Listing Thumbnail

    HackerOne

     Info
    Sold by: HackerOne 
    Deployed on AWS
    Vendor Insights
    HackerOne is the global leader in human-powered security, harnessing the creativity of the world's largest community of security researchers with cutting-edge AI to protect your digital assets. The H1 Platform combines the expertise of our elite community and the most up-to-date vulnerability database to pinpoint critical security flaws across your attack surface. Our integrated solutions, including H1 Bug Bounty, H1 Pentesting, code security audits, spot checks, and AI red teaming, ensure continuous vulnerability discovery and management throughout the software development lifecycle. Trusted by industry leaders such as Coinbase, General Motors, GitHub, Goldman Sachs, Hyatt, PayPal, Snap Inc, and the U.S. Department of Defense, HackerOne was named a Best Workplace for Innovators by Fast Company in 2023 and a Most Loved Workplace for Young Professionals in 2024.
    4.5

    Overview

    Play video

    The H1 Platform is the leading solution for combining human-powered security testing with advanced AI to safeguard your digital assets. Our platform provides an integrated suite of security solutions that ensure continuous vulnerability discovery and management throughout the software development life cycle. By harnessing the strengths of the world's largest community of security researchers and the latest AI technologies, HackerOne helps organizations reduce their threat exposure and transform their businesses with confidence.

    For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@hackerone.com , for a private offer.

    H1 Response

    • Leading Vulnerability Disclosure Program (VDP) platform
    • Streamlines third-party vulnerability reporting
    • Integrates with 20+ SDLC systems
    • Ensures compliance and collaboration

    H1 Pentest

    • Methodology-driven security testing
    • SaaS-based delivery model
    • Curated elite pentester teams
    • End-to-end testing process

    H1 Code Security Audit

    • Premium code review service
    • 600+ vetted senior software engineers
    • Deep source code analysis
    • Early-stage vulnerability detection

    H1 Bounty

    • Continuous security testing
    • The global ethical hacker community
    • Performance-based rewards
    • Scales with business needs

    H1 AI Red Teaming

    • Specialized AI system testing
    • Expert security advisory support
    • Identifies AI-specific vulnerabilities
    • Mitigates model risks and biases

    H1 Challenge

    • Time-bound security testing sprints
    • Targeted vulnerability discovery
    • Ideal for new releases
    • Flexible engagement model

    Streamlined integrations and automation: HackerOne offers robust APIs and built-in integrations and automation, simplifying vulnerability management and streamlining workflows.

    Managing different programs within our AI-powered platform provides unprecedented insights into your security program's effectiveness while offering the efficiency and ease of a single interface.

    Together, these integrated solutions provide indispensable capabilities for organizations. They ensure that vulnerabilities are continuously identified, prioritized, and remediated, providing unmatched protection from code to the cloud.

    Learn more about each one of our offerings designed to address specific security challenges with our Defense-in-Depth strategy at https://www.hackerone.com/product/overview 

    Highlights

    • Maintain continuous vigilance for your expanding digital attack surface, including applications, cloud assets, APIs, IoT, and the software supply chain. Quickly meet compliance and regulatory standards to ensure your product launches stay on track. Measure threats, examine the landscape, and demonstrate value to stakeholders, customers, and partners.
    • Flag elusive vulnerability classes that only human ingenuity and precision can uncover and avoid the false positives that come from automated scanners. Access security skills that align with your technology stack and free up internal resources to focus on more strategic initiatives. Direct communication with researchers: The platform facilitates real-time communication between organizations and security researchers, enabling remediation suggestions and quick vulnerability resolution.
    • Hai - AI copilot provides a deeper and more immediate understanding of your security program so you can make decisions and deliver fixes faster. Effortlessly translate natural language into precise queries, enrich vulnerability reports with relevant context, and use platform data to generate insightful recommendations. Integrate Hai's features into your current processes and tools with custom vulnerability scanner templates, API integrations, and dynamic automation.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    HackerOne Platform
    Proven human-powered security testing, enhanced by AI
    $500,000.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    Rewards overage fee
    $0.01

    AI Insights

     Info

    Dimensions summary

    This contract listing has two pricing dimensions that work together. You commit to the HackerOne Platform, which delivers human-powered security testing supported by AI. This is the core subscription you buy for a fixed term. The Rewards overage fee is a usage-based add-on. It applies when the rewards you pay to security researchers exceed your committed amount. So one dimension covers your base platform access, while the other charges only if reward payouts run past your commitment. Your total cost scales with how much you pay out in researcher rewards.

