HackerOne Launches H1 Remediation to Accelerate the Path from Validated Exposure to Verified Fix
New H1 Platform capability delivers developer-ready fix plans, grounded in source code and validated exploitability, delivered directly into the tools engineers use today
SAN FRANCISCO — July 29, 2026 — HackerOne, a global leader in Continuous Threat Exposure Management (CTEM), today launched H1 Remediation, a new capability in the H1 Platform. H1 Remediation delivers developer-ready fix plans for validated, exploitable findings. Each plan is grounded in the customer's own source code, enriched with business context, and delivered directly into the issue tracking tools and AI coding agents engineering teams already use via Model Context Protocol (MCP). Root cause is traced to specific lines of code, so engineers can act immediately without follow-up from security. This helps reduce exposure debt faster.
H1 Remediation addresses a gap that has widened as AI accelerates discovery faster than security and engineering teams can validate and fix what's found. With AI enabling faster discovery, the resolution rate for critical-severity findings has fallen significantly over the last year, even as critical-finding mean time to remediate improved by more than 50%. The result is that the backlog of unresolved critical issues has grown 29x over that same timeframe, according to H1 Platform data.
The bottleneck is not effort. It is friction: security lacks the data to make a compelling prioritization case, engineering is skeptical of severity ratings it cannot verify, and both sides operate from different risk frameworks with no shared ground truth. H1 Remediation removes that friction at the source. Fix plans are generated only for findings with validated exploitability, traced to the actual lines of vulnerable code in the codebase. Engineers get the specificity they need to act fast, without waiting for security to verify the work.
"Boards no longer want to hear how many vulnerabilities were found. They need to know the magnitude of the exposure debt you’re carrying and what you are doing about it,” said Kara Sprague, CEO at HackerOne. “H1 Remediation gives security leaders a defensible answer to both. Every finding carries a documented trail from validated exploitable vulnerability to verified fix, with exposure duration as a measurable, reportable metric. Closing that gap faster is both an operational improvement and a governance imperative."
“The value for us is in speed to resolution. H1 Remediation hands our engineers clear technical steps already grounded in our own code, so they can move straight to a fix,” said Connor Knabe, Application Security Architect at Veterans United Home Loans. “This results in time saved for the security and product teams. It's clear this isn't generic guidance. It's based on our actual code and fits right into how our team already works, so there's no new process, just better information showing up exactly where we need it.”
Unlike AI coding assistants that generate fixes without security validation, H1 Remediation works only from validated, exploitable findings. Those findings come from across the platform: security researchers identifying real-world impact through H1 Bounty, pentesters working through H1 Agentic Pentesting, and continuous exposure signals from H1 Continuous Testing. For each of these findings, Hai, HackerOne’s agentic AI orchestrator, traces root cause to the actual lines of code, and generates a developer-ready fix plan informed by context from the customer's actual environment and grounded in the codebase. The result is a complete picture that gives engineering teams the confidence to act on findings they know are real.
"Every customer conversation comes back to the same problem: validated findings sitting unresolved because engineering lacks the context to act on them quickly," said Nidhi Aggarwal, Chief Product Officer at HackerOne. "H1 Remediation extends the workflow from discovery to verified fix. When a fix plan starts from a validated, exploitable finding traced to the actual source code, is informed by the customer’s context, and is delivered into the engineering workflows teams already use, the friction that stalls remediation disappears. Combining agentic capabilities with human ingenuity from the security research community is what gives teams the confidence that what they are fixing is real. That is what turns remediation from a backlog problem into a continuous improvement process that drives measurable risk reduction.”
How H1 Remediation Closes the Gap
H1 Remediation is generally available through the H1 Platform. It runs automatically on incoming HackerOne-native findings, from security researchers, pentesters, and continuous testing, once exploitability and severity are validated. Key capabilities include:
- Source code-informed root cause analysis that connects to customer repositories (GitHub, GitLab, Azure DevOps, Bitbucket, public and private) and traces findings to the specific lines of code where the vulnerability exists. Root cause analysis sharpens validation confidence and anchors fix guidance in the customer's actual codebase.
- In-report fix plans with a remediation approach, root cause analysis detailing exactly where a risky input enters the code and where it does damage, language-specific code change suggestions, business context, and implementation guidance, added directly to the finding.
- Context enrichment from connected Jira, Linear, and Confluence sources, including incident history and asset information, so fix plans reflect the customer's actual environment before delivery.
- One-click delivery into issue tracking tools such as Jira, Linear, and ServiceNow as structured tickets, with status syncing back to the H1 Platform automatically.
- H1 Platform MCP server integration that exposes fix plans directly to IDEs and AI coding agents, including Claude Code and Cursor, so engineers can access and act on guidance without leaving their environment.
- Remediation dashboard tracking resolution rate, mean time to remediate by severity, findings flow, and exposure backlog trends, with peer benchmarking and year-over-year comparisons, giving security leaders an executive and board-level view of risk reduction over time.
H1 Remediation is available today in the H1 Platform.
About HackerOne:
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world's largest community of security researchers to secure the AI-native enterprise. The H1 Platform unites agentic AI solutions with security researchers' ingenuity to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions such as agentic and human offensive security testing, AI red teaming, code security, validation, and remediation, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing.
Q&A
Why is HackerOne launching H1 Remediation?
H1 Remediation is HackerOne’s answer to the widening vulnerability remediation gap. H1 Remediation enables security teams to resolve vulnerabilities significantly faster and with greater precision.
What value does H1 Remediation deliver to security leaders?
The Remediation Dashboard tracks remediation rate, Mean Time to Remediate (MTTR) by severity, exposure backlog trends within the H1 Platform, with MTTR benchmarked against the platform average.
How does H1 Remediation support my Continuous Threat Exposure Management (CTEM) framework?
H1 supports CTEM by giving security teams a more dynamic, always-on approach to managing risk. By continuously surfacing and prioritizing the most critical exposures, H1 Remediation helps organizations move faster from discovery to remediation, improve operational focus, and strengthen resilience against evolving threats.
What technologies is H1 Remediation compatible with?
H1 Remediation connects to source code repositories such as GitHub, GitLab, Azure DevOps, and Bitbucket for root cause analysis, delivers fix plans directly into issue tracking tools including Jira, Linear, and ServiceNow, pulls context from Confluence, and exposes fix plans to AI coding agents such as Claude Code and Cursor via the H1 Platform MCP server.