> My guess would be, that MSRC and Apple's equivalent have an OKR about keeping bounties under a certain level. Security is seen as a cost centre by most companies, and what do "well run" companies do with cost centres... they minimize them :)
It would have to be this.
If you start to increase the payout, you get more people wanting the payout.
It would have to be this.
If you start to increase the payout, you get more people wanting the payout.