Listing Thumbnail

    HackerOne

     Info
    Sold by: HackerOne 
    Deployed on AWS
    HackerOne is the global leader in human-powered security, harnessing the creativity of the world's largest community of security researchers with cutting-edge AI to protect your digital assets. The H1 Platform combines the expertise of our elite community and the most up-to-date vulnerability database to pinpoint critical security flaws across your attack surface. Our integrated solutions, including H1 Bug Bounty, H1 Pentesting, code security audits, spot checks, and AI red teaming, ensure continuous vulnerability discovery and management throughout the software development lifecycle. Trusted by industry leaders such as Coinbase, General Motors, GitHub, Goldman Sachs, Hyatt, PayPal, Snap Inc, and the U.S. Department of Defense, HackerOne was named a Best Workplace for Innovators by Fast Company in 2023 and a Most Loved Workplace for Young Professionals in 2024.
    4.5

    Overview

    Play video

    The H1 Platform is the leading solution for combining human-powered security testing with advanced AI to safeguard your digital assets. Our platform provides an integrated suite of security solutions that ensure continuous vulnerability discovery and management throughout the software development life cycle. By harnessing the strengths of the world's largest community of security researchers and the latest AI technologies, HackerOne helps organizations reduce their threat exposure and transform their businesses with confidence.

    For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@hackerone.com , for a private offer.

    H1 Response

    • Leading Vulnerability Disclosure Program (VDP) platform
    • Streamlines third-party vulnerability reporting
    • Integrates with 20+ SDLC systems
    • Ensures compliance and collaboration

    H1 Pentest

    • Methodology-driven security testing
    • SaaS-based delivery model
    • Curated elite pentester teams
    • End-to-end testing process

    H1 Code Security Audit

    • Premium code review service
    • 600+ vetted senior software engineers
    • Deep source code analysis
    • Early-stage vulnerability detection

    H1 Bounty

    • Continuous security testing
    • The global ethical hacker community
    • Performance-based rewards
    • Scales with business needs

    H1 AI Red Teaming

    • Specialized AI system testing
    • Expert security advisory support
    • Identifies AI-specific vulnerabilities
    • Mitigates model risks and biases

    H1 Challenge

    • Time-bound security testing sprints
    • Targeted vulnerability discovery
    • Ideal for new releases
    • Flexible engagement model

    Streamlined integrations and automation: HackerOne offers robust APIs and built-in integrations and automation, simplifying vulnerability management and streamlining workflows.

    Managing different programs within our AI-powered platform provides unprecedented insights into your security program's effectiveness while offering the efficiency and ease of a single interface.

    Together, these integrated solutions provide indispensable capabilities for organizations. They ensure that vulnerabilities are continuously identified, prioritized, and remediated, providing unmatched protection from code to the cloud.

    Learn more about each one of our offerings designed to address specific security challenges with our Defense-in-Depth strategy at https://www.hackerone.com/product/overview 

    Highlights

    • The H1 Platform continuously discovers, validates, prioritizes, and remediates to reduce exposure debt before attackers act. Hai scores and validates at machine speed while a community of elite security researchers surfaces business logic flaws and novel attack chains no automated tool reaches. Confirmed findings route directly into Jira, GitHub, ServiceNow, Azure DevOps, Slack, and Teams through 30+ integrations.
    • Hai, HackerOne's agentic AI orchestrator, handles thousands of reports per week at 95% accuracy, improving signal by 40%, and reduces prioritization decisions from hours to seconds. H1 Remediation delivers source code-informed, developer-ready fix plans into your issue tracking tools in one click, or directly to an AI coding agent via MCP. Retests confirm fixes hold. Regression monitoring ensures they stay closed.
    • Managing all programs within the H1 Platform gives security leaders a unified view of exposure across the full attack surface. Cross-program dashboards track exposure velocity, remediation speed, and signal quality. Self-serve Return on Mitigation quantifies program value as avoided financial loss, with $32B+ in risk exposure mitigated for customers to date.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    HackerOne Platform
    Proven human-powered security testing, enhanced by AI
    $500,000.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    Rewards overage fee
    $0.01

    AI Insights

     Info

    Dimensions summary

    This contract listing has two pricing dimensions that work together. You commit to the HackerOne Platform, which delivers human-powered security testing supported by AI. This is the core subscription you buy for a fixed term. The Rewards overage fee is a usage-based add-on. It applies when the rewards you pay to security researchers exceed your committed amount. So one dimension covers your base platform access, while the other charges only if reward payouts run past your commitment. Your total cost scales with how much you pay out in researcher rewards.

    Top-of-mind questions for buyers

    Rewards are the payments you make to security researchers for valid vulnerabilities they find. Your committed amount covers a set pool of these payouts. The overage fee applies only once your actual reward payments pass that committed pool. It charges the amount that runs beyond your commitment.
    The Platform dimension covers your subscription to the security testing service. This includes access to a community of security researchers, AI-assisted triage and validation, vulnerability report management, dashboards, and integrations with your existing tools. Researcher reward payouts are billed separately through the Rewards overage fee, not within this dimension.
    Both dimensions bill together on the same contract. The HackerOne Platform is a fixed subscription for your term. The Rewards overage fee grows only when researcher payouts pass your committed pool. Programs that surface many valid vulnerabilities see the overage fee become the variable part of the bill.
    www.hackerone.com+1
    Helpful?

    Vendor refund policy

    There are no refund options available.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    To ensure that you receive timely assistance, it's important to be aware of our Support & Mediation team's business hours. This documentation details when our Support Team is available, how to reach them, and additional resources for self-help outside of these hours.

