What’s New for HackerOne Researchers

HackerOne Team
Image
HackerOne Graphic with Pink, Green, and Blue Colors

Researchers have been clear with us about what they need from HackerOne: better visibility into scope and rewards, more control over how they work, clearer answers about how reports are handled, and more evidence that feedback turns into change. So instead of giving you a list of launches, we want to show what has changed in practice.

We’re starting a new series of regular researcher updates. These posts will share changes across the platform and community, explain what they mean for researchers, and give you a clearer view of what’s coming next.

For this first update, we’re looking back at changes made through July. We plan to publish these quarterly, with the next update expected in November (Q3).

Here’s what changed.

Clearer scope and rewards before you test

Before you spend time on a program, you should be able to understand what is in scope, what is excluded, and what rewards apply.

We added a Hacker API endpoint that lets researchers retrieve the report categories a program excludes from rewards. That means you can bring those exclusions into your own research and automation workflows before you test or submit.

It does not replace the program policy, which governs. You should still check the current scope, exclusions, testing requirements, and reward table before starting. But it makes one important piece of that information easier to work with programmatically. See the Hacker API documentation.

As of now, the structured-scopes endpoint is currently limited to 50 requests per minute.

We also introduced Unified Scope & Rewards Groups. For programs that adopt the new setup, assets, scope descriptions, testing requirements, and bounty tables can now be presented together instead of being spread across different parts of the program page. The goal is simple: make it easier to understand what you can test, how you should test it, and what a program has published about rewards for what you find.

Adoption is up to each program, so formats may vary by program. Award decisions remain with the program and are subject to its policy and the HackerOne terms. Read the April 2026 changelog. 

More surface area to test

Researchers also need worthwhile things to test. Over the twelve months ended June 30, 2026, new and expanding programs added more than 35,000 in-scope, testable assets to HackerOne, a 45% increase in the number of in-scope assets available to researchers on the platform. Growth was particularly strong across AI models and systems, infrastructure and IP addresses, APIs, and web applications.

Not every asset carries a bounty, and testing conditions vary by program. But there is meaningfully more surface area available to researchers than there was a year ago.

More control when writing a report

AI can help with reporting, but it should not take control of the report away from the researcher. With Report Assistant, you can write directly in the report form or paste in something you already drafted. The assistant is designed to point out missing information and suggest improvements without rewriting or changing your report unless you ask it to. Asset, weakness, and severity fields remain editable.

You decide which suggestions to accept or reject, and you remain responsible for understanding, reproducing, and standing behind what you submit. Read the April 2026 changelog.

Clearer expectations for AI-assisted research

In April, we also updated the Community Member Code of Conduct to clarify expectations for using AI-enabled and automated tools responsibly during security research.

The update makes clear that researchers remain responsible for validating AI-assisted outputs before submitting them and reinforces existing expectations for accurate, high-quality reports. It also prohibits misuse, including large-scale submission of low-signal or unverified reports and AI-assisted testing that results in unsafe or prohibited activity. The update also provides greater transparency into how HackerOne may address misuse.

More visibility into routing and initial review

As AI-assisted research increases report volume, researchers have reasonable questions about how reports are routed, what automation is doing, what data it can access, and where people remain responsible for decisions.

Triage Prioritization is now used more broadly across our standard triage operations. It uses factors including report severity and researcher signal to help route reports. Read more about HackerOne's response to AI-driven report volume.

We have also expanded agentic validation. Agentic validation checks your report against the program's policy, scope, and prior reports to flag possible duplicates, scope mismatches, policy issues, and platform-standard concerns.

When agentic validation reaches high confidence in its assessment, it closes the report directly as Duplicate, Informative, Spam, or Not Applicable, or requests NMI. Every one of those automated decisions is backed by accuracy data, and we continuously monitor and spot-check the outcomes to keep it that way. 

Lower-confidence flags go to an analyst as context rather than being acted on automatically, and other report decisions follow HackerOne's normal review process. You can reopen an automatically closed report as you would any other closure, and mediation remains available if you disagree with the outcome.

HackerOne does not use confidential researcher submissions or customer vulnerability data to train, fine-tune, or otherwise improve generative AI models. You can find more information in our Hai Security and Trust documentation and our Responsible AI at HackerOne blog.

Improving visibility and workflows

Not every useful improvement is a major product launch. We separated the leaderboard experience so individual researcher performance is easier to distinguish from AI-powered collectives and business accounts.

We also added webhook and email notifications for program teams when a researcher requests disclosure or mediation. That makes disclosure and mediation requests easier for the right program teams to see.

Investing in researcher success

The platform is only one part of the researcher experience. The HackerOne Ambassador program grew from 51 to 60 actively managed chapters. Average attendance increased from roughly 35 to 45 people per event. Those chapters create more opportunities for researchers to learn, meet other researchers, share techniques, and build local communities.

Just the beginning 

Security researchers have shared valuable feedback on report handling, notifications, API access, researcher signal, mediation, and how we follow through on feedback. We're motivated by these insights and committed to advancing work in each of these areas.

We also believe that trust is built through action, not words. That's why we're committed to being transparent about what we've heard, what we've changed, what remains in progress, and the reasoning behind our decisions. That is the standard we want to hold ourselves to more consistently.

So this is not meant to be a one-off update.

We expect to be back in November with our Q3 researcher update, including a look at the new dedicated researcher Discord community and more of what changed across the platform and community.

We want you to be able to judge progress for yourself.

Not by what we promise.

By what changes.