• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. HackerOne
Logo of HackerOne

HackerOne

byHackerOne
in Application Crowdtesting Services
4.6

Overview

Service Information on HackerOne

Updated 6th November 2025

What is HackerOne?

HackerOne helps organisations with Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of a global community of security researchers to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprise organisations around the world.

HackerOne Pricing

Overall experience with HackerOne

Manager, IT Security and Risk Management
30B + USD, Retail
FAVORABLE

“Efficient Platform Facilitates Transparency and Trust in Hacker Engagement Process”

5.0
Dec 12, 2025
It's a really easy platform to work with and the support provided by all at HackerOne takes the stress away from managing and engaging with ethical hackers. The model and how we engage with the hacker community is very well designed, allowing for transparency and building trust between the programs and hackers.
Head of InfoSec Audit & Assessments
10B - 30B USD, Manufacturing
CRITICAL

“Understanding the Paradox: The Constrained Value of Public VDP Programs”

3.0
Jun 2, 2024
The VDP program does allow a company to have a channel for external researchers to communicate with the right teams that can handle any known external vulnerabilities, however this works well only when your running a private program and the benefits stop once this goes public (not that advantageous)

About Company

Company Description

Updated 19th November 2025

HackerOne helps organisations with Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of a global community of security researchers to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprise organisations around the world.

Company Details

Updated 19th November 2025
Company type
Private
Year Founded
2012
Head office location
San Francisco, United States
Number of employees
201 - 500
Website
https://hackerone.com

Do You Manage Peer Insights at HackerOne?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Top HackerOne Alternatives

Logo of YesWeHack
1. YesWeHack
4.9
(49 Ratings)
Logo of Bugcrowd
2. Bugcrowd
4.9
(27 Ratings)
Logo of Synack Crowdsourced Application Testing Services
3. Synack Crowdsourced Application Testing Services
4.8
(21 Ratings)
View All Alternatives

Peer Discussions

HackerOne Reviews and Ratings

4.6

(78 Ratings)

Rating Distribution

5 Star
64%
4 Star
35%
3 Star
1%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.5

Planning & Transition

4.6

Delivery & Execution

4.6

Integration & Deployment

5.0

Service & Support

4.7

Service Capabilities

4.6

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Manager, IT Security and Risk Management
    10B+ USD
    Retail
    Review Source

    Efficient Platform Facilitates Transparency and Trust in Hacker Engagement Process

    5.0
    Dec 12, 2025
    It's a really easy platform to work with and the support provided by all at HackerOne takes the stress away from managing and engaging with ethical hackers. The model and how we engage with the hacker community is very well designed, allowing for transparency and building trust between the programs and hackers.
  • IT Security & Risk Management Associate
    50M-1B USD
    Media
    Review Source

    HackerOne Enhances Security With Early Issue Detection and Custom Bug Bounty Coverage

    4.0
    Mar 30, 2026
    HackerOne has improved our overall application security program by providing us with actionable findings and reducing duplicated reports. We have been able to fix a lot of issues early before they were exploited in the wild.
  • SR SECURITY OPERATION ENGINEER
    50M-1B USD
    Software
    Review Source

    A dependable solution that improves visibility and efficiency for externally reported vulnerabilities.

    4.0
    Jan 28, 2026
    Overall, our experience with HackerOne has been a positive one. The platform is mature and mostly intuitive, it provides a structured workflow to receive, triage and manage researcher's reported findings. Their support and program management have been responsive, and the tooling helps keep internal stakeholders and external researchers aligned. As with any platform, there is opportunity to reduce noise and improve reporting, but overall HackerOne has been a reliable partner,
  • IT SECURITY & RISK MANAGEMENT ASSOCIATE
    50M-1B USD
    Software
    Review Source

    Small Security Teams Gain Increased Bug Coverage Through Platform Collaboration Tools

    5.0
    Jan 5, 2026
    HackerOne has enabled my small security team to scale and identify critical bugs in sensitive services. We have utilized the main platform and H1's more focused spot check reports to engage directly with researchers and focus on application features that are scheduled for GA.
  • It Security & Risk Management Associate
    50M-1B USD
    Finance (non-banking)
    Review Source

    Strategic Insights and Human Resource Aggregation Enhance Bug Bounty Program Effectiveness

    5.0
    Feb 11, 2026
    Hacker1 has been an excellent partner and is completely novel in the world of vendors from our perspective, mostly due to their excellent customer service and strategic insights.
...
Showing Result 1-5 of 79

Recommended Gartner Insights

  • Market Guide for Application Crowdtesting Services
Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

Reviewer Insights for: HackerOne
Performance of HackerOne Across Market Features

HackerOne Likes & Dislikes

Like

The flow of submissions through the platform and validation/prioritisation by triage means my team can focus on the findings that have real risk associated with them. HackerOne has one of the best implementations of AI that I have seen in any commercial product as of yet. The insights, ability to pull data from submissions and draw out complex exploits saves a huge amount of time. I can curate reports from common data points to the very complex at speed and with accuracy. The quality of reports and the depth of findings that would not have been picked up by traditional detections alone make the HackerOne community so invaluable to security programs.

Like

This service works well for internal programs which are not public

Like

- It provides a great deal of customization to specify exactly what areas we are looking to have covered by our bug bounty program. - They have a good number of offerings to encourage hackers to continue working for your program by offering different incentives and promotions. - Their AI tooling helps to reduce the time required to triage new reports by summarizing findings and their potential impact.

Dislike

While the majority of the hacker community are fantastic, you can sometimes come across someone who does not behave in a professional manor but the HackerOne Mediation team have always been able to assist in these scenarios. This is more of an industry problem than vendor specific. Standard reporting within the UI can be a little disjointed at times, but the Insights feature makes building out reports off platform easy to manage.

Dislike

publicly listed programs have barely any intel and information, this makes things difficult and adds additional cost just to run a service which derives vaule for the business

Dislike

- The user interface can sometimes be difficult to navigate, especially when searching for specific reports. - There is an incentive for hackers to submit multiple reports for similar issues (different parameters in the same API call, for instance). This can sometimes increase the amount of noise in new reports. - They are starting to build out their own MCP to help with triage, but it is still early in development; having a mature offering here would help to integrate H1 findings with our local codebase more easily for triage and remediation.