Fundraising Fox

Hackerone

also invests · investor profile

San Francisco, US · 10 known investors

HackerOne operates a platform for coordinating cybersecurity vulnerability disclosures and bug bounty programs. The company connects security researchers with organizations to identify and remediate security vulnerabilities.

Also known as H1 · HackerOne Inc.

Founders & leadership

MMMårten Mickos
Mårten MickosinFounder

Investors · 10

Also in the syndicate · 4

Drew HoustonJeremy StoppelmanNew Enterprise AssociatesYuri Milner

Company profile

researched Sep 2026

HackerOne Inc. is a San Francisco-headquartered cybersecurity company that operates a platform pairing a global community of security researchers with software and AI tooling to find, validate and remediate vulnerabilities. It was among the first companies to build a business model around crowd-sourced security, pioneering bug bounty programs and coordinated vulnerability disclosure. Organizations run public or private programs on the platform; researchers submit vulnerability reports, which are triaged and, where valid, rewarded with bounties.

The current product set is marketed as the H1 Platform, positioned around Continuous Threat Exposure Management (CTEM) spanning discovery, validation, prioritization and remediation. Components include H1 Bounty, H1 Agentic Pentest, H1 Continuous Testing, H1 Remediation, H1 Validation and H1 AI Red Teaming (adversarial testing of AI systems mapped to the OWASP LLM Top 10, MITRE ATLAS and the NIST AI RMF), all coordinated by an agentic AI orchestrator called Hai. The company also maintains free and community-facing offerings: a Community Edition giving eligible open source projects free access to the platform for vulnerability submission, and founding membership in the Internet Bug Bounty, a bug bounty program for core internet infrastructure and open source projects funded early on by Microsoft and Facebook. Educational and competitive resources for researchers include the Hacker101 CTF, a program directory, Hacktivity disclosure feeds, reputation and leaderboard systems, and the vetted HackerOne Clear community.

Cited customers over time include the U.S. Department of Defense, U.S. Department of State, General Motors, GitHub, Goldman Sachs, Google, Hyatt, Lufthansa, Microsoft, MINDEF Singapore, Nintendo, PayPal, Slack, Starbucks, Twitter, Yahoo, Dropbox, Shopify and Snap. HackerOne maintains a trust center listing certifications and compliance frameworks including SOC 2 Type 2, ISO 27001, PCI DSS, FedRAMP, GDPR, CCPA, UK Cyber Essentials Plus, and the ISO 29147 and ISO 30111 vulnerability handling standards.

Founding story

In 2011, Dutch hackers Jobert Abma and Michiel Prins set out to find security vulnerabilities in 100 prominent high-tech companies, an effort they called the "Hack 100"; they found flaws in all of them, including Facebook, Google, Apple, Microsoft and Twitter. Many firms ignored their disclosures, but Facebook COO Sheryl Sandberg passed the warning to head of product security Alex Rice. Rice, Abma and Prins connected and, together with Merijn Terheggen, founded HackerOne in 2012. According to co-founder Jobert Abma, the founders moved the business to San Francisco because ambitious funding was easier to secure there; Amsterdam investors were prepared to put in only $2.5 million, whereas the company raised $9 million in its first round in the US.

Business model

HackerOne sells access to its platform and to a vetted researcher community to enterprise and government customers, which fund bug bounty programs, pentests, continuous testing, AI red teaming and remediation workflows. Researchers are paid bounties by customer organizations for valid vulnerability reports, and can also earn stipends for pentest engagements (advertised at up to $5,000 per engagement). Eligible open source projects can use a free Community Edition.

Revenue derives from customer-side subscriptions and services for the H1 Platform's bounty, pentesting, continuous testing, validation, remediation and AI red teaming offerings, with bounty payments flowing from customers to researchers through the platform.

