HackerOne logo

    HackerOne

    Sold by
    HackerOne is the global leader in human-powered security, harnessing the creativity of the world's largest community of security researchers with cutting-edge AI to protect your digital assets. The H1 Platform combines the expertise of our elite community and the most up-to-date vulnerability database to pinpoint critical security flaws across your attack surface. Our integrated solutions, including H1 Bug Bounty, H1 Pentesting, code security audits, spot checks, and AI red teaming, ensure continuous vulnerability discovery and management throughout the software development lifecycle. Trusted by industry leaders such as Coinbase, General Motors, GitHub, Goldman Sachs, Hyatt, PayPal, Snap Inc, and the U.S. Department of Defense, HackerOne was named a Best Workplace for Innovators by Fast Company in 2023 and a Most Loved Workplace for Young Professionals in 2024.

    Ratings and reviews

    4.5
    91 ratings
    73%
    22%
    4%
    1%
    0%
    3 AWS reviews
    |
    88 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (91)
    Lior A.

    Strengthens Security and Streamlines Issue Management

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate H1 Platform for allowing me to get reports and awareness of issues way earlier than when we notice them. This feature helps prevent attacks by raising security concerns before they become problems, extending our ongoing testing. It also enables me to understand reports faster and respond more professionally to researchers submitting tickets. I find the integration with tools like Claude very useful for getting an overview of all my tickets, prioritizing them, and resolving them more effectively. The integration with other platforms, like Confluence and Slack, helps manage vulnerabilities, provides useful statistics, and facilitates communication through alert channels.
    What do you dislike about the product?
    We had a few challenges at the beginning because a lot of our assets were on prem and inside our VPN, so the integration to Confluence wasn't as intuitive. We had a lot of problems with that specifically.
    What problems is the product solving and how is that benefiting you?
    I use H1 Platform to harden security, get reports, and identify issues early. It prevents attacks and raises security concerns, extending our testing.
    Information Services

    Great bug bounty platform. Diverse researchers, good UI, strong integrations, excellent support

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    HackerOne is a great bug bounty platform. The UI is clean and generally easy to use. It has all the integrations we need to connect to our other systems. Support is excellent, both our dedicated CSM and the agents that have helped us with miscellaneous support tickets. The AI features have drastically improved in the last 6 months and it's getting better every week.

    We've gotten very good value from having hundreds of additional eyes on our product, submitting many (and varied) vulnerabilities, and then of course remediating those and the resulting internal discussions on secure coding, secure architecture, and so on.
    What do you dislike about the product?
    The biggest pain point is when videos are submitted as part of bug bounty reports. The loading is slow or sometimes the video does not play at all. Often a hard refresh of the page is required but that does not always fix it and it can be annoying to scroll back down to the video (also related to next point).

    It's also easy to drown in information on a given report (huge report, tons of information, perhaps comments with additional screenshots, videos, walls of text, etc.). All of it is presented at once and the vertical scrolling space can be huge—there is potential to improve UX via presenting information better or perhaps using toggles or similar.
    What problems is the product solving and how is that benefiting you?
    The core problem is faster software development and the resulting vulnerabilities that other, internal security controls can miss. H1 is helping us with this by getting external researchers with a different perspective to look at our platform and finding vulnerabilities.
    Cong N.

    User-Friendly Platform That Decreased Our Response Time

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    The platform is user-friendly and easy to navigate. HAI has definitely helped, as it has decreased our response time.
    What do you dislike about the product?
    I’m pretty happy with the platform right now.
    What problems is the product solving and how is that benefiting you?
    H1 is able to validate findings and provide recommendations or fixes when requested.
    Computer Software

    HAI AI Assistant Makes Reports Easier and Replies Faster

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    Its AI assistant HAI. Its helpful in understanding reports as well generate replies faster.
    What do you dislike about the product?
    Sometimes reports takes too long to load or stuck on blank page.
    What problems is the product solving and how is that benefiting you?
    Fiction between customer and hackers.
    Manufacturing

    Easy to Use and Great for Building a Researcher Community

    Reviewed on Aug 12, 2026
    Review provided by G2
    What do you like best about the product?
    Ease of use and the ability the build a community with a group of experienced researchers
    What do you dislike about the product?
    Triage has been lacking recently but that is due to the influx of AI reports.
    What problems is the product solving and how is that benefiting you?
    The triage process is due to change for the better soon which will benefit us by having reports validated at a faster pace.
    sohit a.

