What is HackerOne?
HackerOne's documentation distinguishes vulnerability disclosure programs from bug bounty programs. Both require a clear scope and response process; a bounty adds reward rules. Public and private program settings can differ.
Read the full overview
Sources checked 27 September 2026: Program types, Disclosure guidelines.
Key capabilities
- Program setup: Define eligible assets and reporting terms.
- Report handling: Receive and triage researcher findings.
- Coordination: Track remediation and disclosure decisions.
Vulnerability intake and researcher coordination are the core product functions.
Use HackerOne when an organization is prepared to receive, triage and resolve external security reports. Write the scope, safe-harbor language and internal ownership before inviting submissions.
The program's quality depends on timely, consistent treatment of a valid report, not simply publishing a bounty page.
Technical details
- Access
- See vendor
- Source model
- Other license
- Founded
- 2012
- Headquarters
- San Francisco, California, USA
- Pricing model
- Freemium
- API
- Available
- Website
- www.hackerone.com ↗
Official resources
What to verify for your environment
Start from the users, systems and operating responsibilities the tool needs to support.
- Confirm current features, licensing and support terms with the publisher.
- Validate deployment, data location, access control, backup and recovery requirements.
- Test integrations, export paths and a representative operational workflow before committing.
ITHub profiles are discovery summaries. Read how product information is presented or report a correction.
Reviews of HackerOne
No published reviews yet.
Loading review form…