Code of Conduct

By participating in programs on HackerOne, all Community Members agree to help empower our community by following the HackerOne Code of Conduct (CoC). The CoC is in addition to the General Terms and Conditions and Community Member  Terms and Conditions that all Community Members must agree to when creating an account.

This CoC sets out guidelines for engaging on the HackerOne platform and describes HackerOne’s potential actions if a violation occurs. A program may include additional rules of engagement or conduct in their program policy and may enforce those rules with program-level sanctions, so Community Members must always review the program policy before engaging on a particular program. By submitting a report to a customer’s program, you are agreeing to adhere to that program’s rules in connection with your submission. 

Platform interactions should at all times be respectful and communicated in a professional manner and tone with a view to being beneficial to the report validation process. Please do not 

  • Create unnecessary noise on reports by spamming report comments or circumventing the Mediation process by submitting multiple support tickets for updates
  • Make rude, offensive, or inappropriate comments in vulnerability reports, support tickets, or other communications with HackerOne, customers, or Community Members
  • Conduct yourself unprofessionally at Live Hacking Events or other in-person events where you are attending in your capacity as a Community Member
  • Threaten disclosure in violation of customer program policy and/or HackerOne terms and conditions

These actions decrease triage efficiency, are not beneficial to Community members or customers, and are inconsistent with HackerOne’s platform standards and terms of use.

HackerOne does not tolerate any discrimination based on age, ethnicity, level of experience, nationality, personal appearance, race, religion, sexual or gender identity and orientation, physical appearance, political beliefs, or other protected classes. 

Hate speech, profanity, illegal or defamatory language, or any aggressive threats or abusive language in report comments, support tickets, or other communication methods (including related posts on social media and other platforms) will not be tolerated in any form. If it is confirmed that a Community Member account is tied to actions which amount to a breach of our CoC, enforcement action may be taken. 

Abusive behaviour is not tolerated in any form on the platform or at in-person events. Please note that any abusive behavior at Live Hacking Events or other in-person events where you are attending in your capacity as a Community member is a violation of our CoC and will lead to a ban from participation in future Live Hacking Events, in-person events, and other enforcement action on the HackerOne platform, up to and including permanent banning of your account.

Ethical Working Practices 

HackerOne is committed to ethical business partnerships and has a zero tolerance policy with respect to slavery, human trafficking, and forced or child labor. Community Members are strictly prohibited from using slavery, trafficked/forced labor, and/or child labor that violates applicable modern slavery or child labor protection laws in the provision of any security research, security testing, or any other work done in connection with the HackerOne platform. Where applicable, HackerOne reserves the right to inform relevant authorities as it deems necessary. 

Unlawful or obscene content 

Users are strictly prohibited from using the platform to post, create, share, upload, or make available any obscene, explicit, violent, or otherwise unlawful content (including images), including in any support tickets, in your submissions/vulnerability reports, or in any communications with HackerOne, customers, or Community Members. Any violation of this policy may result in the removal of the submitted content and suspension or termination of the associated account, at the sole discretion of HackerOne. Where applicable, HackerOne reserves the right to inform relevant authorities as it deems necessary.

Community Members must not perform testing which might be deemed "unsafe" without prior authorization from the Customer. If there is any uncertainty always ask for clarification from the Customer before engaging in the testing. This includes (but is not limited to): exploiting a vulnerability beyond what is necessary to show impact (i.e. accessing excessive amounts of customer internal information, dumping a database, etc.), gaining access to and using accounts or production credentials not approved per the program's policy, altering production or database information or causing a Denial of Service, impacting the stability of customer systems outside of posted testing policies, or otherwise conducting security research or submitting reports in violation of a program’s policies.

Hazardous testing—as outlined in HackerOne's Core Ineligible Findings —must never be attempted unless explicitly authorized by the program. This includes but is not limited to:

  • Excessive traffic or request generation (e.g., DoS, DDoS)
  • Testing that affects system availability
  • Social engineering (e.g., phishing, opening support tickets)
  • Noisy attacks that disrupt users or admins (e.g., notification or form spam)
  • Physical security testing

If using Hackbots, please ensure that use is in alignment with the principles detailed here.

  • By the Rules: Hackbots must operate within the published vulnerability disclosure policies of the program they're engaging with, along with HackerOne's Code of Conduct and Disclosure Guidelines.
  • Human-in-the-Loop: Hackbots must not operate in a fully autonomous manner. We employ a “hacker-in-the-loop” model, requiring human experts to investigate, validate, and confirm all potential vulnerabilities before submitting to a Vulnerability Disclosure (VDP) or Bug Bounty Program (BBP).
  • Bounty Eligible: Human operators of Hackbots qualify for any applicable bug bounty rewards, just as if the vulnerabilities were discovered through traditional means.
  • Accountable: Hackbot operators are responsible for their Hackbots and must exercise due diligence to ensure compliance with platform rules and program policies.

