Fixing the Fix Gap: Introducing H1 Remediation
Over the past year, HackerOne platform data has told a strange story. Security teams got faster: Mean Time to Remediate (MTTR) across the platform dropped roughly 80%, with the median time to resolve down nearly 70%.
By any normal read, that is a program improving. But over the same period, the backlog of unresolved critical-severity findings grew 29 times over, and the resolution rate for critical findings fell from over 85% to under 44%.
Teams are not getting worse at fixing things. They are fixing the easy things faster, while a growing pile of validated, exploitable risk sits untouched. We call this exposure debt, and it does not accumulate because someone decided a finding did not matter. It accumulates because the effort required to get a finding taken seriously and acted on exceeds the bandwidth available to do it.
What closes exposure debt is findings that arrive with everything needed to fix them.
Why Validated Findings Stall
Ask a security leader why a confirmed, exploitable finding has been open for three weeks, and the answer is rarely "we don't think it's a problem."
Security has a severity and priority rating; engineering has no shared evidence to independently confirm it, and that friction alone is often enough to push a finding to the bottom of the queue. Volume compounds the problem: most automated scanning output is noisy enough that engineers have learned to deprioritize it on sight. Mediums and lows are rarely ignored on purpose; they just never win the negotiation.
AI is accelerating both sides of this at once. Attack surface is expanding faster than security teams can test it, while engineering increasingly leans on AI coding agents that attack the symptom, not the root cause, generating a plausible-looking fix with no ticket, no trail, and no confirmation the underlying issue was ever real or exploitable.
Closing this gap needs a different starting point: a fix path that begins from an already-proven exploit, grounded in the customer's own application code, and delivered directly into the tools engineers already use.
Introducing H1 Remediation
Starting today, H1 Remediation closes the discovery-to-remediation gap: every HackerOne finding where root cause is confirmed carries a developer-ready fix plan, generated automatically and attached directly to the report.
This runs on the same engine that powers the rest of the H1 Platform.
- H1 Continuous Testing and H1 Agentic Pentest give Hai's agentic capabilities scale and speed across the attack surface.
- HackerOne's community of security researchers gives it something scale can't: the business logic flaws, novel attack chains, and adversarial techniques that no training set contains.
- H1 Remediation makes sure every one of those findings, however it surfaced, turns into a shipped fix as fast as it's found, instead of stalling in a backlog.
H1 Remediation uses source code-informed root cause analysis to trace a finding to the exact lines of code where it lives, then builds a complete fix plan around that evidence: an explanation of the root cause, tracing exactly where the risky input enters the code and where it does the damage, a recommended remediation approach, language-specific code change suggestions, and the business context an engineer needs to prioritize it.
From there, your team sends the full plan to a connected issue tracker in one click, or hands it directly to an AI coding agent through the HackerOne MCP server.
This is not a new queue to manage or a parallel workflow bolted onto your existing process. It runs inside the platform on findings you already receive, and it strengthens the validation step in the process: the same source code trace that anchors the fix plan also sharpens confidence that the finding is real in the first place.
What Actually Changes for Your Team
The fix plan is specific to your code, not generic guidance pulled from a pre-canned list. Because root cause analysis is grounded in your own repositories, engineers see exactly what to change and why, without a back-and-forth with security to confirm it.
It shows up where engineers already work. One click sends the full plan, including root cause and code-level suggestions, into Jira, Linear, or ServiceNow as a structured ticket, with status syncing back to HackerOne automatically. Or it goes straight into an AI coding agent such as Claude Code, Codex, or Cursor via MCP, so a developer can act without leaving their IDE.
Plans arrive with context, not just a ticket number. H1 Remediation pulls incident history and related issues from Jira and Linear, and business and asset context from Confluence, so a finding routes to the right owner with the reasoning already attached.
Leaders get a real answer to "how exposed were we, and for how long." A new Remediation Dashboard tracks resolution rate, MTTR by severity, and backlog trends over time, with mean time to remediate benchmarked against the platform average, so security leaders can show a board or an auditor that exposure is actually closing, not just being discovered faster.
Put together, the outcome is straightforward: your security team stops being the translator between a finding and a fix, and your engineering team stops needing to take that translation on faith.
Findings that used to sit in exposure debt indefinitely now have a clear, low-effort path to resolution, because everything needed to close them arrives with the ticket.
From Here, the Gap Keeps Closing
H1 Remediation launches today for findings from security researchers, pentesters, and HackerOne's continuous testing agents, the sources that already carry demonstrated, adversarially validated exploitability.
From here, we're extending the same source code-informed fix planning to findings surfaced by third-party scanners.
We'll be sharing more at Black Hat USA 2026 in August. In the meantime, exposure should close because a fix shipped, not because a ticket got closed. That's what H1 Remediation is built to do.