Do you have a bug bounty program for your SaaS? What are your typical rewards and practices?
I’ve been contacted by a security researcher form Asia, who found a number of vulnerabilities in my SaaS, pretty ugly ones (a hacker can delete - but not read - other users data) so I fixed those and I’m willing to pay him a reward. Not sure what the number should be. He asked for $3k but that’s too much for our small bootstrapped company, I’m trying to negotiate him down… So I’m trying to understand the typical reward scale. I understand companies like Facebook/Instagram/etc pay at a scale of “thousands”, but this number looks too big for smaller self-funded companies…
So, any thoughts/experience on this would be appreciated. Thanks!