    Streamlines Vulnerability Management with Stellar Support

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate how easy to use the H1 Platform is, which makes the workflow quite smooth. The task team helps us manage findings effectively before assigning them to our development team. I like having a large number of security researchers contributing to the platform, which aids us in identifying vulnerabilities that we might otherwise miss. The VDP program feature is particularly valuable as it assists us in maturing our security program by disclosing vulnerabilities. The number of researchers and the way the platform hosts challenges are also significant factors that led us to choose H1 Platform.
    What do you dislike about the product?
    Managing the inflow of reports in our VDP program can be challenging. We have over 5,000 assets, and sometimes it's hard to identify which teams own those assets, making it difficult to manage all the reports. However, after discussions with the HackerOne support team, they've introduced custom tags that help us assign reports to the correct product teams, which has been a significant improvement.
    What problems is the product solving and how is that benefiting you?
    H1 Platform helps us manage over 5,000 assets by identifying vulnerabilities through external researchers. It saves us from internal testing, improves security, and boosts customer confidence. The workflows are smooth, and the platform effectively assigns vulnerabilities to developers.
    Cameron H.

    Essential for Secure and Efficient Testing

    Reviewed on Aug 10, 2026
    Review provided by G2
    What do you like best about the product?
    H1 is easy to use, and the built-in AI tooling gives us quick insight into our most impactful bugs without the sloppiness and hallucinations you hear about with AI elsewhere. Onboarding quality researchers is simple, and because we run an invite-only program, we control who gets access and keep the expertise level high. That control over researcher quality is a significant reason I wouldn't use any other platform.
    What do you dislike about the product?
    There isn't really anything we don't like. HAI helps to navigate when we can't find anything and is is getting better every day. For our use case the Platform is perfect.
    What problems is the product solving and how is that benefiting you?
    We run dozens of customer-facing brands on a shared stack, and no internal team can continuously test that entire surface. H1 solves that by giving us ongoing coverage from skilled researchers who find real, exploitable issues across applications, not just scanner noise. Every valid report becomes a tracked fix, so the benefit is straightforward: vulnerabilities get found and closed before an attacker finds them first.
    Anonymous

    Solid Platform for Security Insights with Minor Usability Issues

    Reviewed on Aug 10, 2026
    Review provided by G2
    What do you like best about the product?
    I use H1 Platform for the bug bounty program, which helps us see security issues beyond our own testing and reviews. I appreciate that the people involved in the program do a great job of being transparent and letting us know what the H1 program offers. Also, it's good for communicating with an internal team member and setting up engagements.
    What do you dislike about the product?
    The website is a bit clunky, for example, if I click out of my inbox to another screen it will hold the ticket I was looking at. If I click away from the screen into a new window it should hold that data; it's like two screens in one which I do not like.
    What problems is the product solving and how is that benefiting you?
    H1 Platform helps us identify security issues beyond our own testing and reviews.
    Biotechnology

    Hai Makes Submission Triage Easy and Provides Helpful Remediation Insights

    Reviewed on Aug 05, 2026
    Review provided by G2
    What do you like best about the product?
    Hai helps me triage submissions more easily. I also appreciate that it provides useful insight and helps with remediation and fixes when I’m filling out tickets for eng.
    What do you dislike about the product?
    In general, I’m pretty satisfied. The only thing that could be improved is the H1 triage times.
    What problems is the product solving and how is that benefiting you?
    H1 gives us continuous external testing coverage
    Pranay Jain

    Platform has expanded my ethical hacking skills and provides trusted bug bounty opportunities

    Reviewed on Jun 14, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for HackerOne is bug bounties and getting paid through that platform. Companies like Fastify and Oracle create bug bounties and vulnerability disclosure programs on HackerOne. Ethical hackers test the company's applications, websites, APIs, and systems for security issues. Whenever a vulnerability is found, we can submit it as a report to the platform, and then the company reviews the report. If there is a bug related to that issue, they can fix it and reward the researcher based on the severity of the vulnerability. HackerOne acts as a trusted intermediary.

    HackerOne is a platform where bug bounty hunters can come to one place to find opportunities. Whenever a company raises a new web application and wants continuous security testing, they can publish it on HackerOne. HackerOne has testers and workers who are continuously testing for vulnerabilities and reporting those findings. For example, a researcher can find cross-site scripting vulnerabilities in a user comment section.

