Listing Thumbnail

    HackerOne

     Info
    Sold by: HackerOne 
    Deployed on AWS
    HackerOne is the global leader in human-powered security, harnessing the creativity of the world's largest community of security researchers with cutting-edge AI to protect your digital assets. The H1 Platform combines the expertise of our elite community and the most up-to-date vulnerability database to pinpoint critical security flaws across your attack surface. Our integrated solutions, including H1 Bug Bounty, H1 Pentesting, code security audits, spot checks, and AI red teaming, ensure continuous vulnerability discovery and management throughout the software development lifecycle. Trusted by industry leaders such as Coinbase, General Motors, GitHub, Goldman Sachs, Hyatt, PayPal, Snap Inc, and the U.S. Department of Defense, HackerOne was named a Best Workplace for Innovators by Fast Company in 2023 and a Most Loved Workplace for Young Professionals in 2024.
    4.5

    Overview

    Play video

    The H1 Platform is the leading solution for combining human-powered security testing with advanced AI to safeguard your digital assets. Our platform provides an integrated suite of security solutions that ensure continuous vulnerability discovery and management throughout the software development life cycle. By harnessing the strengths of the world's largest community of security researchers and the latest AI technologies, HackerOne helps organizations reduce their threat exposure and transform their businesses with confidence.

    For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@hackerone.com , for a private offer.

    H1 Response

    • Leading Vulnerability Disclosure Program (VDP) platform
    • Streamlines third-party vulnerability reporting
    • Integrates with 20+ SDLC systems
    • Ensures compliance and collaboration

    H1 Pentest

    • Methodology-driven security testing
    • SaaS-based delivery model
    • Curated elite pentester teams
    • End-to-end testing process

    H1 Code Security Audit

    • Premium code review service
    • 600+ vetted senior software engineers
    • Deep source code analysis
    • Early-stage vulnerability detection

    H1 Bounty

    • Continuous security testing
    • The global ethical hacker community
    • Performance-based rewards
    • Scales with business needs

    H1 AI Red Teaming

    • Specialized AI system testing
    • Expert security advisory support
    • Identifies AI-specific vulnerabilities
    • Mitigates model risks and biases

    H1 Challenge

    • Time-bound security testing sprints
    • Targeted vulnerability discovery
    • Ideal for new releases
    • Flexible engagement model

    Streamlined integrations and automation: HackerOne offers robust APIs and built-in integrations and automation, simplifying vulnerability management and streamlining workflows.

    Managing different programs within our AI-powered platform provides unprecedented insights into your security program's effectiveness while offering the efficiency and ease of a single interface.

    Together, these integrated solutions provide indispensable capabilities for organizations. They ensure that vulnerabilities are continuously identified, prioritized, and remediated, providing unmatched protection from code to the cloud.

    Learn more about each one of our offerings designed to address specific security challenges with our Defense-in-Depth strategy at https://www.hackerone.com/product/overview 

    Highlights

    • The H1 Platform continuously discovers, validates, prioritizes, and remediates to reduce exposure debt before attackers act. Hai scores and validates at machine speed while a community of elite security researchers surfaces business logic flaws and novel attack chains no automated tool reaches. Confirmed findings route directly into Jira, GitHub, ServiceNow, Azure DevOps, Slack, and Teams through 30+ integrations.
    • Hai, HackerOne's agentic AI orchestrator, handles thousands of reports per week at 95% accuracy, improving signal by 40%, and reduces prioritization decisions from hours to seconds. H1 Remediation delivers source code-informed, developer-ready fix plans into your issue tracking tools in one click, or directly to an AI coding agent via MCP. Retests confirm fixes hold. Regression monitoring ensures they stay closed.
    • Managing all programs within the H1 Platform gives security leaders a unified view of exposure across the full attack surface. Cross-program dashboards track exposure velocity, remediation speed, and signal quality. Self-serve Return on Mitigation quantifies program value as avoided financial loss, with $32B+ in risk exposure mitigated for customers to date.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    HackerOne Platform
    Proven human-powered security testing, enhanced by AI
    $500,000.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    Rewards overage fee
    $0.01

    AI Insights

     Info

    Dimensions summary

    This contract listing has two pricing dimensions that work together. You commit to the HackerOne Platform, which delivers human-powered security testing supported by AI. This is the core subscription you buy for a fixed term. The Rewards overage fee is a usage-based add-on. It applies when the rewards you pay to security researchers exceed your committed amount. So one dimension covers your base platform access, while the other charges only if reward payouts run past your commitment. Your total cost scales with how much you pay out in researcher rewards.

