# Sharing the Philosophy Behind Shopify's Bug Bounty

DevFeed: [Sharing the Philosophy Behind Shopify's Bug Bounty](<https://devfeed.tech/articles/sharing-the-philosophy-behind-shopify-s-bug-bounty-1575.md>)

Original publisher: [Read original article](<https://shopify.engineering/sharing-the-philosophy-behind-shopifys-bug-bounty>)

Author: Jaime Woo

Published: 2017-02-16T14:26:00Z

Content type: article

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Shopify](<https://devfeed.tech/topics/shopify.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [communication](<https://devfeed.tech/tags/communication.md>), [security](<https://devfeed.tech/tags/security.md>), [shopify](<https://devfeed.tech/tags/shopify.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Shopify explains the philosophy behind its bug bounty program, which evolved from a security response program launched in 2012 to a HackerOne bug bounty in 2015. The article describes the program's results, emphasis on security and merchant trust, minimum $500 payouts, transparency, public disclosure, communication with researchers, and educational value. It begins describing vulnerabilities uncovered through the program, including an invoice-swapping issue that exposed merchant information.

## Source excerpt

2 minute read Bug bounties have become commonplace as companies realize the advantages to distributing the hunt for flaws and vulnerabilities among talented people around the world. We're no different, launching a security response program in 2012 before evolving it into a bug bounty with HackerOne in 2015. Since then, we've seen meaningful results including nearly 400 fixes from 250 researchers, to the tune of bounties totalling over half a million dollars. Security is vital for us. With the number of shops and volume of info on our platform, it's about maintaining trust with our merchants. Entrepreneurs are running their businesses and they don't want to worry about security, so anything we can do to protect them is how we measure our success. As Tobi recently mentioned on Hacker News, "We host the livelihoods of hundreds of thousands of other businesses. If we are down or compromised all of them can't make money." So, we have to ensure any issue gets addressed.