I'm consulting with a small, bootstrapped company, and a security researcher responsibly disclosed an extremely serious issue that leaked root database credentials. Based on the vulnerability, I doubt this researcher spent a ton of time discovering the exploit, but the value to the company is (obviously) tremendous.
I want to formally recommend a reward amount, but I know the company doesn't have much free cash. There is no bug bounty program in place. How do you go about thinking through pricing, especially for a non-BigCo? Thanks!