HackerOne

HackerOne supports vulnerability disclosure programs and bug bounty programs with defined researcher rules.

Visit official website

Published Updated

CategoryVulnerability Management
AccessSee vendor
PricingFreemium
APIAvailable
Overview

What is HackerOne?

HackerOne's documentation distinguishes vulnerability disclosure programs from bug bounty programs. Both require a clear scope and response process; a bounty adds reward rules. Public and private program settings can differ.

Read the full overview

Sources checked 27 September 2026: Program types, Disclosure guidelines.

Why teams use it

Key capabilities

  • Program setup: Define eligible assets and reporting terms.
  • Report handling: Receive and triage researcher findings.
  • Coordination: Track remediation and disclosure decisions.
Core areas

Vulnerability intake and researcher coordination are the core product functions.

Positioning

Use HackerOne when an organization is prepared to receive, triage and resolve external security reports. Write the scope, safe-harbor language and internal ownership before inviting submissions.

Why it matters

The program's quality depends on timely, consistent treatment of a valid report, not simply publishing a bounty page.

Deployment & technical details

Technical details

Access
See vendor
Source model
Other license
Founded
2012
Headquarters
San Francisco, California, USA
Pricing model
Freemium
API
Available
Check with the publisher

Official resources

Before you shortlist

What to verify for your environment

Start from the users, systems and operating responsibilities the tool needs to support.

  • Confirm current features, licensing and support terms with the publisher.
  • Validate deployment, data location, access control, backup and recovery requirements.
  • Test integrations, export paths and a representative operational workflow before committing.
Community experience

Reviews of HackerOne

No published reviews yet.

Loading review form…