HackerOne
HackerOne is a San Francisco-based cybersecurity platform that combines a community of more than 2 million vetted security researchers with its Hai agentic AI orchestrator to deliver Continuous Threat Exposure Management for over 1,300 enterprise and government customers worldwide.
- Company typePrivate
- Founded2012
- HeadquartersSan Francisco, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What HackerOne does
HackerOne operates a global crowdsourced security platform that pairs a community of more than 2 million vetted security researchers with an agentic AI orchestration layer (Hai) to discover, validate, prioritize, and remediate exploitable vulnerabilities across enterprise and government attack surfaces. The H1 Platform hosts specialized modules — H1 Continuous Testing, H1 Code, H1 Validation, H1 Agentic Pentest, H1 Bounty, H1 AI Red Teaming, HackerOne Response, HackerOne Clear, and Code Security Audit — all wired into engineering, ITSM, cloud, and security operations tools via 36+ native integrations. Hai coordinates a set of specialized agents (Report Assistant, Deduplication, Priority Escalation, Insight, Validation) across the vulnerability lifecycle, reporting 95% exploitability-validation accuracy, 40% signal improvement, and adoption by 90% of customers.
The company serves more than 1,300 organizations, including 40% of the Fortune 50 and major U.S. federal agencies, with named customers spanning Salesforce, Anthropic, IBM, Adobe, PayPal, Uber, Shopify, Snap, Zoom, Crypto.com, and the Department of Defense. Revenue is generated through enterprise subscriptions to the H1 Platform, transaction-based commissions on bug-bounty payouts (customers pay only for validated findings; HackerOne took a commission on $81M of researcher payouts in 2025), engagement-based pricing for pentests and AI red teaming, federal contracts via FedRAMP-authorized offerings (GSA Schedule GS-35F-0511T, NASA SEWP V), and marketplace sales through AWS and Carahsoft.
The business is sold primarily through direct enterprise field sales augmented by a PartnerOne channel program spanning North America, EMEA, APAC, and LATAM, with a self-serve path for vulnerability disclosure and bug-bounty programs. Hack the Pentagon (2016) established the federal franchise, while 2024–2026 brought a CEO transition to Kara Sprague, CRO and CMO appointments, the H1 Platform relaunch around Hai, the H1 Agentic Pentest and H1 Validation launches, and strategic alliances with OpenAI, Wiz, Armis, AWS, IBM, and Anthropic that reframe HackerOne as the security substrate for both enterprise software and frontier AI deployments.
HackerOne firmographics
Firmographics- Name
- HackerOne
- Legal name
- HackerOne
- Website
- https://hackerone.com
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- HackerOne is a San Francisco-based cybersecurity platform that combines a community of more than 2 million vetted security researchers with its Hai agentic AI orchestrator to deliver Continuous Threat Exposure Management for over 1,300 enterprise and government customers worldwide.
- Ownership category
- akta.pro rank
HackerOne industry classification
Industry- Product category
- Vulnerability Management & Continuous Threat Exposure Management (CTEM) Platform
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Deception Technology & Threat Hunting (HDADAGAI)
- akta.pro secondary industries
- Email & Collaboration Threat Detection/Response (ICR/CTDR) (HDADAKAI), Identity Threat Detection & Response (ITDR) (HDAEAJAH), Access Security & Identity Threat Detection (ITDR, UEBA for Identity) (HDADAAAI), Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where HackerOne is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
HackerOne business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- H1 Platform Subscription: SaaS subscription for the H1 Platform (Hai, H1 Continuous Testing, H1 Validation, H1 Code) with recurring annual contracts for enterprise customers. Self-serve Return on Mitigation (RoM) is included as a built-in capability.
- Bug Bounty Rewards & Commissions: Customer pays only for confirmed, validated vulnerability reports submitted by the researcher community. HackerOne takes a percentage/commission of each bounty payout, with global payments infrastructure handling researcher compensation.
- Pentest as a Service (PTaaS): Time-bound or continuous pentest engagements billed as managed services combining AI-driven and human pentester resources. Pricing based on scope and engagement duration.
- AI Red Teaming Engagements: Fixed-scope 15 or 30-day adversarial testing engagements for AI systems, priced per engagement with bundled Solutions Architect support, mapped to compliance frameworks (OWASP, NIST AI RMF, EU AI Act).