    Support Team Operating Hours Our dedicated Support team is available to assist you during the following hours:

    Monday to Friday: Mediation (Customers)

    8:00am - 5:00pm PT

    Support

    12:00am-4:30pm PT

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Observability, Testing
    Top
    10
    In Assessments
    Top
    50
    In Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    13 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Vulnerability Discovery and Validation
    Continuous discovery, validation, prioritization, and remediation of vulnerabilities across the full attack surface using human-powered security researchers combined with AI-powered analysis
    AI-Powered Triage and Prioritization
    Hai agentic AI orchestrator processes thousands of reports weekly at 95% accuracy, improves signal by 40%, and reduces prioritization decisions from hours to seconds
    Automated Remediation and Fix Generation
    Source code-informed, developer-ready fix plans generated automatically into issue tracking tools or directly to AI coding agents via MCP, with automated retests and regression monitoring
    Unified Security Program Management
    Centralized platform providing cross-program dashboards that track exposure velocity, remediation speed, signal quality, and quantify program value through Return on Mitigation metrics
    Penetration Testing Service
    Penetration Testing as a Service (PTaaS) platform combining security professionals with AI and automation, delivering 50+ pentest types with streamlined workflows and accelerated remediation.
    Attack Surface Management
    Continuous visibility into internal and external attack surfaces with capabilities to discover unknown assets, identify exposure gaps, and prioritize remediation based on real-world risk contextualization.
    Red Team and Adversary Simulation
    Red team engagements simulating real-world adversaries that chain vulnerabilities across identity, application, cloud, and infrastructure layers to demonstrate breach scenarios and measure detection effectiveness.
    Specialized Security Teams
    Dedicated teams specializing in application, cloud, infrastructure, identity, and mainframe security assessments with proprietary testing frameworks and tooling.
    AI-Accelerated Security Workflows
    AI-accelerated platform enabling critical security workflows with use case-driven experience to move from findings to fixes faster through automated processes.
    AI-Powered Researcher Sourcing
    Platform uses data and AI to source and activate security researchers and pentesters across multiple dimensions for continuous vulnerability discovery.
    Penetration Testing as a Service
    Modern PTaaS suite enabling rapid pen test launches against any target within days with prioritized findings dashboard and DevSec workflow integration.
    Automated Triage and Noise Reduction
    Core triage competency that rapidly removes false positives and adds context for prioritization, handling critical vulnerabilities within a single day.
    Vulnerability Disclosure Program Management
    Managed VDP solution providing intake channels, validation, triage, researcher relations, SDLC integration, and reporting for public vulnerability submissions.
    Security Knowledge Graph Analytics
    Deep analytics engine built on millions of data points about vulnerabilities, assets, and hacker skill sets to drive insights, recommendations, and AI models.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    106 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    70%
    25%
    4%
    1%
    0%
    3 AWS reviews
    |
    103 external reviews
    External reviews are from G2  and PeerSpot .
    Anshul O.

    Easy to Use, Packed with Qualified Researchers and New Integrations

    Reviewed on Sep 11, 2026
    Review provided by G2
    What do you like best about the product?
    It’s easy to use, and it offers numerous qualified researchers, along with new integrations and tools.
    What do you dislike about the product?
    The report staging system felt a bit complex to understand at first, and it took me some time to get familiar with how it works.
    What problems is the product solving and how is that benefiting you?
    Getting valuable security reports from well-qualified researchers, along with a third-person perspective on security.
    Rachel R.

    Hai Makes Complex Reports Easy

    Reviewed on Sep 10, 2026
    Review provided by G2
    What do you like best about the product?
    I've grown to love Hai! It's very helpful when receiving complex reports.
    What do you dislike about the product?
    The platform can be buggy at times, especially when I’m navigating between our public program and our private program. I also find it difficult to locate certain areas in the UI because there are so many different sections, which can make things feel a bit hard to track down.
    What problems is the product solving and how is that benefiting you?
    It’s been helping us close gaps in our attack surface. Being able to share findings with teams—along with proof that an issue is actually exploitable—makes it much easier to prioritize and get the finding addressed ASAP.
    Hospitality

    Strengthened Our Security by Finding Critical Bugs

    Reviewed on Sep 10, 2026
    Review provided by G2
    What do you like best about the product?
    The bugs we find have greatly helped strengthen the security of our environment.
    What do you dislike about the product?
    Sometimes the reports can be a bit difficult to to decipher
    What problems is the product solving and how is that benefiting you?
    It is finding the bugs in our applications that our devs aren't paying attention to.
    Rachelle W.

    H1 Identifies Vulnerabilities or Flaws Before a Threat Actor Exploits It

    Reviewed on Sep 10, 2026
    Review provided by G2
    What do you like best about the product?
    The H1 platform helps us keep track of our researchers’ findings.
    What do you dislike about the product?
    The platform’s navigation makes it difficult to find things if you’re not a regular user.
    What problems is the product solving and how is that benefiting you?
    The H1 platform helps us to identify vulnerabilities that we may not have known about otherwise.
    Diego T.

    Powerful KPI & Metrics Extraction from MCP and APIs

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    Recently, the ability to extract KPIs and metrics from your MCP and APIs has been quite useful. Automatically obtaining critical insights is a big differentiator.
    What do you dislike about the product?
    Sometimes the notifications create a lot of unnecessary noise, which can be distracting.
    What problems is the product solving and how is that benefiting you?
    It shows real types of attacks and vulnerabilities that are detected by other tools, but due to a business decision they are exempted.
    View all reviews