CourionAI
EN
Newsletter
← Glossary Company

HackerOne

The best-known platform for coordinated vulnerability disclosure, where researchers report security flaws to companies and sometimes get paid for them.

If you find a security hole in a large company’s product, HackerOne is usually where you are supposed to report it. The platform sits between researchers and vendors: you submit the flaw, the company triages it, and if the report holds up you may receive a bounty. The point is to give researchers a legitimate route that does not involve either staying silent or going straight to the press.

The system depends on the vendor actually answering. A report that sits untouched for weeks is a common complaint, and it is why researchers usually set a disclosure deadline up front. When you read that a flaw was “reported in June and remains unpatched”, HackerOne is generally the paper trail behind that sentence.