Listing Thumbnail

    HackerOne

     Info
    Sold by: HackerOne 
    Deployed on AWS
    Vendor Insights
    HackerOne is the global leader in human-powered security, harnessing the creativity of the world's largest community of security researchers with cutting-edge AI to protect your digital assets. The H1 Platform combines the expertise of our elite community and the most up-to-date vulnerability database to pinpoint critical security flaws across your attack surface. Our integrated solutions, including H1 Bug Bounty, H1 Pentesting, code security audits, spot checks, and AI red teaming, ensure continuous vulnerability discovery and management throughout the software development lifecycle. Trusted by industry leaders such as Coinbase, General Motors, GitHub, Goldman Sachs, Hyatt, PayPal, Snap Inc, and the U.S. Department of Defense, HackerOne was named a Best Workplace for Innovators by Fast Company in 2023 and a Most Loved Workplace for Young Professionals in 2024.
    4.5

    Overview

    Play video

    The H1 Platform is the leading solution for combining human-powered security testing with advanced AI to safeguard your digital assets. Our platform provides an integrated suite of security solutions that ensure continuous vulnerability discovery and management throughout the software development life cycle. By harnessing the strengths of the world's largest community of security researchers and the latest AI technologies, HackerOne helps organizations reduce their threat exposure and transform their businesses with confidence.

    For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@hackerone.com , for a private offer.

    H1 Response

    • Leading Vulnerability Disclosure Program (VDP) platform
    • Streamlines third-party vulnerability reporting
    • Integrates with 20+ SDLC systems
    • Ensures compliance and collaboration

    H1 Pentest

    • Methodology-driven security testing
    • SaaS-based delivery model
    • Curated elite pentester teams
    • End-to-end testing process

    H1 Code Security Audit

    • Premium code review service
    • 600+ vetted senior software engineers
    • Deep source code analysis
    • Early-stage vulnerability detection

    H1 Bounty

    • Continuous security testing
    • The global ethical hacker community
    • Performance-based rewards
    • Scales with business needs

    H1 AI Red Teaming

    • Specialized AI system testing
    • Expert security advisory support
    • Identifies AI-specific vulnerabilities
    • Mitigates model risks and biases

    H1 Challenge

    • Time-bound security testing sprints
    • Targeted vulnerability discovery
    • Ideal for new releases
    • Flexible engagement model

    Streamlined integrations and automation: HackerOne offers robust APIs and built-in integrations and automation, simplifying vulnerability management and streamlining workflows.

    Managing different programs within our AI-powered platform provides unprecedented insights into your security program's effectiveness while offering the efficiency and ease of a single interface.

    Together, these integrated solutions provide indispensable capabilities for organizations. They ensure that vulnerabilities are continuously identified, prioritized, and remediated, providing unmatched protection from code to the cloud.

    Learn more about each one of our offerings designed to address specific security challenges with our Defense-in-Depth strategy at https://www.hackerone.com/product/overview 

    Highlights

    • The H1 Platform continuously discovers, validates, prioritizes, and remediates to reduce exposure debt before attackers act. Hai scores and validates at machine speed while a community of elite security researchers surfaces business logic flaws and novel attack chains no automated tool reaches. Confirmed findings route directly into Jira, GitHub, ServiceNow, Azure DevOps, Slack, and Teams through 30+ integrations.
    • Hai, HackerOne's agentic AI orchestrator, handles thousands of reports per week at 95% accuracy, improving signal by 40%, and reduces prioritization decisions from hours to seconds. H1 Remediation delivers source code-informed, developer-ready fix plans into your issue tracking tools in one click, or directly to an AI coding agent via MCP. Retests confirm fixes hold. Regression monitoring ensures they stay closed.
    • Managing all programs within the H1 Platform gives security leaders a unified view of exposure across the full attack surface. Cross-program dashboards track exposure velocity, remediation speed, and signal quality. Self-serve Return on Mitigation quantifies program value as avoided financial loss, with $32B+ in risk exposure mitigated for customers to date.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    HackerOne Platform
    Proven human-powered security testing, enhanced by AI
    $500,000.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    Rewards overage fee
    $0.01

    AI Insights

     Info

    Dimensions summary

    This contract listing has two pricing dimensions that work together. You commit to the HackerOne Platform, which delivers human-powered security testing supported by AI. This is the core subscription you buy for a fixed term. The Rewards overage fee is a usage-based add-on. It applies when the rewards you pay to security researchers exceed your committed amount. So one dimension covers your base platform access, while the other charges only if reward payouts run past your commitment. Your total cost scales with how much you pay out in researcher rewards.