Traction

Public figures include more than $380 million rewarded to researchers and over 1,000 active bug bounty programs on the community site; more than $230 million in bounties paid as of December 2022; over 600,000 bugs found; 1,300+ companies using the platform; and 90% of customers with the Hai AI agent enabled. In the 12 months preceding January 2022 the company said it identified over 17,000 high or critical vulnerabilities for customers, and in the first month after Log4j 612 hackers submitted 2,175 potential vulnerabilities to HackerOne customers. The company reports a 210% increase in AI vulnerability reports in 2025 and states that 25% of findings are actionable.

Latest developments

Current positioning centers on Continuous Threat Exposure Management and AI security, with the Hai agentic orchestrator, H1 Agentic Pentest, H1 Continuous Testing and H1 AI Red Teaming, plus customer deployments such as Snap's use of AI red teaming and Shopify's reported 62% acceleration in validation and triage. Recent publications include the 9th annual Hacker-Powered Security Report and a "Closing the AI Security Gap" research report. Naveen Bhateja has been appointed Chief People Officer.

Full profile — market position, technology, go-to-market, geography, history, risks & controversies

Market position

HackerOne describes itself as a category leader in hacker-powered security and, more recently, in continuous threat exposure management; it was one of the first companies to commercialize crowd-sourced security. It reported over 1,500 customers and more than 500,000 hackers at the time of its 2019 Series D, and currently cites 1,300+ companies on the platform. It was named a Fast Company "brand that matters" and ranked fifth on Fast Company's World's Most Innovative Companies list for 2020.

The company positions its combination of a large vetted researcher community, agentic AI (Hai) and a single connected platform covering discovery through remediation as capabilities competitors do not bring together, arguing human researchers find issues automation misses while AI compresses triage and prioritization time.

Technology

The platform links vulnerability discovery, validation, prioritization and remediation in a single workflow. Hai, an agentic AI orchestrator, coordinates agents across stages, scoring and validating findings continuously. H1 Validation is marketed at 95% accuracy in confirming exploitability with a 40% signal improvement; H1 Remediation produces source code-informed fix plans delivered to engineering in one click; H1 AI Red Teaming performs adversarial testing of AI systems and models mapped to OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF. Human researchers supply findings automation does not reach, such as novel attack chains and business logic flaws.

Go-to-market

Direct enterprise sales supported by customer stories, research publications such as the annual Hacker-Powered Security Report and the "Closing the AI Security Gap" report, live hacking events and conferences, a public program directory, and community programs (Hacker101 CTF, leaderboards, Clear researcher tier, community partner discounts) that attract and retain researchers. A free Community Edition for open source projects and founding participation in the Internet Bug Bounty support ecosystem visibility.

Large enterprises and public sector bodies with significant digital attack surface, including technology, e-commerce, financial services, automotive, travel and defense/government organizations; the platform also serves security researchers as a second user base.

Geography

Headquartered in San Francisco, California, with an engineering office in Groningen and offices opened in London and Paris; additional European offices were added following 240% year-over-year European customer growth reported in 2017. Live hacking events have been held across the US and Asia, and customers include government agencies in the US, UK and Singapore.

History

Founded in 2012, HackerOne hosted a program in November 2013 encouraging discovery and responsible disclosure of software bugs, funded by Microsoft and Facebook, which became the Internet Bug Bounty project. By June 2015 its platform had identified roughly 10,000 vulnerabilities and paid over $1 million in bounties, and in September 2015 it launched a Vulnerability Coordination Maturity Model. Merijn Terheggen stepped down as CEO in November 2015 and was replaced by Mårten Mickos. In March 2016 the U.S. Department of Defense launched "Hack the Pentagon" on the platform, a 24-day program that surfaced 138 vulnerabilities and paid over $70,000 in bounties; follow-on DoD initiatives included the first U.S. government Vulnerability Disclosure Policy and "Hack the Army" (118 valid reports, 371 participants, about $100,000 awarded) and, in May 2017, "Hack the Air Force" (207 vulnerabilities, more than $130,000 in bounties). In August 2022, Defense Digital and the U.S. Air Force ran a "Hack the Satellite" live event. The company reported 240% year-over-year European customer growth in April 2017 and opened additional European offices; it hosted live hacking events in the US and Asia and its first Security@ conference in San Francisco in October 2017. It acquired code-review-as-a-service platform PullRequest in April 2022. Kara Sprague is listed as CEO in current reference material.

