@simonzerafa it feels like a use case for Open Source that is clearly not well covered. We're going back to Hackerone. It's not a perfect fit either especially since we dropped the bounty part - but it still crosses off many more check-boxes for us.
I'll elaborate with some more details in a pending blog post