HackerOne has unveiled the H1 Platform, an agent-based AI tool designed to assist enterprises in managing exploitable risks through continuous discovery, validation, prioritization, and remediation at AI-scale. This launch addresses the growing discovery-remediation gap in security, prevalent due to AI's increasing role in enterprise code development.
Recent data indicates 73% of engineering teams incorporate AI in daily coding tasks, and AI-driven security technologies are identifying vulnerabilities faster than they can be remediated. HackerOne reports a 92% increase in vulnerability reports, with critical and high-severity cases rising while remediation efforts lag.
Addressing Vulnerability Remediation
The H1 Platform leverages agentic AI throughout the CTEM lifecycle to validate and remediate vulnerabilities. Using HackerOne's AI orchestrator, Hai, the platform synthesizes signals of exploitability, remediation insights, and attack trends to help organizations prioritize significant risks.
Recent data indicates 73% of engineering teams incorporate AI in daily coding tasks
"In a rapidly evolving world shaped by advanced AI models, security must be dynamic, validated, and impactful on business," stated Nidhi Aggarwal, Chief Product Officer at HackerOne. "The H1 Platform empowers organizations to continuously identify and address essential risks, operationalize remediation efforts, and reduce cyber threats at AI-scale."
Enhancing Individual Vulnerability Detection
Chief Executive Officer Kara Sprague highlighted the platform's strategic goal: "The AI era necessitates a security platform that is agentic, continuous, and capable of matching the speed of threats. The H1 Platform effectively bridges the discovery-remediation gap, supported by the trusted Fortune 500 and the largest community of security researchers worldwide."
The global community of security researchers integrates their extensive adversarial expertise, identifying issues that cannot be replicated by automated systems. They uncover flaws, innovative attack methods, and adversarial strategies not found in generic training data. This partnership transforms theoretical risk scores into evidence-backed exploitability confirmations critical for strengthening enterprise security at AI scale.
Implementing Continuous Exposure Management
The H1 Platform incorporates agentic features into a single system unifying discovery
The H1 Platform incorporates agentic features into a single system unifying discovery, validation, prioritization, and remediation to ensure continuous exposure management.
This includes consistent agentic testing across attack surfaces informed by historical data and attack-path analyses; prioritization of vulnerabilities by impact on business and exploitability; integrated workflows for remediation across platforms like Jira, GitHub, and Azure DevOps; and validated, evidence-supported findings sent directly to developers for immediate solutions. Furthermore, executive analytics including Return on Mitigation (RoM) metrics assist in quantitatively assessing exposure reduction and remediation investment priorities.
Optimizing Remediation Investments
Supporting over 1,300 organizations globally, including 20% of the Fortune 500, the H1 Platform enables continuous validation and remediation at scale. HackerOne's customers have collectively reduced more than $32 billion in exposure risk and achieved an 80% reduction in the mean time to remediation (MTTR).
Scott Brown of KOHO Financial commented, "We transitioned from a static security program to one that matches the velocity of threats. Reducing triage time by approximately 80% has transformed our focus to confirmed, exploitable vulnerabilities, averting potential risks before they materialize."
HackerOne, a global pioneer in Continuous Threat Exposure Management (CTEM), announces the H1 Platform, an agentic AI platform designed to help enterprises eliminate exploitable risk with continuous discovery, validation, prioritisation and remediation at AI scale.
The launch comes as the discovery-remediation gap becomes the defining security problem of the AI era. AI is now writing meaningful portions of enterprise code. Recent surveys indicate 73% of engineering teams now use AI coding tools daily, and AI-powered security tools are surfacing vulnerabilities faster than security teams can validate and remediate them. H1 Platform data shows vulnerability submissions up 92% year over year, with critical and high-severity findings climbing while remediation throughput lags by a wide margin.
Remediate exploitable vulnerabilities
The H1 Platform addresses this challenge by applying agentic AI capabilities throughout the CTEM lifecycle to validate and remediate exploitable vulnerabilities. Powered by Hai, HackerOne’s agentic AI orchestrator, the platform correlates exploitability signals, remediation intelligence, and observed attack trends to help organizations prioritise high-impact risk.
“In a world reshaped by frontier AI models, security can’t afford to be static, theoretical, or siloed. It must be continuous, validated, and tied to business impact,” said Nidhi Aggarwal, Chief Product Officer at HackerOne. “As exploit windows shrink and vulnerability volume accelerates, organizations need security systems that can continuously discover and validate what matters, prioritise action, and operationalise remediation at AI scale to continuously reduce cyber risk.”
Finding individual vulnerabilities
"The AI era demands a new kind of security platform: agentic, continuous, and operating at the speed of the threat. The H1 Platform closes the discovery-remediation gap that defines this moment, built on the only foundation that could make it work: the simultaneous trust of the Fortune 500 and the world's largest community of security researchers, sustained over more than a decade,” said Kara Sprague, HackerOne’s Chief Executive Officer. “As enterprises move from securing code to securing AI itself, the researcher community's role on this platform will only deepen."
Central to the H1 Platform is the global community of security researchers, who bring adversarial depth that no automated system replicates. Where Hai delivers speed and scale, the global community pushes beyond what any model can reach, surfacing business logic flaws, novel attack chains, and adversarial techniques no training set contains. The result is evidence-based exploitability confirmation, not theoretical risk scores. As enterprises move from securing code to securing AI itself, the researcher community's contribution to the platform will continue to expand beyond finding individual vulnerabilities to shaping the intelligence that protects enterprises at AI scale.
Continuous exposure management
With agentic capabilities built into the H1 Platform, it unifies discovery, validation, prioritisation, and remediation into a single operational system for continuous exposure management. Key platform capabilities include:
- Continuous agentic testing across the attack surface, with exploitability validation informed by program history and attack-path analysis
- Agentic prioritisation that ranks vulnerabilities based on exploitability and business impact
- Integrated remediation workflows across Jira, GitHub, ServiceNow, Azure DevOps, Linear, and dozens of other enterprise integrations
- Agentic exploitation workflows that generate validated, evidence-backed findings routed directly to developers for immediate remediation
- Board and CISO-level executive analytics, including Return on Mitigation (RoM) metrics, designed to help organizations quantify exposure reduction, prioritise remediation investments, and concretely measure security outcomes
Prioritising remediation investments
The H1 Platform supports 1,300 organizations worldwide, including 20% of the Fortune 500 and AI innovators, helping security teams continuously validate and remediate exploitable risk at scale. Across its customer base, HackerOne has helped organizations mitigate more than $32 billion in exposure risk and reduce mean time to remediate (MTTR) by approximately 80%.
"We went from a set-and-forget security program to one that actually keeps pace with how fast threats move,” said Scott Brown, Security Lead, KOHO Financial. “Reducing median triage time by roughly 80% has changed everything. Our team focuses on what's confirmed and exploitable, and vulnerabilities get addressed before they become real risk."