- Federal & Government Contracts: Government contracts via GSA, NASA SEWP, and Carahsoft with FedRAMP-authorized platform offerings, including VDP, bug bounty, and pentest services for federal agencies.
- AWS Marketplace Channel: HackerOne offerings (Pentest, Bounty, Response) listed on AWS Marketplace, enabling cloud-native customers to consume services via existing AWS procurement and billing relationships.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Outcome Based/ Performance | Multi-year contract | Bug Bounty: Pay-for-performance pricing with global bounty pool managed by HackerOne |
| Other | Annual | H1 Agentic Pentest / PTaaS: Engagement-based pricing |
| Other | Multi-year contract | H1 AI Red Teaming: Fixed-scope engagement (15 or 30 days) |
| Subscription | Annual | H1 Platform (Continuous Testing, Validation, Code): Enterprise subscription |
| Other | Multi-year contract | Federal contracts via Carahsoft/GSA Schedule |
Go-to-market motion2 records
Distribution channels6 records
Marketing channels8 records
HackerOne product offering
Product offeringCore offering
HackerOne operates the H1 Platform, an agentic Continuous Threat Exposure Management (CTEM) platform that combines coordinated AI agents (orchestrated by Hai) with a global community of vetted human security researchers to discover, validate, prioritize, and remediate exploitable vulnerabilities across enterprise attack surfaces. The platform is sold via subscription, transaction-fee bug bounty programs, engagement-based pentest services, and federal contracts, with supporting modules for code security, AI red teaming, vulnerability disclosure, and validated exposure management.
Product overview
HackerOne delivers an agentic, platform-plus-modules architecture centered on the H1 Platform, which operationalizes Continuous Threat Exposure Management (CTEM) through a connected system of discovery, validation, prioritization, and remediation orchestrated by Hai, its agentic AI layer. The core H1 Platform hosts specialized modules—H1 Continuous Testing, H1 Code, H1 Validation, H1 Agentic Pentest (with H1 Pentest), H1 Bounty, H1 AI Red Teaming, HackerOne Response, HackerOne Challenge, and Code Security Audit—each addressable as an entry point that scales into the full platform. Hai ties them together with coordinated AI agents (Report Assistant, Deduplication, Priority Escalation, Insight, and Validation Agents), while HackerOne Clear, the PartnerOne Program, and the Technology Alliance Program extend the offering to vetted public-sector engagements and a broad integration ecosystem.
Differentiator
Problem solved
Functional benefit
Brands
- H1 Platform: HackerOne's agentic continuous threat exposure management (CTEM) platform
- Hai
- H1 Continuous Testing
- H1 Code
- H1 Validation
- H1 Pentest / H1 Agentic Pentest
- H1 Bounty
- H1 AI Red Teaming
- HackerOne Clear
- PartnerOne Program
- Technology Alliance Program
Products and services
- H1 Platform The H1 Platform is HackerOne's agentic Continuous Threat Exposure Management (CTEM) platform that continuously discovers, validates, prioritizes, and remediates exploitable risk across an organization's attack surface, orchestrated by the Hai agentic AI layer. It is sold via enterprise subscription to large organizations and government agencies.
- Hai Hai is HackerOne's agentic AI orchestrator that coordinates specialized AI agents (Report Assistant, Deduplication, Priority Escalation, Insight, Validation) across every stage of the H1 Platform to score, validate, prioritize, and route findings. Adopted by 90% of HackerOne customers.
- H1 Continuous Testing Always-on, pentest-grade continuous testing using specialized AI agents that follow Recon, Scan, Exploit, and Report workflows with proprietary exploit intelligence, providing attack steps, payloads, and proof of exploitability across the attack surface.
- H1 Code AI code security solution combining SAST/SCA, modern reasoning models, and human-in-the-loop review to detect, validate, prioritize, and remediate vulnerabilities in commits and pull requests across GitHub, GitLab, Bitbucket, and Azure DevOps.
- H1 Validation Agentic AI and human-expert service that ingests raw vulnerability findings, deduplicates and confirms exploitability at 95% accuracy with 40% signal improvement, and routes validated findings into engineering workflows such as Jira and ServiceNow.
