Engagements are staffed with a team of security researchers led by a technical lead, not a single reviewer — a median of four people, with 86% of engagements running three or more. Auditors are full-time employees, not contractors or an anonymous crowd — the people who built the reputation are the people who do the work.
Every engagement runs as an internal contest. In the blind phase each auditor works alone and commits hashes of their findings before anyone compares notes, which removes groupthink; a prize pool paid per bug keeps the whole team hunting to the last day.
Team size for every published engagement is on each customer page, and in the open dataset.
Request an audit, or get in touch about joining the team.