Risks & controversies

The company's Wikipedia entry carries a notice that the article may have been created or edited in return for undisclosed payments, in violation of Wikipedia's terms of use, and may require cleanup for neutrality.

Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Active bug bounty programsJan 20261,000 programs
Bugs foundJan 2026600,000 bugs
Companies using the platformJan 20261,300 companies
Cumulative bounties paid by customersJan 2019$65M
CustomersJan 20191,500 customers
Customers with Hai AI agent enabledJan 202690%
High or critical vulnerabilities identified for customers in prior 12 monthsJan 202217,000 vulnerabilities
Increase in AI vulnerability reportsJan 2025210%
Registered hackersJan 2019500,000 hackers
Reported ROI per critical vulnerability found before breachJan 2026$4M
Share of findings that are actionableJan 202625%
Total bounties paid to researchersJan 2026$380M
Total funding raised to dateJan 2022$160M
Validation accuracyJan 202695%
Vulnerabilities identified on platformJun 201510,000 vulnerabilities
Vulnerabilities resolved for customersJan 2019130,000 vulnerabilities

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Founder mafia

5 people who came through Hackerone went on to found or lead other companies.

Competitors · 10

by search overlap
Netezza2480 shared keywordsIBM is a global technology company whose business spans enterprise software (including Red Hat, HashiCorp, and Confluent), IT infrastructure such as mainframes, servers, and storage, and IT consulting services. The company is also investing heavily in quantum computing and AI-based enterprise offerings, including its Lightwell open-source software security clearinghouse and the Anderon quantum wafer foundry.
Sentinel One1830 shared keywordsSentinelOne provides an AI-powered cybersecurity platform for enterprises that integrates endpoint protection, threat detection, and incident response capabilities. The company serves large enterprises, including many Fortune 500 organizations, to protect against cyber threats at scale.
PortSwigger1518 shared keywordsPortSwigger provides Burp Suite DAST, an automated security scanning solution that identifies vulnerabilities in web applications and enterprise application portfolios at scale. The platform serves security teams and organizations seeking to assess and monitor their application attack surface without extensive manual testing.
Check Point Software1505 shared keywordsCheck Point Software Technologies is a cybersecurity company providing security products and solutions. This page is its investor relations section, containing annual reports, SEC filings, financial results, and corporate governance information.
Imperva1483 shared keywordsImperva provides cybersecurity solutions to protect customers from cyberattacks across applications, data, and identities during digital transformation. The company serves enterprise customers including major financial institutions, telecom providers, and Fortune 100 companies.
Crowdstrike1398 shared keywordsCrowdStrike provides an AI-native cybersecurity platform that unifies endpoint, identity, cloud, SaaS, and AI protection to detect and stop breaches for enterprise organizations. It combines automated response with human-led security operations including managed detection and response, threat hunting, and security services.
Palo Alto Networks1381 shared keywordsPalo Alto Networks provides cybersecurity platforms and services to protect organizations' digital infrastructure across cloud, network, and security operations. The company serves enterprise organizations, governments, financial institutions, utilities, and healthcare providers globally.
Hack The Box1372 shared keywordsHack The Box provides hands-on training and simulation platforms for cybersecurity blue teams, including labs, courses, and incident response exercises designed to develop skills in SOC operations, digital forensics, and threat hunting. The platform serves enterprise security teams and organizations seeking to measure and improve their defensive readiness against real-world attacks.
ArrowPoint1324 shared keywordsCisco provides networking, data center, and security technology for enterprises, including infrastructure to run traditional and AI workloads and tools to keep organizations running against cyberattacks and outages. Its platform connects networking devices and monitors security events across corporate networks.
Cloudflare Turnstile1309 shared keywordsCloudflare provides a global cloud network platform delivering security, performance, and development services through sixty-plus integrated services including SASE, application security, and full-stack development infrastructure.