- H1 Agentic Pentest (Pentest as a Service) Continuous agentic penetration testing service combining AI agents for reconnaissance and validation with vetted human pentesters who retain oversight, delivering evidence-backed findings across web apps, APIs, networks, cloud, mobile, and AI/LLM systems.
- H1 Bounty Bug bounty platform connecting organizations with HackerOne's global community of vetted security researchers for continuous, incentive-driven vulnerability discovery, augmented by Hai for triage and prioritization. Customers pay only for confirmed, validated reports.
- H1 AI Red Teaming Human-led, agent-driven adversarial testing service for AI models, retrieval pipelines, tools, and agent workflows, delivering framework-mapped findings (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, EU AI Act) and reproducible exploit evidence, including Agentic Prompt Injection Testing. Sold as fixed-scope 15- or 30-day engagements.
- HackerOne Response (Managed VDP) Managed Vulnerability Disclosure Program (VDP) providing a safe, compliance-friendly channel for external researchers to submit vulnerabilities, with triage, reporting, and alignment to standards such as NIST 800-53r5 and ISO/IEC 29147.
- HackerOne Challenge Time-bound, focused offensive testing engagement by elite security researchers for pre-launch validation and targeted coverage of critical assets.
- Code Security Audit Background-checked, skills-vetted engineers conduct source code reviews to identify logic flaws, insecure design patterns, hardcoded secrets, and vulnerabilities such as SSRF, XSS, and improper input validation.
- HackerOne Clear Vetted researcher program providing ID-verified, background-checked, citizenship-filtered, and security-cleared (including Top Secret / TS-SCI) researchers for federal, public sector, and sensitive testing engagements.
Quantifiable outcome
- 80% reduction in Mean Time to Remediate
- +12 more outcomes
Companies that use HackerOne
Customer profileNamed customers16 records
Segments10 records
Ideal customer profiles5 records
HackerOne technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration20 records
AI capability12 records
Feature7 records
HackerOne partnerships and signals
Strategic signalPartnerships
42 partnerships are on record.
- PullRequestHackerOne acquired PullRequest, a startup providing external code review services that helps identify bugs and security vulnerabilities in software before deployment. Deal finalized April 2022 with all PullRequest employees moving to HackerOne; purchase price not disclosed.
- AWS (Amazon Web Services)Strategic cloud marketplace partnership with HackerOne solutions available on AWS Marketplace. Includes AWS Security Hub integration for unified vulnerability findings, AWS Certified ethical hackers for cloud-specific testing, and co-marketing with AWS Startup Partnerships.
- WizIntegration bringing validated vulnerability findings from HackerOne's bug bounty, vulnerability disclosure, pentesting, and AI red teaming programs into Wiz's cloud and AI security platform (Security Graph and Attack Surface Management), enabling security teams to better prioritize exploitable issues.
- OpenAILaunch partner for OpenAI's Daybreak Cyber Partner Program and the Patch the Planet initiative co-founded with Trail of Bits. HackerOne provides security engineering, triage, and coordinated disclosure support for AI vulnerability research across major open-source projects.
- Trail of BitsCo-founded the Patch the Planet open-source supply chain initiative with OpenAI, providing security research, AI-assisted vulnerability research, and human expert review for open-source maintainers including cURL, Python, Go, Sigstore.
- CalifPartner in OpenAI's Patch the Planet initiative, providing security engineering support alongside HackerOne and Trail of Bits for AI vulnerability research and coordinated disclosure across open-source projects.
- Rockwell AutomationStrategic cybersecurity partnership to identify potential risks in Rockwell's industrial automation products, strengthening Rockwell's cybersecurity posture as highlighted in their 2025 Sustainability Report.
- CarahsoftFederal distributor for HackerOne solutions, supporting NA SLED/FED market. HackerOne available via Carahsoft as a procurement channel for government agencies and educational institutions.
- Defy SecurityAdvanced Reseller in North America supporting HackerOne sales, solutions, and support.
- GuidePoint SecurityNorth America reseller providing HackerOne application security services to enterprise customers and government solutions.
- OptivNorth America reseller supporting application security offerings including HackerOne.
- SHINorth America reseller providing HackerOne cybersecurity solutions.
- World Wide Technology (WWT)North America reseller providing HackerOne cybersecurity solutions.