    Top-of-mind questions for buyers

    Rewards are the payments you make to security researchers for valid vulnerabilities they find. Your committed amount covers a set pool of these payouts. The overage fee applies only once your actual reward payments pass that committed pool. It charges the amount that runs beyond your commitment.
    The Platform dimension covers your subscription to the security testing service. This includes access to a community of security researchers, AI-assisted triage and validation, vulnerability report management, dashboards, and integrations with your existing tools. Researcher reward payouts are billed separately through the Rewards overage fee, not within this dimension.
    Both dimensions bill together on the same contract. The HackerOne Platform is a fixed subscription for your term. The Rewards overage fee grows only when researcher payouts pass your committed pool. Programs that surface many valid vulnerabilities see the overage fee become the variable part of the bill.
    www.hackerone.com+1
    Helpful?

    Vendor refund policy

    There are no refund options available.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    To ensure that you receive timely assistance, it's important to be aware of our Support & Mediation team's business hours. This documentation details when our Support Team is available, how to reach them, and additional resources for self-help outside of these hours.

    Support Team Operating Hours Our dedicated Support team is available to assist you during the following hours:

    Monday to Friday: Mediation (Customers)

    8:00am - 5:00pm PT

    Support

    12:00am-4:30pm PT

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Observability, Testing
    Top
    10
    In Assessments
    Top
    50
    In Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    13 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Vulnerability Disclosure Program Platform
    Leading vulnerability disclosure program platform that streamlines third-party vulnerability reporting and integrates with 20+ SDLC systems to ensure compliance and collaboration.
    AI-Powered Security Analysis
    AI copilot system that provides natural language query translation, vulnerability report enrichment with contextual data, and generates insightful recommendations for security program analysis.
    Integrated Security Testing Solutions
    Suite of integrated security solutions including bug bounty programs, methodology-driven penetration testing, premium code review with 600+ vetted senior engineers, and AI-specific red teaming for continuous vulnerability discovery.
    API and Automation Integration
    Robust APIs and built-in integrations with custom vulnerability scanner templates and dynamic automation capabilities to streamline vulnerability management workflows.
    Multi-Surface Attack Coverage
    Continuous security testing across expanding digital attack surfaces including applications, cloud assets, APIs, IoT, and software supply chain with human-powered vulnerability detection.
    Penetration Testing Service
    Penetration Testing as a Service (PTaaS) platform combining security professionals with AI and automation, delivering 50+ pentest types with streamlined workflows and accelerated remediation.
    Attack Surface Management
    Continuous visibility into internal and external attack surfaces with capabilities to discover unknown assets, identify exposure gaps, and prioritize remediation based on real-world risk contextualization.
    Red Team and Adversary Simulation
    Red team engagements simulating real-world adversaries to test people, processes, and technology, chaining vulnerabilities across identity, application, cloud, and infrastructure layers to demonstrate breach scenarios.
    Specialized Security Assessment Teams
    Dedicated teams specializing in application, cloud, infrastructure, identity, and mainframe security with proprietary testing frameworks and tooling for deeper technical validation.
    AI-Accelerated Security Workflows
    AI-accelerated platform experience enabling critical security workflows with reduced complexity, translating vulnerabilities into business and regulatory risk insights with real-time reporting and remediation guidance.
    AI-Powered Researcher Sourcing
    Platform uses data and AI to source and activate security researchers and pentesters across multiple dimensions for continuous vulnerability discovery.
    Penetration Testing as a Service
    Modern PTaaS suite enabling rapid pen test launches against any target within days with prioritized findings dashboard and DevSec workflow integration.
    Automated Triage and Noise Reduction
    Core triage competency that rapidly removes false positives and adds context for prioritization, handling critical vulnerabilities within a single day.
    Vulnerability Disclosure Program Management
    Managed VDP solution providing intake channels, validation, triage, researcher relations, SDLC integration, and reporting for public vulnerability submissions.
    Security Knowledge Graph Analytics
    Deep analytics engine built from millions of data points about vulnerabilities, assets, and hacker skill sets to drive insights, recommendations, and AI models.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    92 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    73%
    22%
    4%
    1%
    0%
    3 AWS reviews
    |
    89 external reviews
    External reviews are from G2  and PeerSpot .
    Lior A.

