Hi all, I’m Chris, the co-founder and CTO of Bugcrowd. We started Bugcrowd to harness a crowd of world-class security researchers that find flaws in your code - before the bad guys do. Today we’re launching ‘Bugcrowd for Enterprise’, a bunch of new features that are based on feedback from our customers.
We’ve learned a lot from working with some of the best companies in the world, including Pinterest, Wink, Indeed, Heroku, Simple and many others.
Here’s what’s new:
- SSO/SAML Integration (OneLogin, Okta, etc)
- Role Based Access
- Integrations with Backend Tools (JIRA, Trello, HipChat)
- Private programs with vetted researchers
We have more info on our blog, complete with a video demo of the
product: https://blog.bugcrowd.com/bugcro...
Feel free to ask me anything or share your feedback, we’re very
excited to hear from the ProductHunt community!
Hello there, my name is Q. Wade Billings, and I am the Sr. Director of Global IT Shared Services for Instructure, the only cloud native provider of Learning Management System services with over 1300 K-12 and higher education organizations as our customers.
Since we launched in 2011, we have performed annual web application security assessments using industry recognized security research firms. These reports have been published publicly on our company blog each year with a challenge to our competition to do the same.
This year, we decided to shake things up by taking a more “offensive” approach to security, because let’s face it, those who wish to do us harm are innovating at a pace that outpaces traditional “defensive” security practices.
Enter BugCrowd and its crowdsourced security researchers.
You can read all about our experience with BugCrowd here (http://blog.instructure.com/canv...).
Needless to say, we were so impressed with the results of the initial flex plan assessment, we decided to establish an ongoing private bug bounty program with them.
Bottom line for me is that BugCrowd enabled Instructure to improve the overall security and integrity of its core services without significantly increasing the OpEx or CapEx budget investment.
I call that a win/win.
Notiv