    Top-of-mind questions for buyers

    Rewards are the payments you make to security researchers for valid vulnerabilities they find. Your committed amount covers a set pool of these payouts. The overage fee applies only once your actual reward payments pass that committed pool. It charges the amount that runs beyond your commitment.
    The Platform dimension covers your subscription to the security testing service. This includes access to a community of security researchers, AI-assisted triage and validation, vulnerability report management, dashboards, and integrations with your existing tools. Researcher reward payouts are billed separately through the Rewards overage fee, not within this dimension.
    Both dimensions bill together on the same contract. The HackerOne Platform is a fixed subscription for your term. The Rewards overage fee grows only when researcher payouts pass your committed pool. Programs that surface many valid vulnerabilities see the overage fee become the variable part of the bill.
    www.hackerone.com+1
    Helpful?

    Vendor refund policy

    There are no refund options available.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    To ensure that you receive timely assistance, it's important to be aware of our Support & Mediation team's business hours. This documentation details when our Support Team is available, how to reach them, and additional resources for self-help outside of these hours.

    Support Team Operating Hours Our dedicated Support team is available to assist you during the following hours:

    Monday to Friday: Mediation (Customers)

    8:00am - 5:00pm PT

    Support

    12:00am-4:30pm PT

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Observability, Testing
    Top
    10
    In Assessments
    Top
    50
    In Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    13 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Vulnerability Discovery and Validation
    Continuous discovery, validation, prioritization, and remediation of vulnerabilities across the full attack surface using human-powered security researchers combined with AI-powered analysis
    AI-Powered Triage and Prioritization
    Hai agentic AI orchestrator processes thousands of reports weekly at 95% accuracy, improves signal by 40%, and reduces prioritization decisions from hours to seconds
    Automated Remediation and Fix Generation
    Source code-informed, developer-ready fix plans generated automatically into issue tracking tools or directly to AI coding agents via MCP, with automated retests and regression monitoring
    Unified Security Program Management
    Centralized platform providing cross-program dashboards that track exposure velocity, remediation speed, signal quality, and quantify program value through Return on Mitigation metrics
    Penetration Testing Service
    Penetration Testing as a Service (PTaaS) platform combining security professionals with AI and automation, delivering 50+ pentest types with streamlined workflows and accelerated remediation.
    Attack Surface Management
    Continuous visibility into internal and external attack surfaces with capabilities to discover unknown assets, identify exposure gaps, and prioritize remediation based on real-world risk contextualization.
    Red Team and Adversary Simulation
    Red team engagements simulating real-world adversaries that chain vulnerabilities across identity, application, cloud, and infrastructure layers to demonstrate breach scenarios and measure detection effectiveness.
    Specialized Security Teams
    Dedicated teams specializing in application, cloud, infrastructure, identity, and mainframe security assessments with proprietary testing frameworks and tooling.
    AI-Accelerated Security Workflows
    AI-accelerated platform enabling critical security workflows with use case-driven experience to move from findings to fixes faster through automated processes.
    AI-Powered Researcher Sourcing
    Platform uses data and AI to source and activate security researchers and pentesters across multiple dimensions for continuous vulnerability discovery.
    Penetration Testing as a Service
    Modern PTaaS suite enabling rapid pen test launches against any target within days with prioritized findings dashboard and DevSec workflow integration.
    Automated Triage and Noise Reduction
    Core triage competency that rapidly removes false positives and adds context for prioritization, handling critical vulnerabilities within a single day.
    Vulnerability Disclosure Program Management
    Managed VDP solution providing intake channels, validation, triage, researcher relations, SDLC integration, and reporting for public vulnerability submissions.
    Security Knowledge Graph Analytics
    Deep analytics engine built on millions of data points about vulnerabilities, assets, and hacker skill sets to drive insights, recommendations, and AI models.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    111 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    70%
    25%
    4%
    1%
    0%
    3 AWS reviews
    |
    108 external reviews
    External reviews are from G2  and PeerSpot .
    Win G.

    Easy-to-Run Pen Tests and High-Value Bug Bounties with H1

    Reviewed on Sep 29, 2026
    Review provided by G2
    What do you like best about the product?
    Over the last year, we’ve run a few different programs with H1. One of those was a penetration test to validate new security controls for our login interface. The pen test program was easy to set up, straightforward to pay for, and it was simple to communicate with the researchers assigned to the engagement.