    Top-of-mind questions for buyers

    Rewards are the payments you make to security researchers for valid vulnerabilities they find. Your committed amount covers a set pool of these payouts. The overage fee applies only once your actual reward payments pass that committed pool. It charges the amount that runs beyond your commitment.
    The Platform dimension covers your subscription to the security testing service. This includes access to a community of security researchers, AI-assisted triage and validation, vulnerability report management, dashboards, and integrations with your existing tools. Researcher reward payouts are billed separately through the Rewards overage fee, not within this dimension.
    Both dimensions bill together on the same contract. The HackerOne Platform is a fixed subscription for your term. The Rewards overage fee grows only when researcher payouts pass your committed pool. Programs that surface many valid vulnerabilities see the overage fee become the variable part of the bill.
    www.hackerone.com+1
    Helpful?

    Vendor refund policy

    There are no refund options available.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    To ensure that you receive timely assistance, it's important to be aware of our Support & Mediation team's business hours. This documentation details when our Support Team is available, how to reach them, and additional resources for self-help outside of these hours.

    Support Team Operating Hours Our dedicated Support team is available to assist you during the following hours:

    Monday to Friday: Mediation (Customers)

    8:00am - 5:00pm PT

    Support

    12:00am-4:30pm PT

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Observability, Testing
    Top
    10
    In Assessments
    Top
    50
    In Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    13 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Vulnerability Discovery and Validation
    Continuous discovery, validation, prioritization, and remediation of vulnerabilities across the full attack surface using human-powered security researchers combined with AI-powered analysis
    AI-Powered Triage and Prioritization
    Hai agentic AI orchestrator processes thousands of reports weekly at 95% accuracy, improves signal by 40%, and reduces prioritization decisions from hours to seconds
    Automated Remediation and Fix Generation
    Source code-informed, developer-ready fix plans generated automatically into issue tracking tools or directly to AI coding agents via MCP, with automated retests and regression monitoring
    Unified Security Program Management
    Centralized platform providing cross-program dashboards that track exposure velocity, remediation speed, signal quality, and quantify program value through Return on Mitigation metrics
    Penetration Testing Service
    Penetration Testing as a Service (PTaaS) platform combining security professionals with AI and automation, delivering 50+ pentest types with streamlined workflows and accelerated remediation.
    Attack Surface Management
    Continuous visibility into internal and external attack surfaces with capabilities to discover unknown assets, identify exposure gaps, and prioritize remediation based on real-world risk contextualization.
    Red Team and Adversary Simulation
    Red team engagements simulating real-world adversaries that chain vulnerabilities across identity, application, cloud, and infrastructure layers to demonstrate breach scenarios and measure detection effectiveness.
    Specialized Security Teams
    Dedicated teams specializing in application, cloud, infrastructure, identity, and mainframe security assessments with proprietary testing frameworks and tooling.
    AI-Accelerated Security Workflows
    AI-accelerated platform enabling critical security workflows with use case-driven experience to move from findings to fixes faster through automated processes.
    AI-Powered Researcher Sourcing
    Platform uses data and AI to source and activate security researchers and pentesters across multiple dimensions for continuous vulnerability discovery.
    Penetration Testing as a Service
    Modern PTaaS suite enabling rapid pen test launches against any target within days with prioritized findings dashboard and DevSec workflow integration.
    Automated Triage and Noise Reduction
    Core triage competency that rapidly removes false positives and adds context for prioritization, handling critical vulnerabilities within a single day.
    Vulnerability Disclosure Program Management
    Managed VDP solution providing intake channels, validation, triage, researcher relations, SDLC integration, and reporting for public vulnerability submissions.
    Security Knowledge Graph Analytics
    Deep analytics engine built on millions of data points about vulnerabilities, assets, and hacker skill sets to drive insights, recommendations, and AI models.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    101 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    70%
    25%
    4%
    1%
    0%
    3 AWS reviews
    |
    98 external reviews
    External reviews are from G2  and PeerSpot .
    Aakash K.