    Strengthens Security and Streamlines Issue Management

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate H1 Platform for allowing me to get reports and awareness of issues way earlier than when we notice them. This feature helps prevent attacks by raising security concerns before they become problems, extending our ongoing testing. It also enables me to understand reports faster and respond more professionally to researchers submitting tickets. I find the integration with tools like Claude very useful for getting an overview of all my tickets, prioritizing them, and resolving them more effectively. The integration with other platforms, like Confluence and Slack, helps manage vulnerabilities, provides useful statistics, and facilitates communication through alert channels.
    What do you dislike about the product?
    We had a few challenges at the beginning because a lot of our assets were on prem and inside our VPN, so the integration to Confluence wasn't as intuitive. We had a lot of problems with that specifically.
    What problems is the product solving and how is that benefiting you?
    I use H1 Platform to harden security, get reports, and identify issues early. It prevents attacks and raises security concerns, extending our testing.
    Information Services

    Great bug bounty platform. Diverse researchers, good UI, strong integrations, excellent support

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    HackerOne is a great bug bounty platform. The UI is clean and generally easy to use. It has all the integrations we need to connect to our other systems. Support is excellent, both our dedicated CSM and the agents that have helped us with miscellaneous support tickets. The AI features have drastically improved in the last 6 months and it's getting better every week.

    We've gotten very good value from having hundreds of additional eyes on our product, submitting many (and varied) vulnerabilities, and then of course remediating those and the resulting internal discussions on secure coding, secure architecture, and so on.
    What do you dislike about the product?
    The biggest pain point is when videos are submitted as part of bug bounty reports. The loading is slow or sometimes the video does not play at all. Often a hard refresh of the page is required but that does not always fix it and it can be annoying to scroll back down to the video (also related to next point).

    It's also easy to drown in information on a given report (huge report, tons of information, perhaps comments with additional screenshots, videos, walls of text, etc.). All of it is presented at once and the vertical scrolling space can be huge—there is potential to improve UX via presenting information better or perhaps using toggles or similar.
    What problems is the product solving and how is that benefiting you?
    The core problem is faster software development and the resulting vulnerabilities that other, internal security controls can miss. H1 is helping us with this by getting external researchers with a different perspective to look at our platform and finding vulnerabilities.
    Cong N.

    User-Friendly Platform That Decreased Our Response Time

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    The platform is user-friendly and easy to navigate. HAI has definitely helped, as it has decreased our response time.
    What do you dislike about the product?
    I’m pretty happy with the platform right now.
    What problems is the product solving and how is that benefiting you?
    H1 is able to validate findings and provide recommendations or fixes when requested.
    Computer Software

    HAI AI Assistant Makes Reports Easier and Replies Faster

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    Its AI assistant HAI. Its helpful in understanding reports as well generate replies faster.
    What do you dislike about the product?
    Sometimes reports takes too long to load or stuck on blank page.
    What problems is the product solving and how is that benefiting you?
    Fiction between customer and hackers.
    Manufacturing

    Easy to Use and Great for Building a Researcher Community

    Reviewed on Aug 12, 2026
    Review provided by G2
    What do you like best about the product?
    Ease of use and the ability the build a community with a group of experienced researchers
    What do you dislike about the product?
    Triage has been lacking recently but that is due to the influx of AI reports.
    What problems is the product solving and how is that benefiting you?
    The triage process is due to change for the better soon which will benefit us by having reports validated at a faster pace.
    View all reviews