Misuse of hackbots will result in potential sanctions against their hackbot operator.

HackerOne permits and encourages the responsible use of AI tools throughout the research workflow, including for learning, reconnaissance, vulnerability discovery, proof-of-concept development, and report quality improvement.

Community Members remain fully responsible for any submissions or other platform content created with the assistance of AI tools, including third-party tools and any proprietary AI tools provided by HackerOne. The use of AI does not change the requirement to validate findings, connect all steps in an attack chain, and provide a clear, reproducible proof-of-concept demonstrating a real vulnerability and its impact.

Submission Standards

Reports must be accurate, reproducible, and demonstrate real-world impact.

High-quality submissions:

  • Demonstrate clear, reproducible impact with step-by-step reproduction
  • Include a strong proof of concept
  • Account for real-world mitigations and context
  • Assign accurate severity at the point of submission - a repeated pattern of inflated severity constitutes a Code of Conduct violation.

Submissions will be closed as Not Applicable (N/A) if they are:

  • Speculative or misleading
  • Missing a proof of concept
  • Not reproducible
  • Based solely on a video attachment
  • Lacking demonstrated impact

Findings that do not account for existing mitigations or defense-in-depth controls are not valid unless a practical exploit path is clearly demonstrated.

Community Members are expected to prioritize quality over quantity. Repeated submission of low-quality or unverified reports may result in increased conduct review and enforcement action.

Use of AI in Testing

When using AI tools, including autonomous or semi-autonomous agents, Community Members remain fully accountable for their use of such AI tools, including reviewing and validating all AI-generated outputs for accuracy, completeness, and appropriateness. All AI-assisted activity must comply with HackerOne's terms and each applicable program's scope, policies, and testing restrictions, including limits on automation, request volume, and rate limiting.

AI-assisted testing must not result in unsafe testing, out-of-scope activity, excessive traffic, or other prohibited conduct.

Prohibited Use of AI

The following behaviors are not permitted:

  • Generating large volumes of low-signal or non-actionable reports
  • Submitting unverified or fabricated vulnerability claims, including those without a proof of concept
  • Relying on AI outputs that contain hallucinated or misleading technical details (e.g., invented endpoints or unsupported impact claims)
  • Using AI in a manner that is likely to cause unsafe testing, policy violations, or unethical behavior
Enforcement

Misuse of AI tools may result in enforcement actions, including reputation impact, rate limiting, loss of private program eligibility, additional verification requirements, suspension, or removal from the platform.

HackerOne recognizes that Community Members may be at different stages of their bug bounty journey, and we support continued growth and enablement. However, thorough and complete reporting remains a fundamental requirement. Consistent with our longstanding policies, HackerOne reserves the right to escalate or de-escalate the severity of an issue when warranted.

The H1 Platform seeks to develop relationships between security researchers and organizations that are grounded in trust. Responsible disclosure is a cornerstone of this relationship. HackerOne's disclosure process is designed to balance public transparency with legitimate security and operational concerns of participating programs. Disclosure done responsibly strengthens trust across the ecosystem; disclosure done irresponsibly undermines it. All Community Members are expected to follow HackerOne's disclosure process and comply with the terms of any programs in which they choose to participate.

The following are expectations of responsible disclosure practices on HackerOne. This list is not exhaustive. Community Members should exercise sound judgment and uphold a collaborative standard in all disclosure situations, including those not explicitly addressed below. Failure to do so will result in enforcement action and/or forfeiture of any monetary reward. "Disclosure" includes social media, blog posts, verbally, press, forums, and other publication methods.

  • Obtain explicit approval from the program team before any vulnerability details are made public. This applies to all closure statuses (including Informative, Duplicate, and Not Applicable).
  • Ensure you review the program's disclosure preferences before participating in the program. Re-review the program's Disclosure Settings and CVD Type (displayed on the "Security" page under "Program Highlights"), and the program's policy prior to initiating any disclosure conversations.
  • Respect program timelines and do not disclose prematurely, even if a fix has been implemented.
  • Follow the formal Disclosure Request process, rather than communicating disclosure intent outside of HackerOne's platform or through other means.
  • Escalate issues with the Disclosure Request process through proper channels (HackerOne Support) rather than disclosing without program authorization or coordination.
  • Maintain professionalism in any public write-ups. Disclosures should educate the security community, not damage a program's reputation, sensationalize a finding, or put the security of systems or the privacy of individuals at risk. Share only what is necessary - disclosure should inform, not cause damage or shame.
  • Never use disclosure as leverage. Threatening to disclose in order to pressure a bounty award or payout increase is a serious violation of the HackerOne Code of Conduct and will result in enforcement action, including potential permanent platform removal.
  • Confidential communications, information, or data belonging to HackerOne, the program, a program's users or customers, or other Community Members must never be published without coordinating with the relevant customer, owner, and/or controller of the data. Personal data that may identify or be capable of identifying an individual must never be published or otherwise disclosed without explicit consent from the individual.

