The Bugcrowd platform continued to evolve on our three key priorities to integrate better with your security workflows, provide security expertise on-demand, and personalize your user experience. Here’s a review of the platform capabilities that we built in 2020.
The goal of the Bugcrowd platform is to provide you the ability to seamlessly integrate the crowd for the right security use case at the right time. In order to achieve this, it is critical that the platform integrates tightly with your workflows – both within your security organization and beyond. We’ve made significant enhancements to the Bugcrowd API last year. It is better designed than the previous one, and supports versioning. You can now continue to use the version you are on, and have control on when to upgrade to a new version.
As part of the new API, the documentation site has been completely redesigned as well. Take a look here. Reach out to the support team if you have any questions and we’ll be glad to assist you in getting set up with the new API!
Jira is an integral part of many of your workflows, so we have enhanced the 2-way integration to now allow for mapping to your internal projects. Check this out in your Integrations setup page.
For customers that wish to build Bugcrowd notifications into your security workflows through communications tools such as Slack, an @customer mention by the Bugcrowd team will now route the notification to the person on call from your organization.
For customers with different needs on user session timeouts on the Bugcrowd platform, we’ve now built customizable rate limits. Depending on your compliance & security requirements, the defaults can be changed as needed.
The Bugcrowd payments infrastructure received a boost last year, to allow for various options in the payment system. There were a multitude of features built out, the most important ones being daily researcher payments, easy tax and compliance checks for OFAC, etc., support for new countries (Afghanistan, Belarus, Congo, Eritrea, Ethiopia, Iraq, Myanmar, and Zimbabwe), and ability for international researchers to maintain their payouts in USD until conversion is required.
Bugcrowd’s proprietary matching engine took a step forward with additional data sources, and better matching and recommendations.
Our platform self-service will continue to surface additional capabilities that are currently offered by our service operations team. Some notable enhancements in this area include:
Submissions now support private comments and the ability to edit them as needed. Cleaner submissions and better communication across all parties involved!
The Customer task list is a single list of to-dos that allows you to quickly prioritize the actions you need to take while on the Bugcrowd platform. With many updates to our workflow rules, and a simpler layout that shows what’s needed to be done, you will find this to streamline your work on the platform. The task list is especially useful for our customers that have scaled to multiple programs, so that you can quickly action on your blockers and submission acceptance!
These were just the highlights in the past 12 months. There are many others that you may have discovered, or have seen in action. Do reach out to us if you have any questions or would like to discuss any capability in more detail.