Hackerone
also invests · investor profileSan Francisco, US · 10 known investors
HackerOne operates a platform for coordinating cybersecurity vulnerability disclosures and bug bounty programs. The company connects security researchers with organizations to identify and remediate security vulnerabilities.
Also known as H1 · HackerOne Inc.
Founders & leadership

Investors · 10
Also in the syndicate · 4
Company profile
researched Sep 2026HackerOne Inc. is a San Francisco-headquartered cybersecurity company that operates a platform pairing a global community of security researchers with software and AI tooling to find, validate and remediate vulnerabilities. It was among the first companies to build a business model around crowd-sourced security, pioneering bug bounty programs and coordinated vulnerability disclosure. Organizations run public or private programs on the platform; researchers submit vulnerability reports, which are triaged and, where valid, rewarded with bounties.
The current product set is marketed as the H1 Platform, positioned around Continuous Threat Exposure Management (CTEM) spanning discovery, validation, prioritization and remediation. Components include H1 Bounty, H1 Agentic Pentest, H1 Continuous Testing, H1 Remediation, H1 Validation and H1 AI Red Teaming (adversarial testing of AI systems mapped to the OWASP LLM Top 10, MITRE ATLAS and the NIST AI RMF), all coordinated by an agentic AI orchestrator called Hai. The company also maintains free and community-facing offerings: a Community Edition giving eligible open source projects free access to the platform for vulnerability submission, and founding membership in the Internet Bug Bounty, a bug bounty program for core internet infrastructure and open source projects funded early on by Microsoft and Facebook. Educational and competitive resources for researchers include the Hacker101 CTF, a program directory, Hacktivity disclosure feeds, reputation and leaderboard systems, and the vetted HackerOne Clear community.
Cited customers over time include the U.S. Department of Defense, U.S. Department of State, General Motors, GitHub, Goldman Sachs, Google, Hyatt, Lufthansa, Microsoft, MINDEF Singapore, Nintendo, PayPal, Slack, Starbucks, Twitter, Yahoo, Dropbox, Shopify and Snap. HackerOne maintains a trust center listing certifications and compliance frameworks including SOC 2 Type 2, ISO 27001, PCI DSS, FedRAMP, GDPR, CCPA, UK Cyber Essentials Plus, and the ISO 29147 and ISO 30111 vulnerability handling standards.
Founding story
In 2011, Dutch hackers Jobert Abma and Michiel Prins set out to find security vulnerabilities in 100 prominent high-tech companies, an effort they called the "Hack 100"; they found flaws in all of them, including Facebook, Google, Apple, Microsoft and Twitter. Many firms ignored their disclosures, but Facebook COO Sheryl Sandberg passed the warning to head of product security Alex Rice. Rice, Abma and Prins connected and, together with Merijn Terheggen, founded HackerOne in 2012. According to co-founder Jobert Abma, the founders moved the business to San Francisco because ambitious funding was easier to secure there; Amsterdam investors were prepared to put in only $2.5 million, whereas the company raised $9 million in its first round in the US.
Business model
HackerOne sells access to its platform and to a vetted researcher community to enterprise and government customers, which fund bug bounty programs, pentests, continuous testing, AI red teaming and remediation workflows. Researchers are paid bounties by customer organizations for valid vulnerability reports, and can also earn stipends for pentest engagements (advertised at up to $5,000 per engagement). Eligible open source projects can use a free Community Edition.
Revenue derives from customer-side subscriptions and services for the H1 Platform's bounty, pentesting, continuous testing, validation, remediation and AI red teaming offerings, with bounty payments flowing from customers to researchers through the platform.
Traction
Public figures include more than $380 million rewarded to researchers and over 1,000 active bug bounty programs on the community site; more than $230 million in bounties paid as of December 2022; over 600,000 bugs found; 1,300+ companies using the platform; and 90% of customers with the Hai AI agent enabled. In the 12 months preceding January 2022 the company said it identified over 17,000 high or critical vulnerabilities for customers, and in the first month after Log4j 612 hackers submitted 2,175 potential vulnerabilities to HackerOne customers. The company reports a 210% increase in AI vulnerability reports in 2025 and states that 25% of findings are actionable.
Latest developments
Current positioning centers on Continuous Threat Exposure Management and AI security, with the Hai agentic orchestrator, H1 Agentic Pentest, H1 Continuous Testing and H1 AI Red Teaming, plus customer deployments such as Snap's use of AI red teaming and Shopify's reported 62% acceleration in validation and triage. Recent publications include the 9th annual Hacker-Powered Security Report and a "Closing the AI Security Gap" research report. Naveen Bhateja has been appointed Chief People Officer.
▸Full profile — market position, technology, go-to-market, geography, history, risks & controversies
Market position
HackerOne describes itself as a category leader in hacker-powered security and, more recently, in continuous threat exposure management; it was one of the first companies to commercialize crowd-sourced security. It reported over 1,500 customers and more than 500,000 hackers at the time of its 2019 Series D, and currently cites 1,300+ companies on the platform. It was named a Fast Company "brand that matters" and ranked fifth on Fast Company's World's Most Innovative Companies list for 2020.
The company positions its combination of a large vetted researcher community, agentic AI (Hai) and a single connected platform covering discovery through remediation as capabilities competitors do not bring together, arguing human researchers find issues automation misses while AI compresses triage and prioritization time.
