Automated HackerOne Bounty Budget Tracking
Every Monday, WebRun opens HackerOne, reads the reports that were resolved and the bounties awarded against them, records each one in Airtable with its severity and payment status, and posts Microsoft Teams a summary of spend to date, what is still pending, and how much of the quarter's budget is left.
How do I track what my bug bounty program has paid out against budget?
WebRun opens HackerOne every Monday and reads the bounties your program has awarded, with their severity and payment status. It records each one in Airtable against your budget and posts Microsoft Teams a summary of spend to date, pending amounts, and budget left, so the budget lasts the quarter.
- Spend to date is known every Monday, not at quarter end
- Pending payouts are visible before they land
- An overspending run rate is flagged while there is time to react
Built for security program managers · application security teams · CISOs · engineering leadership
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
hackerone.comin a real browser with your saved login - no setup, no API keys. -
1
HackerOne - read awarded bounties and payment status
WebRun opens HackerOne to read awarded bounties and payment status. - Open HackerOne and go to your program's report list
- Find reports with a bounty awarded since the last run
- Capture the report reference, the severity, the bounty amount, and the payment status
- Note any resolved report where a bounty is agreed but not yet paid
Done when Every bounty awarded since the last run is captured with its amount and status.
-
2
Airtable - log spend against budget
WebRun opens Airtable to log spend against budget. - Add a record per bounty to your program budget base
- Fill in the severity, the amount, the payment status, and the date awarded
- Skip any report reference already recorded so nothing is counted twice
- Roll up the totals so the base shows spend to date and pending amounts separately
Done when The budget base holds every bounty once, with running totals up to date.
-
3
Microsoft Teams - report the budget position
WebRun opens Microsoft Teams to report the budget position. - Post a short weekly read to your security channel
- Show spend to date, amounts still pending payment, and budget remaining
- Break the spend down by severity so the mix is visible
- Flag it clearly if the run rate would exhaust the budget before the period ends
Done when The security channel has this week's budget position.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it award or pay a bounty itself?
No. WebRun reads what your team has already awarded and records it. Deciding an amount and releasing payment stay manual, so no money moves without a person approving it.
Does it read the vulnerability details?
It works from the report reference, severity, bounty amount, and payment status. The technical write-up stays in HackerOne and is not copied into Airtable or Teams.
How does it avoid double counting a bounty?
It checks the report reference against records already in the Airtable base before adding a row, so a report revisited in a later week is updated rather than duplicated.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.