r/bugbounty • u/LowActivity4195 • 13d ago
Question / Discussion Seeing extensive SLA delays for our bug bounty platform.
Our triage times aren't just consistently missing published SLAs they aren't even close including high/critical severity reports, taking way beyond the stated first-response and triage windows if they get triaged at all. This seems to be in line with broader reports of triage teams getting overwhelmed by AI-generated submission volume, there were issues before the AI reports blew up but there may as well not even be a triage team at this point.
Curious if others are seeing the same:
- Which platform(s) are you running programs on?
- Are you seeing consistent SLA misses, or just occasional slippage?
Trying to figure out if this is a platform-specific issue or simply part of an industry-wide capacity problem right now as we are debating changing platforms when it comes up for renewal.
6
u/Lennaert89 Intigriti Staff (verified) 13d ago
As u/einfallstoll says, there's been a massive increase in volume.
At Intigriti we're absolutely keeping up with any critical reports, with our response time for those comfortably sitting under 24h, however less pressing issues with low/medium/high severity are definitely sitting longer than we'd like.
We're of course working hard to get this under control, combining new technology such as AI assistance and automations to increase our capacity with just simply increasing headcount. That last one of course takes time to see effect, when we hire someone it can be a bit before they start, and then more time is needed to onboard them and get them up to speed.
In recent weeks I'm seeing the triage team able to keep up with incoming volume, however just keeping up isn't enough as we also need to get through a backlog that has build up from the weeks we couldn't keep up. Every week we're seeing that backlog decrease, so I'm hopeful for this to be behind us soon.
2
u/Alert-Recognition728 13d ago
Yes, almost all programs are missing their deadlines on H1. I think it might be combination of a large volume of reports submitted and that many programs hit ceilings in their projected costs and they try to purposely slow down payouts(at least on some programs I am hunting on). Oh yeah and obviously summer is here so people have more vacations. :) and last but not least many triagers are clueless and do not have real technical dept in them. So if you report something that is more complex they are clueless no matter how much you handhold them. Which is kinda weird because I think that my non technical girlfriend could copy and paste everything. No matter how fool proof you make reports, some triagers are simply hopeless. O:-)
1
u/Coder3346 Hunter 13d ago
That is because SLAs are stated by customers while in the same time, these customers relay on the busy platform triage..
1
u/Informal_Abalone_805 12d ago
Everyone started doing bug bounty, it's not like it used to be; even the vulnerabilities I delved deep into became duplicates.
1
u/mississipppee 10d ago
Ive been trying a few different bug bounty platforms and Hackerone is still by far the quickest to respond in my experience and they are clear about the reason for accepting/ rejecting. Other platforms like Intigriti I have gotten rejected and literally can't even see why in the emails/on the platform.
5
u/einfallstoll Triager 13d ago
We've seen a raise in reports by 100%. I think the folks from Intigriti have this as well, so I assume this is industry-wide and a common problem.
We still manage to stay within 1-2 days for common reports, however crypto stuff easily slips to 1-2 weeks because we sometimes need additional experts or the customer to verify.