HackerOne has unveiled its H1 Platform, an innovative AI-driven tool for Continuous Threat Exposure Management (CTEM), designed to assist enterprises in addressing cyber risks by perpetually discovering, validating, prioritising, and remediating vulnerabilities on a large scale.
This initiative emerges as AI's increasing role in producing significant portions of enterprise code exposes new security challenges. With 73% of engineering teams using AI coding tools daily, vulnerabilities are being unearthed faster than they can be managed. HackerOne's data reflects a 92% rise in vulnerability submissions year over year, alongside escalating critical and high-severity findings that outpace the rate of remediation.
Addressing exploitable vulnerabilities
The H1 Platform leverages agentic AI within the CTEM cycle to tackle vulnerable security points, employing HackerOne's orchestrator, Hai.
This system integrates exploitability indicators, remediation strategies, and current attack trends to help organisations focus on critical risks. Nidhi Aggarwal, HackerOne’s Chief Product Officer, remarked on the dynamic nature of today's security environment, stating, "As exploit windows shrink and vulnerability volume accelerates, organisations need security systems that can continuously discover and validate what matters."
Uncovering unique vulnerabilities
This collaboration advances the platform's mission beyond individual vulnerability detection
As enterprises shift focus from code security to AI security, the H1 Platform aims to bridge the gap between discovery and remediation. Kara Sprague, CEO of HackerOne, highlighted the importance of the global security researcher community to the platform's success, noting their ability to reveal intricate flaws and adversarial strategies beyond automated system capabilities. This collaboration advances the platform's mission beyond individual vulnerability detection to fostering a deep-rooted security intelligence framework.
The H1 Platform's unified approach encompasses discovery, validation, prioritisation, and remediation as part of an integrated exposure management system. Key functionalities include non-stop agentic testing with vulnerability validation, prioritisation based on the impact and exploitability of threats, and seamless remediation processes through integrations with platforms like Jira, GitHub, and Azure DevOps. Furthermore, comprehensive analytics at the executive level, such as Return on Mitigation metrics, aid organisations in measuring and prioritising security efforts effectively.
Investment in remediation priorities
Supporting over 1,300 global organisations, including a significant portion of the Fortune 500 and AI leaders, the H1 Platform empowers security teams to constantly verify and address exploitable risks.
With HackerOne's assistance, these organisations have mitigated over $32 billion in exposure risk, achieving a notable reduction in mean time to remediate by approximately 80%. Scott Brown, Security Lead at KOHO Financial, praised the platform, stating, "We went from a set-and-forget security program to one that actually keeps pace with how fast threats move," reflecting on the substantial improvements in triage effectiveness and risk management.
HackerOne, a global pioneer in Continuous Threat Exposure Management (CTEM), announces the H1 Platform, an agentic AI platform designed to help enterprises eliminate exploitable risk with continuous discovery, validation, prioritisation and remediation at AI scale.
The launch comes as the discovery-remediation gap becomes the defining security problem of the AI era. AI is now writing meaningful portions of enterprise code. Recent surveys indicate 73% of engineering teams now use AI coding tools daily, and AI-powered security tools are surfacing vulnerabilities faster than security teams can validate and remediate them. H1 Platform data shows vulnerability submissions up 92% year over year, with critical and high-severity findings climbing while remediation throughput lags by a wide margin.
Remediate exploitable vulnerabilities
The H1 Platform addresses this challenge by applying agentic AI capabilities throughout the CTEM lifecycle to validate and remediate exploitable vulnerabilities. Powered by Hai, HackerOne’s agentic AI orchestrator, the platform correlates exploitability signals, remediation intelligence, and observed attack trends to help organisations prioritise high-impact risk.
“In a world reshaped by frontier AI models, security can’t afford to be static, theoretical, or siloed. It must be continuous, validated, and tied to business impact,” said Nidhi Aggarwal, Chief Product Officer at HackerOne. “As exploit windows shrink and vulnerability volume accelerates, organisations need security systems that can continuously discover and validate what matters, prioritise action, and operationalise remediation at AI scale to continuously reduce cyber risk.”
Finding individual vulnerabilities
"The AI era demands a new kind of security platform: agentic, continuous, and operating at the speed of the threat. The H1 Platform closes the discovery-remediation gap that defines this moment, built on the only foundation that could make it work: the simultaneous trust of the Fortune 500 and the world's largest community of security researchers, sustained over more than a decade,” said Kara Sprague, HackerOne’s Chief Executive Officer. “As enterprises move from securing code to securing AI itself, the researcher community's role on this platform will only deepen."
Central to the H1 Platform is the global community of security researchers, who bring adversarial depth that no automated system replicates. Where Hai delivers speed and scale, the global community pushes beyond what any model can reach, surfacing business logic flaws, novel attack chains, and adversarial techniques no training set contains. The result is evidence-based exploitability confirmation, not theoretical risk scores. As enterprises move from securing code to securing AI itself, the researcher community's contribution to the platform will continue to expand beyond finding individual vulnerabilities to shaping the intelligence that protects enterprises at AI scale.
Continuous exposure management
With agentic capabilities built into the H1 Platform, it unifies discovery, validation, prioritisation, and remediation into a single operational system for continuous exposure management. Key platform capabilities include:
- Continuous agentic testing across the attack surface, with exploitability validation informed by program history and attack-path analysis
- Agentic prioritisation that ranks vulnerabilities based on exploitability and business impact
- Integrated remediation workflows across Jira, GitHub, ServiceNow, Azure DevOps, Linear, and dozens of other enterprise integrations
- Agentic exploitation workflows that generate validated, evidence-backed findings routed directly to developers for immediate remediation
- Board and CISO-level executive analytics, including Return on Mitigation (RoM) metrics, designed to help organisations quantify exposure reduction, prioritise remediation investments, and concretely measure security outcomes
Prioritising remediation investments
The H1 Platform supports 1,300 organisations worldwide, including 20% of the Fortune 500 and AI innovators, helping security teams continuously validate and remediate exploitable risk at scale. Across its customer base, HackerOne has helped organisations mitigate more than $32 billion in exposure risk and reduce mean time to remediate (MTTR) by approximately 80%.
"We went from a set-and-forget security program to one that actually keeps pace with how fast threats move,” said Scott Brown, Security Lead, KOHO Financial. “Reducing median triage time by roughly 80% has changed everything. Our team focuses on what's confirmed and exploitable, and vulnerabilities get addressed before they become real risk."