PullRequest
PullRequest, now HackerOne Code, provides AI-powered code review combined with human expert validation to enterprises, startups, and government entities, integrating natively with GitHub, GitLab, Bitbucket, and Azure DevOps to surface verified vulnerabilities within developer workflows.
- Company typePrivate
- Founded2017
- HeadquartersAustin, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What PullRequest does
PullRequest, founded in 2017 and headquartered in San Francisco, operates an AI-powered code security and review platform now marketed as HackerOne Code (H1 Code) following its 2019 acquisition by HackerOne and 2024 rebrand. The core product combines proprietary AI (Hai) with a human-in-the-loop validation layer in which vetted senior engineers (99% US-based, 5+ years experience) manually review and confirm findings before they reach developers, targeting near-elimination of false positives common to fully automated SAST tools. The platform is delivered as a SaaS subscription with native integrations into all four major source code management systems (GitHub, GitLab, Bitbucket, Azure DevOps) and supports both cloud and self-hosted enterprise deployments, with adjacent offerings including Code Security Audit, Smart Review Selection, Benchmarks analytics, and the h1-hai conversational AI agent for in-PR remediation assistance.
The business sells on a quote-based subscription model to a diversified mix of enterprise and startup customers, including Audi/Silvercar, UK Government, Google, Unity, San Jose Water, TriState Capital Bank, and Alavida Health, with 21,096 reviews reported in the trailing twelve months. The product fits within developer-native workflows, embedding review feedback directly into pull and merge requests rather than functioning as a standalone security dashboard. Post-acquisition by HackerOne, PullRequest no longer operates as an independent go-to-market entity; instead it functions as an integrated product line within HackerOne's broader security platform, with group entities spanning the US, UK, Netherlands, Ireland, and India, and reviewer coverage extended to Canada, Australia, and New Zealand.
PullRequest firmographics
Firmographics- Name
- PullRequest
- Legal name
- Pullrequest, LLC
- Website
- https://pullrequest.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- PullRequest, now HackerOne Code, provides AI-powered code review combined with human expert validation to enterprises, startups, and government entities, integrating natively with GitHub, GitLab, Bitbucket, and Azure DevOps to surface verified vulnerabilities within developer workflows.
- Ownership category
- akta.pro rank
PullRequest industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
- akta.pro secondary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where PullRequest is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
PullRequest business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Code Review as a Service: Subscription-based recurring revenue model for AI-powered code security review services. Customers pay for access to the platform combining AI detection with human expert validation.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Enterprise pricing |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
PullRequest product offering
Product offeringCore offering
PullRequest, now operating as HackerOne Code (H1 Code), provides an AI-powered code security platform that combines automated vulnerability detection with human expert validation. The service integrates natively with major source code management systems (GitHub, GitLab, BitBucket, Azure DevOps) to deliver detection, validation, and remediation guidance directly within developers' existing pull/merge request workflows.
Product overview
PullRequest operates as part of the HackerOne platform under the HackerOne Code (H1 Code) product suite. The core offering combines AI-powered code security with human expert validation through a Detection → Validation → Remediation workflow. The main products include HackerOne Code (the AI-powered code review platform), Code Security Audit (human-led security audits), Smart Review Selection (AI-driven reviewer matching), and Benchmarks (code review analytics). The platform integrates natively with GitHub, GitLab, Bitbucket, and Azure DevOps (both cloud and on-premise versions), delivering feedback directly within pull/merge requests.
Differentiator
Problem solved
Functional benefit
Brands
- HackerOne Code: AI-powered code security with human expert validation for reducing software risk.
- Code Security Audit
Products and services
- HackerOne Code (H1 Code) AI-powered code security platform combining automated detection with human expert validation. Delivers remediation guidance to developers within their existing SCM tools to catch vulnerabilities before they reach production.
- Code Review Human-led code review service where expert engineers manually review and validate code changes within pull/merge requests. Uses AI filtering combined with human-in-the-loop validation to virtually eliminate false positives.
- Smart Review Selection AI-powered intelligent assignment of code reviews to appropriate expert reviewers based on technology expertise, professional experience, and repository familiarity.
- Code Security Audit Comprehensive human-led security audit service for codebases. Expert engineers conduct detailed security analysis and provide remediation recommendations.