- BlueFort SecurityEMEA reseller for HackerOne solutions.
- SoftwareOneEMEA reseller for HackerOne solutions.
- SoftcatEMEA reseller for HackerOne solutions.
- Integrity360EMEA reseller for HackerOne solutions.
- SIAPAPAC reseller for HackerOne solutions in Indonesia.
- UNETAPAC Reseller/Distributor for HackerOne solutions in South Korea.
- EnsignInfo SecurityAPAC reseller for HackerOne solutions.
- AK NetworksLATAM reseller for HackerOne solutions in Brazil.
- ArmisAttack surface management integration — ingest asset and exposure data from Armis into HackerOne to correlate attack surface findings with vulnerability reports for remediation prioritization. Also listed in the PartnerOne Technology Alliance Program.
- ArmorCodeBi-directional integration to ingest and correlate findings from HackerOne to the ArmorCode ASPM platform.
- AsanaBi-directional SDLC workflow integration synchronizing HackerOne reports with Asana tasks.
- Atlassian JiraBi-directional integration synchronizing HackerOne reports with Jira issues, available for Jira Cloud or Jira Server.
- Azure DevOpsBi-directional integration synchronizing HackerOne events with Azure DevOps actions, enabling development and security teams to stay aligned.
- BrinqaIntegration pushing HackerOne submissions to Brinqa for centralized vulnerability report tracking.
- GitHubDeveloper workflow integration pushing vulnerability reports into GitHub with remediation guidance for developers.
- GitLabDeveloper workflow integration pushing vulnerability reports into GitLab with remediation guidance.
- ServiceNowIT service management integration routing validated findings into ServiceNow for engineering workflows.
- SlackNotification and collaboration integration routing HackerOne findings and updates into Slack channels.
- TenablePartnerOne Technology Alliance Program member; integration with Tenable vulnerability management platform.
- CycodePartnerOne Technology Alliance Program member with integration for software supply chain security.
- is*hostingis*hosting launched a Public Vulnerability Disclosure Program with HackerOne in January 2025 to enhance security posture.
- AgodaAgoda launched a public bug bounty program on HackerOne's platform in 2026, offering rewards up to $6,000 for vulnerabilities across Agoda.com, mobile app, and core web services/APIs. Built on a private bug bounty program begun in 2016.
- AnthropicAnthropic partnered with HackerOne for full-stack AI red teaming of Claude, working together on the Jailbreak Challenge and AI Red Teaming initiatives. Anthropic CISO Jason Clinton chose HackerOne for full-deployment testing aligned with ISO 42001.
- IBMHackerOne works directly with IBM on foundational models including Granite, providing AI Red Teaming and adversarial testing.
- CantinaCollaboration integration with Cantina platform for Web3 security.
- ClickUpSDLC workflow integration syncing HackerOne reports with ClickUp tasks.
- CortexIntegration to streamline triage and remediation.
- AWS Security HubSecurity workflow integration reducing manual processes for AWS vulnerability findings from HackerOne.
- Marten Mickos (former CEO)Leadership succession: Kara Sprague succeeded Marten Mickos as CEO in September 2024, marking a transition in HackerOne's leadership to drive enterprise growth and AI security strategy.
Scale indicators17 records
Recent moves6 records
Expansion highlights8 records
HackerOne competitors and assessment
Company assessmentBroad incumbents
- Snyk: Broad incumbent in developer security (SAST/SCA/IaC) that competes with H1 Code in the code-security module. Larger platform footprint and developer-first distribution give Snyk a wider SDLC footprint than HackerOne's code module alone.
- CrowdStrike: Endpoint and broader platform-security incumbent that is increasingly bundling exposure validation and AI-security capabilities. Represents the largest competitive threat in terms of platform consolidation pushing customers off standalone CTEM tools.
- Veracode: Established incumbent in application security testing (SAST, DAST, SCA) competing with H1 Code. Targets the same regulated-enterprise buyer and was named alongside HackerOne in GB Hackers' 2026 secure code review ranking.
- Tenable: Broad vulnerability management and exposure management incumbent that overlaps with HackerOne's CTEM and validation capabilities. Both are PartnerOne Technology Alliance Program members, and Tenable's Nessus-based stack competes for the same CISO budget.
