HackerOne
Editorial coverage of HackerOne.
HackerOne is a platform for buying human security research through vulnerability disclosure programmes, bug bounty programmes and scoped penetration tests.
Who makes HackerOne
HackerOne operates the platform at hackerone.com, connecting organisations with an external community of security researchers and handling programme workflow and reward payment.
Official website: www.hackerone.com ↗
What it actually does
Organisations publish a scope and rules, then receive researcher submissions through managed intake and triage — including duplicate detection, severity assessment and researcher communication — with integrations into issue trackers. Scoped penetration tests delivered by vetted testers produce reports suitable for audits and enterprise security reviews.
Product family
- · Vulnerability Disclosure Programme (VDP)
- · Bug Bounty (public and private)
- · Pentest
- · Triage and programme workflow
What people hire it for
- Running a public or invitation-only bug bounty programme
- Publishing a formal vulnerability disclosure route
- Commissioning a scoped, reportable penetration test
- Triaging inbound security reports without building the workflow in-house
- Demonstrating a mature disclosure process to customers and regulators
Where it runs
Security & privacy
HackerOne is a hosted platform with no software to install; what it consumes is triage attention. A scoped pentest report is commonly accepted as audit evidence, whereas a bug bounty generally is not a substitute for a mandated penetration test — confirm with your assessor.
Where HackerOne appears
Featured in these buying guides
Not yet included in a Best-Of round-up. Editorial planned for the next update cycle.
Head-to-head
Planned
- HackerOne vs Bitdefender — coming soon
- HackerOne vs Norton — coming soon
Planned reviews
Full review published — read it here.
Read next
- CyberSuitePenetration testing, dark web monitoring and security awareness training sold as one SMB subscription instead of a consulting engagement.
- IntruderContinuous vulnerability management and external attack-surface scanning for SMB and mid-market engineering teams.
- DetectifyExternal attack surface management and application scanning powered by a curated ethical hacker community.
- PenteraAutomated security validation that emulates attacks across internal, external and cloud environments for enterprise security teams.