I've spent a significant amount of time testing Personio and interacting with their security team through responsible disclosure. Overall, the experience has been positive. The security team is professional, communicates clearly, and is willing to discuss technical details rather than relying on generic responses. Reports are reviewed carefully, and when a finding is considered out of scope or not applicable, they generally explain their reasoning instead of sending a canned rejection.
NR
Unrated
Personio Bug Bounty
2 more reviews needed for a grade
Reported practices
+
Bounties above market
1 report
+
Fair on duplicates
1 report
+
Offers retests
1 report
+
Clear, honest scope
1 report
+
Fast payout
1 report
+
Clear, current policy
1 report
+
Fast to fix
1 report
+
Responsive communication
1 report
−
Slow to first response
1 report
Found a vulnerability?
Personio has not claimed a profile here. If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf — with your explicit permission — and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
1 publishedProfessional, Transparent, and Responsive.
★★★★★
positive
via Intigriti
1st reply 1–3 months
resubmit yes
recommends yes
skill Intermediate
+ Bounties above market
+ Clear, current policy
+ Clear, honest scope
+ Fair on duplicates
+ Fast to fix
+ Fast payout
+ Offers retests
+ Responsive communication
− Slow to first response
Log in to comment