I head infosec for a “Series A - C” B2B company and a fairly standard request from a potential customer is to see not only our own penetration test reports but third party penetration test results, as well. As a result, we run automated pen tests on weekends and before major releases. We also work with an application security firm every 6-12 months. For what it’s worth, we don’t do anything nearly as intense as defense contracting or handling financial info.
That said, I liked the article - thanks for sharing.
This article was written in September 2013, just a few days before AutoRef - the company the author was working for at the time - announced they were shutting down [1]. Does anybody know if development continued on the project?
I would guess it is precisely because BugCrowd is more expensive. They offer a managed program where BugCrowd's employees validate bug reports for participating companies. Speaking from experience, that process can become very time-consuming.
I'm responsible for information security at one of the other startups listed on BugSheet. As a heads-up, you're going to want to ask bugcrowd.com to remove your company from their list [1], also. We saw a pretty steep increase in the number of daily reports when first listed (4-5/day to >30/day) and it appears someone recently added your company to their site.
I'll also echo what droopybuns stated - creating templates that can address preliminary communication (duplicates, request more info, accept, etc.) will greatly reduce the amount of time you feel as though you are wasting. Some people I know tend to ignore the crazy ones but I generally prefer the "kill them with kindness" approach. One email explaining that you do appreciate the time they spent trying to help secure your site can do a lot to prevent harassment and potential bad press.
Best of luck - responsible disclosure programs are never fun for the person sifting through the reports but once in a while they do expose actual vulnerabilities and on those days, I'm happy we do it.
That said, I liked the article - thanks for sharing.