- Benchmarks Code review metrics and benchmarking service that compares team performance against similar organizations. Provides insights on Issue Catch Rate, Code Review Size, Lifecycle Duration, Reviewer Response Latency, and Tests Percentage.
Quantifiable outcome
- Most detection & validation scanning completes in 2-4 minutes
- +4 more outcomes
Companies that use PullRequest
Customer profileNamed customers20 records
Segments4 records
Ideal customer profiles2 records
PullRequest technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability7 records
Feature5 records
PullRequest partnerships and signals
Strategic signalScale indicators5 records
Recent moves6 records
Expansion highlights5 records
PullRequest competitors and assessment
Company assessmentDirect peers
- Snyk: Developer-first security platform offering SAST, SCA, and container security with AI-powered code analysis. Directly competes in the application and code security space, targeting engineering teams with integrated developer tooling.
- GitHub Advanced Security: GitHub's native code security offering including CodeQL-based code scanning, secret scanning, and dependency review. Competes directly with PullRequest by embedding security review into the GitHub pull request workflow.
- Sonar (SonarQube/SonarCloud): Code quality and security analysis platform with deep integration into SCM platforms and CI/CD pipelines. Competes in code-level vulnerability detection and remediation guidance for development teams.
- Codacy: Automated code quality and security analysis platform integrating with GitHub, GitLab, and Bitbucket. Directly competes with PullRequest in providing review feedback on pull requests and tracking code quality metrics.
Broad incumbents
- Veracode: Established application security testing platform offering SAST, DAST, SCA, and manual penetration testing. Competes in the broader AppSec market where PullRequest's code security review sits as one component of enterprise testing strategy.
- Checkmarx: Enterprise application security platform providing static and dynamic analysis, software composition analysis, and developer security training. Competes for the same enterprise AppSec budget as PullRequest.
Emerging players
- Semgrep: AI-assisted code security scanning platform with strong developer adoption and community-driven rule sets. Emerging competitor in code security with a developer-first, automation-first philosophy contrasting PullRequest's human-augmented model.
- CodeRabbit: AI-powered code review tool providing automated PR review feedback. Emerging AI-native competitor to PullRequest's hybrid AI-plus-human model, betting that pure-AI review can reach acceptable accuracy.
- Aikido Security: Unified code security platform combining SAST, SCA, and runtime scanning with an AI-driven consolidation approach. Emerging competitor targeting security-conscious engineering teams seeking consolidated tooling.
- Corgea: AI-powered code security platform focused on automatically detecting and fixing vulnerabilities. Emerging pure-AI competitor whose trajectory tests whether human-in-the-loop validation remains necessary.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
PullRequest social profiles
Digital presencePullRequest compliance and trust
Trust signalCompliance2 records
PullRequest financial estimates
Financial estimateRevenue estimate
Valuation estimate
PullRequest leadership team
Management profileNumber of profiles
Profiles2 records
PullRequest funding detail
Funding detailFunding overview
Funding rounds4 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
PullRequest M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about PullRequest
What does PullRequest do?
PullRequest, now operating as HackerOne Code (H1 Code), provides an AI-powered code security platform that combines automated vulnerability detection with human expert validation. The service integrates natively with major source code management systems (GitHub, GitLab, BitBucket, Azure DevOps) to deliver detection, validation, and remediation guidance directly within developers' existing pull/merge request workflows.
Is PullRequest a public or private company?
PullRequest is a private company. It is classified as corporate owned and is currently operating.
When was PullRequest founded?
PullRequest was founded in 2017. It employs 11 to 50 people.
Where is PullRequest based?
PullRequest is headquartered in Austin, United States, in the North America region.
How does PullRequest make money?
One revenue line is on record: code Review as a Service.
Who are PullRequest's main competitors?
Direct peers on record are Snyk, GitHub Advanced Security, Sonar (SonarQube/SonarCloud) and Codacy. Broad incumbents are Veracode and Checkmarx. Emerging players are Semgrep, CodeRabbit, Aikido Security and Corgea.
Does PullRequest have an API?
No public API is recorded for PullRequest.
What industry is PullRequest in?
PullRequest's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAG, Code & Repository Security (Git Security, Code Integrity), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 54151 and its SIC code is 7370.