Sleep easy with hackerone!
What do you like best about the product?
From the bug bounty page customization, detailed analytics page to the number of valid reports we have recieved. Hacker one leaves little to be desired.
It has inspired us with the cofidence we need to deploy secure products and keep our customers protected.
Simply Amazing!
What do you dislike about the product?
Initially our inability to invite researchers with certain skillsets/interest.
But H1 later rolled out a feature allowing us, So no dislikes.
What problems is the product solving and how is that benefiting you?
Actionable vulnerability disocvery in production environments through the power of crowdsourcing!
Every Business needs HackerOne.
What do you like best about the product?
HackerOne’s most helpful feature is its streamlined interface for managing bug bounties and coordinating with skilled ethical hackers. The platform enables us to submit, track, and prioritise vulnerabilities with ease, while detailed reporting helps our engineers to understand and fix issues quickly. Additionally, the platform’s vast network of researchers offers a diverse range of expertise, uncovering security gaps that might be missed in-house.
The key upsides of using HackerOne are the broad vulnerability coverage and the in-depth metrics that help us demonstrate program impact and effectiveness. The support from HackerOne’s team make the ongoing management of our program are seamless.
What do you dislike about the product?
Honestly, nothing. It is every improving and adding features, making it easier. New addition of Ai integration has made things faster for us too.
What problems is the product solving and how is that benefiting you?
HackerOne gives the business continuous, proactive vulnerability discovery with the help of a global community of ethical hackers. They bring diverse expertise of thousands of vetted hackers, which would be impossible to replicate in-house. They help us uncover a wider range of vulnerabilities than an in-house team could alone, especially as new threats emerge. The can and have scaled with us, as our business grows which maintains our security posture, aids us in compliance, and protects customer trust.
Overall Positive Experience
What do you like best about the product?
The flexibility to target bounty and VDP scopes on assets as requirements change. Easy to track metrics and payouts as well as other important program information. Great customer support.
What do you dislike about the product?
They are working on it, but the inbox tracking between researchers to our internal team for the current action that needs to be taken could be simplified.
What problems is the product solving and how is that benefiting you?
Supplementing our internal penetration testing teams to provide extended visibility on high priority platforms to see what is visible to people not as familiar with our infrastructure and systems as internal testers.
Streamlining Our Bug Bounty Program with HackerOne
What do you like best about the product?
HackerOne has been a game-changer for our bug bounty program. It’s user-friendly, efficient, and provides a robust platform to manage our program, connect with researchers, and efficiently triage reports. The platform’s features, like vulnerability management and communication tools, are essential for our team’s success.
What do you dislike about the product?
While the platform is generally excellent, some advanced customization options for program settings could be more intuitive.
What problems is the product solving and how is that benefiting you?
HackerOne helps us find and fix vulnerabilities faster, connecting us with a global community of security researchers. This streamlines our bug bounty program, strengthens our security posture, and reduces our risk of costly breaches.
Great Experience so far for their VDP program, customer service is top notch!
What do you like best about the product?
A couple highlights from one year of using their VDP platform:
-Ease of use, easy to navigate and understand the platform
-Customer service team is always available for you
-Their triage team will save you time to review submissions so your teams can work on other stuff
-CSM team provides good recommendations and examples of how to best utilize and strengthen your security
What do you dislike about the product?
Sometimes you have to request more details from the triage team but my experience has been that your PoC will step in to clarify that with them so its not really an issue.
What problems is the product solving and how is that benefiting you?
We needed a VDP platform so we wanted to use one of the best platforms out there.
A must-have if you're serious about security
What do you like best about the product?
It's not really about the platform but the service, HackerOne is probably the most well-known bug bounty platform, the experience (both on the researcher and the "business" side) is very well curated and there is no substitute for the amount of visibility that this service will give to your bug-bounty program.
What do you dislike about the product?
Nothing really to dislike here but sometimes the triaging workflow is a bit clunky and we had a couple of bugs with notifications but none of these problems really affected the service in a major way
What problems is the product solving and how is that benefiting you?
Managing and sponsoring a bug bounty program, the service really takes a ton of implementation/maintenance time out of these activities
Excellent platform for bug bounty
What do you like best about the product?
HackerOne offers a great platform for bug bounty management. We were able to have a program launched in a snap, get hackers testing our system, and find potential issues.
What do you dislike about the product?
The quality of the community report can vary. We wanted to improve the signal to noise ratio, which HackerOne did, but it's still far from perfect.
What problems is the product solving and how is that benefiting you?
We get our system all year round tested by hackers, plus a annual pentest.
Powerful Platform for Effective Security Testing
What do you like best about the product?
HackerOne has been transformative for our security program. The platform connects us with top-notch ethical hackers, uncovering vulnerabilities that traditional tools missed. The interface is user-friendly, making it easy to manage and track reports. Their triage support helps us quickly validate and prioritize findings, saving our team time and effort.
The customization options, including private programs and flexible bounties, allow us to tailor the platform to our needs. Overall, HackerOne has improved our security and credibility, making it an excellent choice for any company focused on proactive security.
Key Pros
Skilled global talent pool
Clear UI and effective triage support
Flexible customization and insightful analytics
What do you dislike about the product?
Our budget took a little hit, but hey, security is priceless, right? 😅
What problems is the product solving and how is that benefiting you?
HackerOne helps us identify and resolve security vulnerabilities we might have missed with traditional tools. By leveraging a global network of skilled hackers, we get diverse insights, faster detection, and improved protection, ultimately strengthening our overall security posture.
They have streamlined the complete process, which gives a sense of security to the users
What is our primary use case?
I mainly use it for downtime activities, earning extra cash alongside a full-time job, and to get new sales and profits.
How has it helped my organization?
It helps me to get new sales, profits, and other benefits.
What is most valuable?
The main thing I like about HackerOne is that it provides a direct way to contact the program directly without the need to wait for weeks to get issues finalized and validated. They have streamlined the complete process, which gives a sense of security to the users.
What needs improvement?
The ability to view the conversation between the triagers and the programs will be really good. When an issue gets reported, the understanding conveyed to the program by the triagers is not visible to the reporter. This can cause gaps between what the finder has reported and what is explained to the program. If this communication is visible, it would benefit both parties.
For how long have I used the solution?
I have been using it for over three years, around three years.
What do I think about the stability of the solution?
I have not had any issues with stability like bugs or breakdowns.
What do I think about the scalability of the solution?
The scalability is good. It is easy to scale up or down data.
How are customer service and support?
The responsiveness has been good.
Which solution did I use previously and why did I switch?
I did not use any different solution before using HackerOne.
How was the initial setup?
The initial setup is not rocket science. It is something easy.
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
The improvements which I have listed should be considered.
Has a variety of programs but needs to implement AI to reduce duplicates
What is our primary use case?
I use the tool for vulnerability assessment and testing.
What is most valuable?
The most valuable feature of HackerOne is its variety of programs. These programs provide depth into various areas, such as mobile, API, and websites.
What needs improvement?
Response time can be improved. The HackerOne Trust team can be slow to respond sometimes. They're not using AI, which could help reduce the number of duplicate reports.
For how long have I used the solution?
I have been using the product for one and a half years.
What do I think about the stability of the solution?
The tool is stable and has only minor bugs.
What do I think about the scalability of the solution?
The solution is only scalable for registered users, not for mass people.
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
Integrating HackerOne into existing security protocols is impossible because it's just a platform. I rate the overall solution a six out of ten. For beginners, HackerOne is quite intuitive if you know the basics. You can easily create an account and start exploring different things.