    All-in-One Triage with a Strong Researcher Pool That Catches What Scans Miss

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    The biggest benefit is having the entire triage process in one place; from intake and researcher back-and-forth to severity scoring. So things do not get lost. The researcher pool is strong too. They regularly find issues that our automated scans miss.
    What do you dislike about the product?
    The biggest issue is report quality. Too much triage time goes to filtering low-effort or duplicate submissions before we can focus on valid findings. The platform can also feel slow and clunky when moving between reports, programs, and analytics.
    What problems is the product solving and how is that benefiting you?
    HackerOne gives us broader vulnerability coverage than relying on internal testing and automated scanning alone. The researcher community helps uncover issues our existing tools can miss, and it’s helpful that reporting and triage stay together in a single workflow.
    Mini M.

    Self-Explanatory UI and H1 Triage That Saves Significant Effort

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    It has a very self explanatory UI. I like the H1 triage feature and team, it saves us significant effort of initial triaging, also appreciate direct integrations with ticketing tools to allow auto ticket creation,
    What do you dislike about the product?
    The AI features can be better, the results from HAI are not always helpful
    What problems is the product solving and how is that benefiting you?
    H1 platform helps us augment the security testing of our products by inviting external vetted researchers. it allows us to identify security vulnerabilities at a much faster pace
    Noa K.

    Great Triage and Metrics, but Pricing Tiers and Renewals Create Friction

    Reviewed on Sep 02, 2026
    Review provided by G2
    What do you like best about the product?
    I really like the way critical and high findings are prioritized. The H1 triage analysts are extremely helpful and genuinely pleasant to work with.

    I also appreciate that the platform offers many different ways to pull metrics, which makes it easier to share clear updates with leadership on how the program is progressing.

    The researcher community is very large and includes highly talented security researchers from around the world, so it’s easy to find people who can support our program’s specific needs.

    Additionally the UI in the platform is very appealing and easy to use (especially in dark mode).
    What do you dislike about the product?
    The pricing structure (consumption tiers every 50-100K in bounty spend) is the worst part about H1. It makes running a program significantly more difficult and forces us to be very careful when paying researchers and hinders out ability to mature our program. The value that comes from a 50K different in bounty spend is not work the additional cost from the consumption tier. Switching to a unlimited tier structure would be amazing.

    The triage time historically has also been quite slow, although recently we have seen large improvements via prioritization of high impact findings.

    The support in terms of getting quotes and working with HackerOne folks also has room for improvement. It is a difficult process to work back and forth trying to get renewals/upgrade quote processed.

    HAI also hallucinates metrics all the time and will struggle to provide details on where it got the data.

    The findings tab should also have the ability to export results across all pages, not just one page at a time. This would make it much easier to generate out own metrics using data we trust.
    What problems is the product solving and how is that benefiting you?
    They provide everything we need to run our bug bounty program and helps us identify vulns that our other security tooling misses.
    Leon G.

    H1 Team Saves Us Time by Validating Submissions

    Reviewed on Sep 01, 2026
    Review provided by G2
    What do you like best about the product?
    The h1 team help us to validate all the submissions, saving us time and keeping the team focused on tasks and projects that are valuable for our external customers
    What do you dislike about the product?
    Navigating through the platform and findings is not easy as I would, the communication channels within the findings is also not intuitive.
    What problems is the product solving and how is that benefiting you?
    It's validating all the potential security vulnerabilities that we don't know of, building trust that we can offer a secure product to our customers.
    Manuel O.

    Great Inbox, Strong Hacker Network, and Useful Metrics

    Reviewed on Sep 01, 2026
    Review provided by G2
    What do you like best about the product?
    Great inbox, great contact with a lot of hackers, i love the metrics sections
    What do you dislike about the product?
    The UI/UX has a lot to improve, the CVSS calculator is lacking functions as enviromental or temportal scores
    What problems is the product solving and how is that benefiting you?
    Founding external vulnerabilities
    View all reviews