# Reflecting on the Five Years of Bug Bounty at Grab

[Grab](https://yomu.fyi/company/grab) · Ajay Srivastava · Dec 16, 2020

**Type:** Explainer

## Summary

Grab launched a private bug bounty programme on HackerOne before opening it publicly in 2017 to complement internal product security efforts. Prior to going public, the team conducted security sweeps, established policies, and expanded the testing scope to prepare for an influx of reports. Operationally, the team opted to pay full bounties immediately upon report triage rather than waiting for vulnerability resolution to incentivize security researchers. Noise reduction was handled using HackerOne Triage, Human-Augmented Signal, and by blocking automated scanning networks targeting Grab's infrastructure. In addition, rotating security engineers weekly and integrating HackerOne APIs with PagerDuty ensured fast initial response times.

## Context

Grab needed to supplement its internal product security efforts and safeguard consumer data across infrastructure and mobile applications without overwhelming its security engineers with report volume.

## Approach / What changed

Grab tested and refined policies via a private bug bounty on HackerOne, expanded to a public programme, joined Google Play Security Reward Programme, automated triage workflows with PagerDuty, and paid full bounties immediately after triage.

## Takeaways

- Grab pays the full bounty payout immediately after a report is triaged rather than waiting for vulnerability remediation.
- A dedicated security engineer is assigned each week during sprint planning to focus exclusively on reviewing and responding to bug bounty reports via PagerDuty and HackerOne API alerts.
- Mobile app testing engagement faced obstacles including anti-fraud account blocks, manual verification gates for driver accounts, and geographical restrictions for researchers outside Southeast Asia.

**Tags:** [Android](https://yomu.fyi/topic/android), [Testing](https://yomu.fyi/topic/testing)

[Read original post](https://engineering.grab.com/reflecting-on-the-five-years-of-bug-bounty-at-grab)
