Companies that use Hackerone

Analyzed and validated by Henley Wing Chiu
All application security testing Hackerone

Hackerone We detected 490 customers using Hackerone. The most common industry is Software Development (32%) and the most common company size is 10,001+ employees (22%). Our methodology involves discovering URLs with known URL patterns through web crawling, certificate transparency logs, or modifications to subprocessor lists.

Note: We only track companies with a public vulnerability disclosure program

About Hackerone

Hackerone combines agentic AI solutions with the world's largest community of security researchers to continuously discover, validate, prioritize, and remediate vulnerabilities across code, cloud, and AI systems through bug bounty, vulnerability disclosure, pentesting, AI red teaming, and code security services.

⏱️ Data is delayed by 1 month. To show real-time data, sign up for a free trial or login
Company Employees Industry Region YoY Headcount Growth Usage Start Date
Vercel 501–1,000 Software Development US +37.6% 2025-12-05
Henkel 10,001+ Manufacturing DE +9.3% 2025-12-02
BankUnited 1,001–5,000 Banking US +6.1% 2025-12-02
Desempregado 10,001+ Staffing and Recruiting MZ +21.3% 2025-12-02
jamieweb.net 2–10 N/A N/A N/A 2025-11-24
Northern.tech 51–200 Software Development NO +15% 2025-11-17
Vectra AI 501–1,000 Computer and Network Security US +4.8% 2025-11-12
Mueller Water Products 1,001–5,000 Manufacturing US +12.4% 2025-11-05
Drumgrange Ltd 51–200 Defense and Space Manufacturing GB +4.5% 2025-11-04
Adevinta 5,001–10,000 Internet Marketplace Platforms NL -4.2% 2025-10-29
Cam Model Referral Earn $10,000 + per week 10,001+ Entertainment Providers N/A N/A 2025-10-29
DoorDash 10,001+ Software Development US +22% 2025-10-23
Kong 501–1,000 Software Development US +29.4% 2025-10-21
Robinhood 1,001–5,000 Financial Services US +26.1% 2025-10-18
Roke 1,001–5,000 IT Services and IT Consulting GB N/A 2025-10-16
Vueling Airlines 1,001–5,000 Airlines and Aviation ES +7.4% 2025-10-15
Regions Bank 10,001+ Banking US +4.2% 2025-10-14
Lovable 51–200 Software Development SE +2054.2% 2025-10-03
Baird 5,001–10,000 Financial Services US +6.3% 2025-10-01
Helium 11–50 Technology, Information and Internet US +46.2% 2025-09-24
Showing 1-20 of 490

Market Insights

🏢 Top Industries

Software Development 139 (32%)
Financial Services 59 (13%)
Technology, Information and Internet 46 (10%)
IT Services and IT Consulting 24 (5%)
Computer and Network Security 21 (5%)

📏 Company Size Distribution

10,001+ employees 107 (22%)
1,001-5,000 employees 100 (21%)
51-200 employees 73 (15%)
2-10 employees 53 (11%)
501-1,000 employees 45 (9%)

📊 Who in an organization decides to buy or use Hackerone?

Source: Analysis of 100 job postings that mention Hackerone

Job titles that mention Hackerone
i
Job Title
Share
Information Security Engineer
37%
Security Operations Center (SOC) Analyst
13%
Director, Information Security
6%
QA Engineer
4%
My analysis shows that HackerOne is primarily purchased by security leadership roles, with Directors and VPs of Information Security driving buying decisions across organizations from startups to Fortune 500 companies. These leaders are focused on scaling security programs without proportionally scaling headcount, managing compliance requirements like SOC 2 and ISO 27001, and staying ahead of emerging threats across cloud, API, and AI systems. Their strategic priorities center on building comprehensive vulnerability management programs that can handle modern, distributed architectures.

The day-to-day users are overwhelmingly security engineers and analysts who manage HackerOne as their vulnerability disclosure and bug bounty platform. These practitioners spend their time triaging incoming reports, validating vulnerabilities, reproducing issues in controlled environments, coordinating remediation with development teams, and maintaining relationships with external security researchers. They integrate HackerOne into broader security workflows alongside tools like Burp Suite, Wiz, and SIEM platforms.

I noticed recurring themes around managing vulnerability intake at scale and bridging security and development teams. Companies specifically mention needing to "manage intake from bug bounty platforms" and "coordinate with development teams to prioritize and remediate findings in a timely manner." Multiple postings emphasize "right-sizing severity" and creating "actionable reports," revealing that organizations struggle with prioritization and want to move beyond just collecting vulnerabilities to actually fixing them efficiently.

🔧 What other technologies do Hackerone customers also use?

Source: Analysis of tech stacks from 490 companies that use Hackerone

Commonly Paired Technologies
i
Technology
Likelihood
2203.0x
2085.7x
1935.3x
1482.1x
788.0x
745.1x
I noticed that companies using HackerOne tend to be high-growth technology companies that take both security and operational efficiency extremely seriously. The presence of tools like Docker Business and Watershed alongside HackerOne suggests these are mature tech organizations running sophisticated cloud infrastructure while also tracking their environmental impact. They're not just building products, they're building them responsibly at scale.

The pairing of HackerOne with UserTesting is particularly revealing. These companies are simultaneously stress-testing their security through bug bounties while gathering detailed user feedback on their products. This dual focus suggests a product-led growth motion where both security and user experience are competitive advantages, not afterthoughts. The high correlation with Golinks points to companies large enough that internal knowledge management has become critical. When your team needs a URL shortening system just to navigate internal resources, you're dealing with substantial organizational complexity.

The presence of Decagon AI, a customer service automation platform, alongside these other tools paints a picture of companies managing significant customer volumes while trying to maintain efficiency. These aren't early-stage startups figuring things out. They're growth-stage or mature companies dealing with scale challenges across multiple dimensions: security threats, customer support loads, internal collaboration, and infrastructure complexity.

👥 What types of companies is most likely to use Hackerone?

Source: Analysis of Linkedin bios of 490 companies that use Hackerone

I noticed that HackerOne's customers span an incredibly diverse range of industries, but they share a common thread: they operate digital infrastructure that millions of people depend on daily. These aren't just tech companies. I see financial institutions moving billions in transactions (Citi, Wells Fargo, Itaú Unibanco), consumer brands people interact with constantly (Starbucks, Peloton, Ferrero), entertainment platforms (DoorDash, FanDuel, Audible), and critical infrastructure providers (British Airways, Finnair, Vueling). What unites them is that they've built digital products or services where a security breach would be catastrophic to their brand, their customers, and their bottom line.

These are predominantly mature, established enterprises. I see Fortune 500 companies, publicly traded firms with Post IPO funding rounds, and businesses with 10,000+ employees dominating the list. Even the smaller companies tend to be well-funded (Series D, E, F rounds) or specialized players in critical sectors like defense. The presence of household names like Porsche, Dyson, PepsiCo, and the NBA tells me HackerOne attracts organizations where reputation risk is enormous.

Alternatives and Competitors to Hackerone

Explore vendors that are alternatives in this category

F5 Web App Scanner F5 Web App Scanner BlackDuck BlackDuck Ethiack Ethiack SonarQube SonarQube SonarQube Cloud SonarQube Cloud Astra Security Astra Security Checkmarx One Checkmarx One Tinfoil Security Tinfoil Security Detectify Detectify

Loading data...