Come and #hackallthethings at Grab

[Grab](https://yomu.fyi/company/grab) · Grab Engineering · Jul 11, 2017

**Type:** Announcement

## Summary

Grab has officially launched a public bug bounty program in partnership with HackerOne to strengthen the security of its platform. This rollout follows a private bounty initiative operated over the previous year, during which the organization worked with over 350 security researchers and resolved nearly 200 awarded bug reports. The new public program invites external researchers to scrutinize Grab's code for critical flaws, including remote code execution, SQL injections, and exportable cross-site scripting vulnerabilities. To support ethical and responsible disclosure, Grab offers payouts reaching up to $10,000 per valid vulnerability report based on severity and impact.

## Context

Grab seeks to ensure that the data of millions of driving partners and consumers remains secure and to protect users through transparent, ethical security practices.

## Approach / What changed

Grab launched an official public bug bounty program in partnership with HackerOne, offering monetary rewards for identified and responsibly disclosed vulnerabilities.

## Takeaways

- Grab ran a private bug bounty program for one year, working with more than 350 researchers and awarding nearly 200 bug reports.
- The public bug bounty program invites researchers to identify high-impact issues including remote code execution, SQL injections, and exportable XSS vulnerabilities.
- Valid bug reports submitted through HackerOne are eligible for rewards of up to $10,000 depending on impact and severity.

**Tags:** [Privacy](https://yomu.fyi/topic/privacy), [Reliability](https://yomu.fyi/topic/reliability), [Testing](https://yomu.fyi/topic/testing)

[Read original post](https://engineering.grab.com/come-and-hackallthethings-at-grab)