Technology
The platform links vulnerability discovery, validation, prioritization and remediation in a single workflow. Hai, an agentic AI orchestrator, coordinates agents across stages, scoring and validating findings continuously. H1 Validation is marketed at 95% accuracy in confirming exploitability with a 40% signal improvement; H1 Remediation produces source code-informed fix plans delivered to engineering in one click; H1 AI Red Teaming performs adversarial testing of AI systems and models mapped to OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF. Human researchers supply findings automation does not reach, such as novel attack chains and business logic flaws.
Go-to-market
Direct enterprise sales supported by customer stories, research publications such as the annual Hacker-Powered Security Report and the "Closing the AI Security Gap" report, live hacking events and conferences, a public program directory, and community programs (Hacker101 CTF, leaderboards, Clear researcher tier, community partner discounts) that attract and retain researchers. A free Community Edition for open source projects and founding participation in the Internet Bug Bounty support ecosystem visibility.
Large enterprises and public sector bodies with significant digital attack surface, including technology, e-commerce, financial services, automotive, travel and defense/government organizations; the platform also serves security researchers as a second user base.
Geography
Headquartered in San Francisco, California, with an engineering office in Groningen and offices opened in London and Paris; additional European offices were added following 240% year-over-year European customer growth reported in 2017. Live hacking events have been held across the US and Asia, and customers include government agencies in the US, UK and Singapore.
History
Founded in 2012, HackerOne hosted a program in November 2013 encouraging discovery and responsible disclosure of software bugs, funded by Microsoft and Facebook, which became the Internet Bug Bounty project. By June 2015 its platform had identified roughly 10,000 vulnerabilities and paid over $1 million in bounties, and in September 2015 it launched a Vulnerability Coordination Maturity Model. Merijn Terheggen stepped down as CEO in November 2015 and was replaced by Mårten Mickos. In March 2016 the U.S. Department of Defense launched "Hack the Pentagon" on the platform, a 24-day program that surfaced 138 vulnerabilities and paid over $70,000 in bounties; follow-on DoD initiatives included the first U.S. government Vulnerability Disclosure Policy and "Hack the Army" (118 valid reports, 371 participants, about $100,000 awarded) and, in May 2017, "Hack the Air Force" (207 vulnerabilities, more than $130,000 in bounties). In August 2022, Defense Digital and the U.S. Air Force ran a "Hack the Satellite" live event. The company reported 240% year-over-year European customer growth in April 2017 and opened additional European offices; it hosted live hacking events in the US and Asia and its first Security@ conference in San Francisco in October 2017. It acquired code-review-as-a-service platform PullRequest in April 2022. Kara Sprague is listed as CEO in current reference material.
Risks & controversies
The company's Wikipedia entry carries a notice that the article may have been created or edited in return for undisclosed payments, in violation of Wikipedia's terms of use, and may require cleanup for neutrality.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Founder mafia
5 people who came through Hackerone went on to found or lead other companies.
Competitors · 10
by search overlapCompanies competing with Hackerone for the same Google search keywords, organic and paid, via search-intersection analysis.
Acquisitions · 1
Early investors' stakes continue via these dealsPullRequest was a marketplace and platform for on-demand code review, connecting development teams with expert reviewers who checked pull requests for quality and security issues. Acquired by HackerOne in 2022.
Timeline · 15
launches, deals, and filingsNaveen Bhateja was named Chief People Officer at HackerOne.
Defense Digital partnered with the U.S. Air Force at the Air Force Research Laboratory, Lawrence Berkeley National Laboratory and USAG Fort Hunter Liggett for a live hacking event in which participants targeted a satellite.
HackerOne acquired PullRequest, a code-review-as-a-service platform.
HackerOne raised $49 million in a Series E round led by GP Bullhound, bringing total investment to nearly $160 million, to fund R&D and go-to-market expansion.
$49M source ↗
Launched in August 2021 to address issues in applications deployed on AWS; the company reported rapid uptake.
HackerOne was ranked fifth on Fast Company's World's Most Innovative Companies list for 2020 and was later named a Fast Company 'brand that matters'.
HackerOne announced a $36.4 million Series D round, bringing total raised to more than $110 million, to scale enterprise and data-powered offerings, expand global reach and strengthen its hacker community.
$36.4M source ↗
A 200-attendee event with speakers from the DoD, General Motors, Uber and hackers.
The DoD extended its hacker-powered programs to the Air Force, leading to 207 vulnerabilities discovered and more than $130,000 in paid bounties.
The company announced 240% year-over-year customer growth in Europe and opened additional European offices; it also cited offices in London and Paris alongside its Groningen engineering office.
DoD created the first U.S. government Vulnerability Disclosure Policy, first used in the Hack the Army initiative, which produced 118 valid vulnerability reports from 371 participants and about $100,000 in awards.
The 24-day program resulted in discovery and mitigation of 138 vulnerabilities in DoD websites with over $70,000 paid in bounties.
Co-founder Merijn Terheggen stepped down as CEO and was succeeded by Mårten Mickos.
The company released a model codifying minimum standards for how organizations handle incoming unsolicited vulnerability reports.
HackerOne hosted a program encouraging discovery and responsible disclosure of software bugs, funded by Microsoft and Facebook, known as the Internet Bug Bounty.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
▸Research sources · 8
primary sources listed
- Hackeronehackerone.com · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Hackerone do?
- HackerOne runs a crowdsourced security platform combining bug bounty, pentesting and AI agents for continuous threat exposure management.
- Who are Hackerone's investors?
- Hackerone's investors include 1/1 Capital, Defy Partners, New Enterprise Associates (NEA), Savano Capital Partners, Valor Equity Partners, Benchmark.
- Where is Hackerone headquartered?
- Hackerone is headquartered in San Francisco, US.