Nothing in this list is intended or should be interpreted to conflict with any rights of disclosure to specific agencies where such disclosure is protected under applicable law. Community Members with questions about responsible disclosure practices should proactively communicate with HackerOne Support. Following responsible disclosure practices protects both the researcher community and the programs they support, fostering trust and accountability across the ecosystem.

Private Programs

In addition to the Responsible Disclosure expectations listed above, private programs have additional confidentiality obligations. Before participating in private programs, Community Members should ensure they understand their obligations under this CoC and the program policy related to disclosure prior to submitting a report.

Do not disclose publicly the existence of any private program on the H1 Platform. These programs are designated private by the customer for a reason and must be treated as confidential. This includes program name, scope, vulnerability information, bounty structure, account information, communications with program personnel, or any other detail that could identify the program. Disclosure to anyone who is not a HackerOne employee or a member of that program will be considered a violation of the Code of Conduct. This includes verbally or in writing. Do not collaborate with other Community Members without the express permission of the private program.

For more information on private program disclosure, please see HackerOne's Disclosure Process - Disclosure for Private Programs.

Third-Party Assets

Unless mentioned in the program policy, if you discover a vulnerability or widespread misconfiguration affecting a third-party component, you are required to make reasonable and good faith efforts to notify the component owner before reporting elsewhere. Where the component owner maintains a separate customer program, Community Members are not permitted to disclose unpatched details downstream without coordination and approval from component owner. Community Members should first contact HackerOne Support to collaborate or help coordinate, to the extent possible, on a responsible path forward.

If you discover a vulnerability affecting a HackerOne customer, do not contact that customer’s customers, partners, or end users. All disclosure requests must go through the H1 Platform to give affected parties time to triage and remediate responsibly.

Only use approved communication channels to discuss vulnerabilities submitted to HackerOne. Unless the program has explicitly provided an alternative contact method to you in their program policy, contacting security teams “out-of-band” about reports submitted on HackerOne is a violation of this CoC. The HackerOne platform is the only approved communication channel, except where approved alternative communication channels are outlined within the program policy page or otherwise notified in writing by the program. Unless otherwise specified in a program policy, communicate with the program on the report.

Duplicate account abuse: Any case where multiple HackerOne user accounts are used to circumvent a sanction against a user account, to mislead, to create an unfair advantage on the platform, or to otherwise engage in behavior that is inconsistent with this CoC or HackerOne’s terms and conditions. Community Members are permitted to have and use one sole account for the purpose of submitting vulnerability reports. This also encompasses cases where a Community Member uses multiple accounts to circumvent trial report restrictions. Community Members are prohibited from sharing, selling, trading, or giving away their account.

Reputation farming: Any activity that creates an unfair gain in reputation. This includes sharing account access and submitting the work of other Community Members, as well as inappropriate requests for closure status changes for the purpose of maintaining or improving reputation. This also encompasses cases where Community Members may attempt to social engineer HackerOne staff into assisting with the launch of an illegitimate program. Community Members are also prohibited from triaging and/or rating their own reports (to the extent a Community Member works on a HackerOne customer program).

What is Intellectual Property?

Intellectual property (IP) is a broad term that refers to the legal rights that protect original creations. There are many categories of intellectual property, some familiar terms might include copyright, trademarks, or patents. In the context of what Community Members do on the HackerOne Platform, this includes things like software, tools, documentation, exploit techniques, research reports, and branding. Importantly, this includes both your work and the work owned by others: HackerOne, Customers and other Community Members. Examples would include:

  • Code you write for a PoC or automation script
  • A tool you develop or customize for scanning or testing
  • Research papers, write-ups, or blog posts
  • Internal methods, systems, or source code of the Customer you're testing.

Who Owns What?