    We also get a lot of value from our bug bounty program, which helps us surface some of our most critical, previously overlooked vulnerabilities.
    What do you dislike about the product?
    The interface can be confusing at times, depending on which program you’re viewing. Until recently, my biggest frustration with the H1 platform was the billing structure around system tiers and committed spend for paying out vulnerabilities. Even if we went just one dollar over, we would have been forced to upgrade to the next tier. On top of that, we couldn’t integrate our SIEM with hackerone because we didn’t have the enterprise tier. This has since been addressed with the new billing plan.
    What problems is the product solving and how is that benefiting you?
    H1 is an extension of the subject-matter expertise within our organization. We can only protect ourselves from what we already know, and HackerOne helps us identify and better understand the unknowns. The initial triage that HackerOne performs before we validate an issue has been extremely helpful for determining whether a report is legitimate.
    Nicola F.

    Intuitive Day-to-Day Use with Strong Triage Tools and a Well-Documented API

    Reviewed on Sep 29, 2026
    Review provided by G2
    What do you like best about the product?
    My day-to-day experience using it is good and intuitive. They offer a lot of tools that help with triage, and the API is very good and very well documented.
    What do you dislike about the product?
    In some cases, the way the organization and the program are presented can be quite confusing, but overall it’s all good.
    What problems is the product solving and how is that benefiting you?
    Well, obviously it detects things that our internal team didn’t see, and it helps our H1 triage team review issues as an extra pair of eyes.
    Antonio C.

    Smooth, Streamlined UI for Receiving, Reviewing, and Awarding Reports

    Reviewed on Sep 28, 2026
    Review provided by G2
    What do you like best about the product?
    The UI workflow for receiving, reviewing, triaging, and awarding reports is great and runs smoothly.
    What do you dislike about the product?
    The multi-program management workflow feels weak. It lacks bulk actions and program-scoped automation, which makes managing multiple programs more difficult than it should be.
    What problems is the product solving and how is that benefiting you?
    A vulnerability inbox for external researchers who want to securely report sensitive information.
    Cosmetics

    A Solid Platform for Bug Bounty Programs

    Reviewed on Sep 25, 2026
    Review provided by G2
    What do you like best about the product?
    The best part for me is how much operational effort the platform takes off our plate. Having access to a large and skilled pool of researchers, combined with reliable triage, means we receive findings that are relevant and actionable. The relationship with the HackerOne team also stands out, especially Andrea Griffin, who consistently goes above and beyond to support us and make sure the program keeps evolving.
    What do you dislike about the product?
    If I had to point out one thing, it would be the occasional delays in triage. Still, it's fair to say this reflects a broader trend across bug bounty platforms, with the surge of AI-assisted submissions putting pressure on every triage team. I'm confident HackerOne is aware of it, and any improvements in how these reports are filtered and prioritized would make a real difference for us.
    What problems is the product solving and how is that benefiting you?
    The platform addresses a key challenge for us: keeping our applications under constant, real-world security testing without having to scale the internal team at the same pace. By connecting us with skilled researchers and handling triage and program management, HackerOne lets us find and fix vulnerabilities faster and with less friction. This has strengthened our overall security posture, improved collaboration with our development teams around remediation, and given leadership greater visibility into the risks we are actually facing.
    Goodness Caleb I.

    API-Driven Findings and Easy Bounty Budget Tracking

    Reviewed on Sep 23, 2026
    Review provided by G2
    What do you like best about the product?
    As an engineer, I really appreciate the API availability. It lets me pull findings via the API and feed them into triage agents, which helps me develop fixes for those findings more efficiently. I also like that H1 helps me track my bounty budget and related expenses.
    What do you dislike about the product?
    There needs to be a more structured approach, with clear terms, for researchers who request higher payouts. Also, when researchers submit findings, HackerOne should flag possible duplicates. It doesn’t have to show the full details of those duplicates, but it should at least indicate that a similar report has already been submitted.
    What problems is the product solving and how is that benefiting you?
    H1 is helping us maintain a more continuous approach to testing and reviewing our systems, since vulnerabilities can be detected at any time. This is a big improvement over relying only on scheduled pentests, which can leave you blind until the next cycle.
    View all reviews