I've spent a significant amount of time testing Personio and interacting with their security team through responsible disclosure. Overall, the experience has been positive. The security team is professional, communicates clearly, and is willing to discuss technical details rather than relying on generic responses. Reports are reviewed carefully, and when a finding is considered out of scope or not applicable, they generally explain their reasoning instead of sending a canned rejection.
Researcher profile
Not enough independently verifiable evidence yet. This is not a low score, it is no score.
What you’ve added here: reviews written, and how useful others found them.
How this BugScore is built
BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. You’re Unrated because nothing costly-to-fake is linked yet. Not a low score, just nothing to grade. Private and pseudonymous work counts: link a platform, claim a credit, or submit evidence.
How this Contribution is built
Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.