Companies competing with Hackerone for the same Google search keywords, organic and paid, via search-intersection analysis.

Acquisitions · 1

Early investors' stakes continue via these deals
PullRequest

PullRequest was a marketplace and platform for on-demand code review, connecting development teams with expert reviewers who checked pull requests for quality and security issues. Acquired by HackerOne in 2022.

Timeline · 15

launches, deals, and filings
Jan 2026
Naveen Bhateja appointed Chief People Officer

Naveen Bhateja was named Chief People Officer at HackerOne.

source ↗

Aug 2022
Hack the Satellite live hacking event

Defense Digital partnered with the U.S. Air Force at the Air Force Research Laboratory, Lawrence Berkeley National Laboratory and USAG Fort Hunter Liggett for a live hacking event in which participants targeted a satellite.

source ↗

Apr 2022
Acquisition of PullRequest

HackerOne acquired PullRequest, a code-review-as-a-service platform.

source ↗

Jan 2022
Series E of $49 million led by GP Bullhound

HackerOne raised $49 million in a Series E round led by GP Bullhound, bringing total investment to nearly $160 million, to fund R&D and go-to-market expansion.

$49M source ↗

Aug 2021
HackerOne Assessments: Application Pentest for AWS

Launched in August 2021 to address issues in applications deployed on AWS; the company reported rapid uptake.

source ↗

Jan 2020
Ranked fifth on Fast Company World's Most Innovative Companies

HackerOne was ranked fifth on Fast Company's World's Most Innovative Companies list for 2020 and was later named a Fast Company 'brand that matters'.

source ↗

Jan 2019
Series D of $36.4 million led by Valor Equity Partners

HackerOne announced a $36.4 million Series D round, bringing total raised to more than $110 million, to scale enterprise and data-powered offerings, expand global reach and strengthen its hacker community.

$36.4M source ↗

Oct 2017
First Security@ conference held in San Francisco

A 200-attendee event with speakers from the DoD, General Motors, Uber and hackers.

source ↗

May 2017
Hack the Air Force program

The DoD extended its hacker-powered programs to the Air Force, leading to 207 vulnerabilities discovered and more than $130,000 in paid bounties.

source ↗

Apr 2017
European expansion after 240% customer growth

The company announced 240% year-over-year customer growth in Europe and opened additional European offices; it also cited offices in London and Paris alongside its Groningen engineering office.

source ↗

Oct 2016
Hack the Army and first U.S. government Vulnerability Disclosure Policy

DoD created the first U.S. government Vulnerability Disclosure Policy, first used in the Hack the Army initiative, which produced 118 valid vulnerability reports from 371 participants and about $100,000 in awards.

source ↗

Mar 2016
U.S. Department of Defense launches Hack the Pentagon on HackerOne

The 24-day program resulted in discovery and mitigation of 138 vulnerabilities in DoD websites with over $70,000 paid in bounties.

source ↗

Nov 2015
Mårten Mickos replaces Merijn Terheggen as CEO

Co-founder Merijn Terheggen stepped down as CEO and was succeeded by Mårten Mickos.

source ↗

Sep 2015
Vulnerability Coordination Maturity Model launched

The company released a model codifying minimum standards for how organizations handle incoming unsolicited vulnerability reports.

source ↗

Nov 2013
Internet Bug Bounty project launched

HackerOne hosted a program encouraging discovery and responsible disclosure of software bugs, funded by Microsoft and Facebook, known as the Internet Bug Bounty.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

Research sources · 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Hackerone do?
HackerOne runs a crowdsourced security platform combining bug bounty, pentesting and AI agents for continuous threat exposure management.
Who are Hackerone's investors?
Hackerone's investors include 1/1 Capital, Defy Partners, New Enterprise Associates (NEA), Savano Capital Partners, Valor Equity Partners, Benchmark.
Where is Hackerone headquartered?
Hackerone is headquartered in San Francisco, US.