    I have a specific example of how I have used HackerOne in a real situation. I personally used it for finding a bug in one of the applications. In one application, whenever we clicked on the login button three times, we were able to go to the home page. After logging in, if we clicked back three times and then clicked again after logout, we were able to go to the home page again because the session storage was not getting stored properly. I reviewed that and raised a report against that vulnerability for a company known as Adwords.

    What is most valuable?

    HackerOne provides a platform for both developers and bounty hunters, as well as companies to publish their applications and get paid through bug bounty programs and vulnerability disclosure programs. HackerOne offers report management, triage, a large research community, severity and risk assessment, workflow integration, analytics and reporting, and many other features. One of the biggest strengths is combining a large community of ethical hackers with a structured platform that helps organizations discover, manage, and remediate security vulnerabilities efficiently.

    The community aspect of HackerOne helps me personally and helps organizations because they can leverage a global community of ethical hackers to find vulnerabilities before any attackers do. HackerOne functions as a UAT environment where people can test the application, and after the UAT environment, there is a place where testing can be done by breaking the product. Breaking the product is important to test the product thoroughly. HackerOne can be the solution for that when you want to test your product thoroughly, as sometimes breaking the product is the best testing approach. HackerOne can be integrated into tools such as Jira, Slack, and GitHub to streamline the remediation. It also provides a dashboard and insights into security trends, response time, and program performance, which is very helpful for an organization to get their product tested and to get insights about it.

    What needs improvement?

    HackerOne can be improved, and the insights can be a little better. I chose a nine for my rating because it has very great features such as a large research community, workflow integration, analytics and reporting, bug bounty programs, and vulnerability disclosure programs. However, some things can be improved, such as better report deduplication by automatically identifying duplicate vulnerability reports more accurately. In the current era of AI, enhancing AI accuracy and AI-assisted triaging would be beneficial.

    More advanced AI capabilities would help prioritize reports, reduce false positives, and speed up the validation. For example, not being able to log in is a very high priority rather than a user not being able to get the current date or current time. In applications, if the user is not able to type something, that is the highest priority, rather than the user typing something, getting the information, but on the last page getting something random. That is not a major bug compared to the other issue. Prioritizing through AI can be a better approach.

    For how long have I used the solution?

    I have been using HackerOne for around 3.5 years.

    What do I think about the stability of the solution?

    HackerOne is quite stable.

    What do I think about the scalability of the solution?

    HackerOne's scalability is very strong.

    How are customer service and support?

    HackerOne's customer support is very great.

    Which solution did I use previously and why did I switch?

    I did not use any previous solution before HackerOne, but I have knowledge about Bugcrowd and Intigriti, which are in the European region.

    How was the initial setup?

    The pricing of HackerOne is good and very great from a pricing perspective. The setup cost is not very much and is very minimal. From a setup cost perspective, the onboarding is relatively straightforward. The organization just needs to define the scope of assets that they need to be tested, configure what workflows they need to be tested, and establish the policies for handling any reports.

    What was our ROI?

    I have definitely seen a return on investment because every time our application goes to UAT, it is tested by our sales people. However, sometimes the sales people can disregard something or forget to test something. In those cases, HackerOne platform is very good because it provides a great place to test the applications. I haven't seen any specific ROI metrics, but my general impression is that HackerOne provides strong value by helping organizations find vulnerabilities faster and reduce the higher costs associated with security breaches.

    Which other solutions did I evaluate?

    I evaluated a few options such as Bugcrowd and Intigriti before going to HackerOne.

    What other advice do I have?

    My organization does not use HackerOne as a product, but I personally use HackerOne because I am an ethical hacker who uses it to test different applications and try to find vulnerabilities. The reason I do it is to get more information about the different applications, to learn through that experience, and to find how to identify problems in an application. It increases my knowledge regarding any subject, which is very helpful for me.

    HackerOne has helped me learn, and there is one technique that I got to pick up. At one place, I was finding a cross-site script issue. There was an API for an order that was passing in the query parameter as the ID of the customer. The order ID and customer ID were getting passed as the query parameter. Whenever we changed that query parameter and if we had the JSON Web Token for authentication, we were able to get the data of other customers as well. This can be protected if you use some other particular tokens and the payload can be tested properly. I got to know about this problem, which improved my knowledge in back-end writing, especially regarding writing the back-end in APIs. That is one area that I have handled.

    Regarding HackerOne's AI capabilities, I think the accuracy is very good. Up until now, I have not used its AI features, but the accuracy appears to be good. I gave HackerOne a rating of nine out of ten based on my overall experience with the platform.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)