Customer story

Adobe & HackerOne

A decade of ethical hacking partnership, leveraging human-powered security to enhance digital experiences for millions of customers worldwide

Image
Adobe
By the numbers

Driving results through collaboration

Since 2015, Adobe has resolved over 7,403 reports with 1,473 ethical hackers. With an average 8-hour first-response time, the company demonstrates clear commitment to rapid, responsible vulnerability disclosure.

Adobe also scaled its PSIRT team using HackerOne Triage, integrating with internal systems and enabling direct collaboration with developers through proof of concept reports and automated ticketing.

The Red Team builds on bounty findings to test internal response and detection systems, measuring real-world exploit potential.

10+
years of partnership
7,403
reports resolved
1,473
security researchers
Image
LHE Engaging

Strengthening hacker relationships

Adobe goes beyond traditional bug bounty, building community and engagement through programs like:

  • Researcher Hall of Fame: Recognizes top contributors
  • Ambassador World Cup (AWC): 32% high/critical report rate vs. 20% in standard bounty—fueled by motivated, global teams
  • Live Hacking Events: Expanded reach to new researchers and direct connections at events like the AWC in Buenos Aires
     
Image
Ethical hackers performing AI Red Teaming with HackerOne

Innovation in AI security

With a strong foundation in cybersecurity, Adobe has focused on mitigating risks associated with generative AI by fostering transparency about the capabilities and limitations of large language models (LLMs). 

By engaging with ethical hackers, Adobe enhances its security measures and addresses potential AI vulnerabilities early in the development process. To that end, Adobe’s bug bounty program includes rewards for discovering vulnerabilities in Content Credentials and Adobe Firefly. Content Credentials, built on the C2PA open standard, provide tamper-evident metadata for digital content, ensuring transparency in creation and editing processes.

Adobe’s proactive approach aims to enhance AI security, foster innovation, and promote responsible AI development.

Modernizing Pentesting

Platform Integration

Direct engagement between Adobe's product team and pentesters, fostering more immediate and meaningful interactions.

Automated Ticket Creation

Issues identified during pentests automatically generate tickets, streamlining the issue-tracking process.

Streamlined Launch

Accelerated setup and scheduling process helps with rapid deployment of pentesting services.

Elevated Vulnerability Discovery

Community-driven pentesting increases the discovery of unique vulnerabilities, strengthening Adobe's security defenses.

Hear from Adobe:

Speak with a Security Expert

Enhance your security posture

Join industry leaders like Adobe in leveraging human-powered security to protect your digital assets.