Customer Story

Trust on Both Sides: How Temu Secures Its Global Marketplace

By pairing a strong internal information security team with an elite global researcher community and professional triage, Temu extended continuous security coverage from consumer to seller without slowing down.

Industry
Retail & E-Commerce
Use Cases
Crowdsourced Security, Defense in Depth
Solutions
H1 Bounty, Hai, Hai Triage
Regions
Asia Pacific, Middle East, Europe, North America
Smooth gradient background transitioning from deep navy blue on the left to bright cyan and magenta on the right

Temu is one of the fastest-growing global e-commerce platforms, serving millions of consumers and a rapidly expanding seller community across markets worldwide. At that scale, security underpins everything: every purchase, seller interaction, and consumer experience depends on the platform working as intended. For Temu's security team, the question was how to ensure security keeps pace the growth of the platform. 

Challenge

Ground to Defend Expands

Temu's security program is built around a strong in-house team. The team owns the full lifecycle — system design, threat modeling, incident response — and knows how the systems work because it built them. That foundation has been independently verified — Temu's app security practices meet the Mobile Application Security Assessment (MASA) cybersecurity standard. But an internal team, however skilled, tests from the inside out. Attackers work from the outside in.

As the platform grew, so did the ground to defend. New consumer features, seller tools, product categories and markets each added systems that needed testing. 

Internal testing could cover what the team knew to look for. Independent researchers around the world, each with different methods, tools, and habits, could find what it didn’t.

The team also knew what a good program looked like: once skilled researchers would choose to join, where reports moved quickly, rewards were fair, and trust held over time. The challenge  was building the processes to deliver that consistently as the program grew. 

An in-house team is the foundation; outside researchers add ways of thinking the team can't replicate

Every new feature and market adds systems to protect, on both sides of the marketplace

Researchers only keep participating if they trust the program — trust is a requirement, not a bonus

Impact

Efficient Triage and Remediation

The industry-leading response times tell one part of the story. The more durable outcome is how the program has grown. Early on, the expectation was straightforward: researchers find issues, the team fixes them. Over time, the way researchers found those issues began to inform how Temu builds products in the first place – before anything reaches testing.

What began as a way to respond to problems now helps prevent them: security now shapes how products get built, not only how issues get fixed.

"What emerged over time was something more valuable — the findings started informing how our internal teams approach security earlier in the development process."

Temu also measures the program's health by researcher engagement. A high-quality, active researcher community is both a signal and a standard — evidence that the program operates with the consistency, fairness, and responsiveness that keeps skilled researchers coming back. That trust is the foundation the program is built on.

"Scale is only an achievement if the standards hold at scale."

 

Time-to-triage ranked among the best in the industry across all HackerOne programs

Average time-to-triage is <3 days as of June 2026.

Improved mean time-to-remediation

Resolutions timelines have improved steadily since program launch.