THE H1 PLATFORM — YOUR FOUNDATION

Vulnerability Disclosure · Asset Management · Agentic AI · Analytics · Integrations · Governance 
 

 

Professional

The essential CTEM foundation for teams operationalizing continuous exposure management.

  • Always-on VDP, asset inventory & discovery
  • Hai Chat & Agentic Signal Enrichment
  • Real-time dashboards & SDLC integrations
  • RBAC, SSO & up to 5,000 automations/mo

Talk to Sales

 

Enterprise

Advanced coverage, governance, and scale for complex, security-mature organizations.

  • Everything in Professional, plus:
  • Cross-program risk insights & proactive alerts
  • Executive reporting, benchmarking & premium integrations
  • SCIM, attestation letter & unlimited automations

Talk to Sales

Most Advanced
WHY TEAMS CHOOSE OUR MODEL

Priced For How Security Actually Runs

Predictable by Design

A committed platform subscription plus prepaid credits you size up front. You set reward budgets and approve every payout, so spend never runs away from you.

Priced to Fit

Your edition’s entitlements are defined up front and credit usage is metered in real time. No per-payout surprises and no mandatory add-on tiers to reconcile.

Validated, Not Noisy

H1 Validation and Agentic Signal Enrichment confirm what is actually exploitable and filter duplicates, so your team acts on proven findings instead of a raw queue.

Consolidate Your Stack

Bounty, pentest, continuous testing, and remediation run on a single license and workflow. Consolidate your stack instead of stitching point tools together.

PRICING FAQ

How Our Pricing Works

A quick look at what makes the HackerOne pricing model different, and why security teams tell us it is easier to plan around than buying point tools one contract at a time.

You start with one H1 Platform edition, Professional, Enterprise, or Enterprise Plus, that acts as the foundation for everything else. From there you activate the products you need, such as H1 Bounty and H1 Pentest, on the same platform. Pricing is scoped to your program rather than sold as a fixed, one-size box.

Every security program is different in size, asset footprint, and the products it runs. We scope pricing to what you actually need so you are not paying for a tier built for someone else. Your team gets a clear, itemized quote before any commitment.

Competitors often sell each capability as a separate contract, with its own onboarding, integrations, and renewal to manage. With HackerOne, one platform license unifies intake, validation, analytics, and governance. That means less procurement overhead and no stitched-together stack to reconcile.

The platform covers the shared foundation: vulnerability disclosure, asset management, agentic AI, analytics, integrations, and governance. Products such as H1 Bounty, H1 Pentest, and H1 AI Red Teaming are the engagements you run on that foundation. You never pay twice for the same underlying capabilities.

Always-on Vulnerability Disclosure Program (VDP) coverage is included in the Professional, Enterprise and Enterprise Plus Platform edition's subscription, not sold as a separate add-on with its own price tag.

Yes. In addition to its products, HackerOne offers expert and managed services, including managed triage and validation, security advisory services, and live hacking events. These are optional and scoped to each program's needs, confirmed in the quote rather than bundled in by default. As with everything else, customers only pay for what they choose to run.

Agentic products run on Agentic Credits, a single prepaid pool you spend across any agentic workflow. Each action, such as a continuous test or a root cause analysis on a validated finding, draws down a set number of credits, so your cost tracks the work you actually run rather than a fixed per-seat license.

Every platform edition includes an allotment of agentic credits, so your team can experience H1 Asset Intelligence, H1 Continuous Testing and H1 Remediation inside your existing contract before deciding how much capacity to commit to.

One flexible currency spans every agentic product, so you are never locked into a fixed quantity of a single tool. Direct spend to wherever risk is highest this quarter and shift as your program evolves, all from the same pool.

You can add credits at any time, and they follow the same term as your platform subscription. You see consumption in real time and are notified as you approach your balance, and admins control which agentic workflows draw on credits, so there are no surprises.

Yes. Many teams begin with the platform and one product, then add engagements or move up an edition as their program matures. Because everything lives on the same platform, expanding does not mean re- onboarding or migrating data.

Customers set their own reward table and approve every payout, so spend stays within the budget and limits they define. Rewards are paid directly to researchers for valid findings and sit separate from the platform subscription. A rewards service fee applies to the bounty program and is confirmed in the quote, so the full cost is clear before committing.

Your entitlements are defined up front by the edition you choose, so there are no hidden platform charges. Researcher rewards in a bounty program are separate from your subscription and are always in your control, with spend limits and approvals you set.