Our terms and conditions set out in some detail the use and licensing of intellectual property rights (IPR). However, in more simple terms, as a Community Member you own the tools, scripts, research, and original content you personally create, unless stated otherwise in a Program Policy or separate terms. HackerOne and/or our Customers own all our respective intellectual property such as proprietary systems, source code, confidential information and/or non-public data, you interact with during participating in a Program. This means that all Community Members own their own original tools, writeups, or methods—even if shared publicly or used as part of a community project.

What does a breach of IPR mean?

A breach of intellectual property rights is an expression to describe when intellectual property is used without the permission or licence of the owner. Examples of breaches of IP:

  • Claiming credit for someone else’s vulnerability discovery or research
  • Copy-pasting PoC code, scripts, or report content from another researcher without permission or attribution
  • Using someone else’s tools or exploits in submissions without permission or acknowledgment, especially in BBPs or collaborative projects
  • Forking or modifying someone’s open-source project and removing licensing or author attribution in violation of terms

Even if a Community Member shares work publicly, that doesn’t mean it’s free to take or rebrand. Always check licenses, give credit, and when in doubt—ask.

Why respecting IP matters?

Failure to use IP lawfully may result in legal disputes and

  • Causes damage to the Community
  • Protects your contributions, reputation, and future opportunities
  • Encourages ethical collaboration and knowledge sharing
  • Maintains fairness in Programs and the distribution of Rewards.

Do not attempt to, without written authorization, socially engineer another party through impersonation of a HackerOne employee, another Community Member, a program member, or a security team.

Community Members are solely responsible for the tools that they use, which must be lawful and legally acquired and permitted by the Program Policy. If it is brought to HackerOne’s attention that illegal or counterfeit software was used, HackerOne will be required to take appropriate action, including potential sanction under this Code of Conduct. Where applicable, HackerOne reserves the right to inform relevant authorities as is deemed necessary.

HackerOne has a zero tolerance for any behaviours that are related to or amount to extortion or blackmail. You must not attempt to obtain bounties, money or services by coercion. Any cases of extortion or blackmail may be escalated based on severity and may amount to a criminal offense. Where applicable, HackerOne reserves the right to inform relevant authorities as is deemed necessary.

Do not attempt to circumvent a program or platform ban by creating new accounts. Doing so will result in an immediate permanent platform ban of any newly created accounts.

Enforcement Actions 

Enforcement of the HackerOne Community Member Code of Conduct is informed by the action guidelines below. The below matrix is intended to provide a general floor – not a ceiling – of potential enforcement action to be taken in the event of a Code of Conduct violation. 

Please note that HackerOne reserves the right to escalate or de-escalate the severity of enforcement and sanctions in accordance with the nature of the offense and irrespective of previous offenses. Depending upon the severity, nature, and/or numerosity of the offense(s), sanctions may include, without limitation, longer temporary bans, immediate removal from HackerOne Clear and HackerOne Clear Programs, exclusion from in-person events, and/or a permanent ban from the HackerOne Platform.

IncidentFirst OffenseSecond OffenseThird OffenseFourth OffenseFifth OffenseSixth Offense
Unprofessional BehaviorEducational1st Warning2nd WarningFinal WarningTemporary Ban (12 months)Permanent Platform Ban
Abusive Language/HarassmentFinal WarningTemporary Ban (12 months)Permanent Platform Ban   
Service Degradation/Unsafe TestingEducational1st Warning2nd WarningFinal WarningTemporary Ban (12 months)Permanent Platform Ban
Large-scale submission of low-quality or unverified vulnerability reports, including misuse of AI tools and automationFinal WarningTemporary Ban (12 months)Permanent Platform Ban   
Uncoordinated Vulnerability DisclosureFinal WarningPermanent Platform Ban    
Contacting Program Teams Out-of-Band1st Warning2nd WarningFinal WarningTemporary Ban (12 months)Permanent Platform Ban 
Reputation Farming/Duplicate Account Abuse1st Warning2nd WarningFinal WarningTemporary Ban (12 months)Permanent Platform Ban 
Extortion/BlackmailPermanent Platform Ban     
Misuse of Intellectual propertyFinal WarningPermanent Platform Ban    
Social EngineeringFinal WarningPermanent Platform Ban    
Circumventing a BanPermanent Platform Ban     


See something, say something: If you see a Finder violating these rules, request Mediation Assistance via the HackerOne Support Portal here. If you need help on a report of your own, you can request mediation directly from the report in question. 

Note: HackerOne may update this Code of Conduct from time to time, based on industry standards and best practices. We will endeavor to provide notice of any such update. Enforcement actions are taken at HackerOne’s sole discretion. By participating on the HackerOne platform, you acknowledge and agree to this Code of Conduct in effect from time to time.