Direct peers
- Cobalt: Direct competitor in Pentest-as-a-Service (PTaaS). Overlaps with HackerOne's H1 Agentic Pentest offering on talent-based pentesting delivered as an on-demand service to enterprise software teams.
- Synack: Direct competitor in crowdsourced security and penetration testing with a vetted (rather than open) researcher model. Competes head-to-head on federal and enterprise PTaaS, and was named alongside HackerOne and Bugcrowd in Omdia's bug-bounty platform leader analysis.
- Bugcrowd: Closest direct competitor to HackerOne in crowdsourced bug bounty and vulnerability disclosure. Omdia groups Bugcrowd and HackerOne as the two dominant standalone bug-bounty platforms; overlap on enterprise customers, researcher community, and PTaaS offerings.
Emerging players
- Pentera: Automated security validation / agentic pentesting vendor that increasingly overlaps with HackerOne's H1 Continuous Testing and H1 Validation modules. Differentiates on fully automated, software-only red-teaming rather than human-in-the-loop.
- Wiz: Cloud and AI security platform that is both a distribution partner (HackerOne findings flow into Wiz Security Graph) and a rising platform competitor. Wiz's rapid enterprise penetration makes it the most strategically important peer despite a different primary product.
- Detectify: Crowdsourced attack-surface and continuous vulnerability testing vendor with partial overlap to HackerOne's CTEM offering. Smaller community and scope than HackerOne but a comparable 'human + automation' crowdsourced model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat8 records
Key risks5 records
Key highlights6 records
Customer concentration
HackerOne social profiles
Digital presenceHackerOne compliance and trust
Trust signalCompliance10 records
HackerOne financial estimates
Financial estimateRevenue estimate
Valuation estimate
HackerOne leadership team
Management profileNumber of profiles
Profiles11 records
HackerOne subsidiaries and ownership
Company hierarchySubsidiaries1 record
HackerOne funding detail
Funding detailFunding overview
Funding rounds6 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
HackerOne M&A and investment
M&A and investmentM&A2 records
Investments1 record
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about HackerOne
What does HackerOne do?
HackerOne operates the H1 Platform, an agentic Continuous Threat Exposure Management (CTEM) platform that combines coordinated AI agents (orchestrated by Hai) with a global community of vetted human security researchers to discover, validate, prioritize, and remediate exploitable vulnerabilities across enterprise attack surfaces. The platform is sold via subscription, transaction-fee bug bounty programs, engagement-based pentest services, and federal contracts, with supporting modules for code security, AI red teaming, vulnerability disclosure, and validated exposure management.
Is HackerOne a public or private company?
HackerOne is a private company. It is classified as venture growth investor backed and is currently operating.
When was HackerOne founded?
HackerOne was founded in 2012. It employs 251 to 500 people.
Where is HackerOne based?
HackerOne is headquartered in San Francisco, United States, in the North America region.
How does HackerOne make money?
Six revenue lines are on record. H1 Platform Subscription is the primary driver. The others are bug Bounty Rewards & Commissions, pentest as a Service (PTaaS), AI Red Teaming Engagements, federal & Government Contracts and AWS Marketplace Channel.
Who are HackerOne's main competitors?
Broad incumbents on record are Snyk, CrowdStrike, Veracode and Tenable. Direct peers are Cobalt, Synack and Bugcrowd. Emerging players are Pentera, Wiz and Detectify.
Does HackerOne have an API?
Yes. HackerOne offers a public REST API (api.hackerone.com) and webhooks for custom integrations and workflow automation. The API enables developers to integrate with internal tools, automate vulnerability workflows, build bidirectional connections with developer, security, and IT tools (e.g., Jira, Slack, ServiceNow, GitHub, GitLab), and supports 30+ native integrations across SDLC, ITSM, communication, and security platforms. Authentication is documented at docs.hackerone.com; rate limits and sandbox availability not specified in source. Developer documentation is at api.hackerone.com.
What industry is HackerOne in?
HackerOne's product category is Vulnerability Management & Continuous Threat Exposure Management (CTEM) Platform. Its primary akta.pro industry code is HDADAGAI, Deception Technology & Threat Hunting, with a secondary code of HDADAKAI, Email & Collaboration Threat Detection/Response (ICR/CTDR). Its NAICS code is 561621 and its SIC code is 7370.