HackerOne Pentest as a Service: what you get and what your quote must cover
HackerOne Pentest as a Service is a quoted, fixed-scope penetration test. One to five vetted community testers, not HackerOne employees, work for two weeks, and you get a report and an attestation letter. No dollar price is published. Included retesting lasts 30 or 90 days depending on your tier, so get the tier in writing.
Sources checked October 9, 2026. We read HackerOne's public product, pricing and help-center pages. We did not buy or run a test, and we did not inspect a sample report.
Should you put HackerOne on your shortlist?
Yes, if you need a human-led pentest that ends in a report for an auditor or a customer, and you are fine getting a quote before you see a price.
It deserves a closer look if:
- You need a full report plus a short attestation letter you can hand to a customer.
- You plan several tests a year. HackerOne sells hours you draw down across tests.
- You already run a HackerOne bug bounty or disclosure program.
- You need testers matched by skill, certification or citizenship.
It is probably not your first call if:
- You need a price before you talk to sales.
- Your contract says the testers must be employees of the provider.
- You want one small test and no ongoing platform relationship. That may be possible, but nothing public confirms it.
Four things to get in writing: the pentest size in hours, the tier (Essential or Premium), the total commitment including any platform subscription, and the report date.
Already decided? Have your scope and dates ready and ask HackerOne to price that exact engagement.
Request a scoped HackerOne pentest quote
That link opens HackerOne's sales contact page. It is not a checkout and it does not reserve a start date. HackerOne says its team typically responds within one business day.
What is HackerOne Pentest as a Service, and which offer is it?
It is HackerOne's scoped, time-boxed penetration test, delivered through its online platform. HackerOne now sells it as H1 Pentest and H1 Agentic Pentest. "Pentest as a Service" (PTaaS) is the older label and still appears on the product page.
Two terms, in plain words. A penetration test (pentest) is a planned attack on your systems by people you hired, to find weaknesses before someone else does. PTaaS means the test runs through a platform where you see each finding as it is reported, instead of waiting for a PDF at the end.
HackerOne is best known for bug bounties, and that causes confusion. A pentest is like paying an inspector for a fixed visit with a checklist. A bounty is like posting a reward for anyone who finds a fault. HackerOne draws the same line itself. Its Pentest FAQs say the goal of a pentest is "to help meet regulatory compliance and pass vendor assessments through a structured and checklist-driven process," and they point buyers whose priority is finding critical bugs toward the bounty products.
HackerOne sells four things that sound alike. Only the first two are the pentest.
| Offer | What HackerOne's pages say it is | Fits when | Does not fit when |
|---|---|---|---|
| H1 Pentest | A scoped test by a selected team of community pentesters, with live findings, a report and an attestation letter | You need a defined assessment and evidence you can hand over | The quote leaves out your actual assets, dates or total cost |
| H1 Agentic Pentest | The same pentest with AI agents assisting human testers | You have a large or fast-changing set of web apps and accept AI assistance | Your auditor or customer restricts AI use, or your assets are not "supported web application tests" |
| H1 Continuous Testing | "A fully agentic, always-on testing capability" paid for with Agentic Credits | You want ongoing checks as your app changes | You need a staffed test and a signed-off report. Nothing we read shows this offer supplies that |
| H1 Bounty | A program that rewards researchers for the vulnerabilities they find. Rewards are separate from the subscription, and a service fee applies | You want as many eyes as possible looking for serious bugs | You were asked for a pentest report. A bounty program is not one |
Sources: product page, H1 Pricing, Continuous Testing and Agentic Pentest article (June 3, 2026), Pentest FAQs (July 17, 2024). All provider-published.
Which one to ask about: if someone asked you for "a pentest," start with H1 Pentest. Ask about the agentic version only if you want it. On AI, the product page says: "For supported web application tests, agentic systems may assist with reconnaissance and repeatable validation under strict guardrails. Human pentesters retain full oversight and review all agent findings." If your report recipient cares about AI use, ask HackerOne in writing whether agents will touch your test.
What HackerOne publishes about the pentest, in one table
Most of the buying detail is not on the sales page. It sits in HackerOne's help center, spread across several articles. Here it is in one place. Every row is HackerOne's own published statement, not something we tested.
| Item | What HackerOne publishes | Source and its date | Still to confirm for your quote |
|---|---|---|---|
| What it tests | Web apps, APIs, iOS and Android apps, internal and external networks, cloud, desktop apps, AI and LLM systems, source code audit | Product page | Which of yours are in scope |
| Who tests | Community pentesters, not HackerOne employees | Pentest FAQs, Jul 17, 2024 | The team for your test |
| Team size | One lead plus up to four more testers | Phases and Terminology, Aug 21, 2026 | Your team size |
| Oversight | A HackerOne-employed Technical Engagement Manager runs kickoff, quality checks and wrap-up | Your Pentest Team, Apr 7, 2025 | None |
| Length | 14 calendar days of testing, at every size | Phases and Terminology | Your start date |
| Effort | 40 hours per tester. Sizes run from P40 to P200 | Phases and Terminology | Your size |
| Tiers | Essential and Premium. Customers on the newer platform plans use Premium | Phases and Terminology | Your tier |
| Price | No dollar price on the pentest page or the pricing page. A quote is required | Product page; H1 Pricing | The quote |
| Updates | Findings appear live. Slack updates every 3 to 5 days | Phases and Terminology | None |
| Final report | 3 to 5 business days after testing ends | Phases and Terminology | Your report date |
| Report contents | Executive summary, technical summary, severity scores, retest status, scope, methodology, tools used, testing team | Pentest Deliverables, Jul 17, 2024 | A sample report |
| Attestation letter | A short letter confirming the test and its scope, without the findings | Pentest Deliverables | Whether your recipient accepts a letter alone |
| Retesting | Included for 30 days (Essential) or 90 days (Premium). An older FAQ says 60 days | Three articles, see the retest section | Your tier and window |
| AI use | Agents may assist on supported web app tests. Humans review all agent findings | Product page | Whether agents are used on yours |
| CREST | CREST's own supplier listing shows HackerOne with the Penetration Testing accreditation | CREST listing, checked Oct 9, 2026 | Current status, if your customer requires CREST |
Help-center sources: Phases and Terminology, Pentest Deliverables, Your Pentest Team, Pentest FAQs.
How much does a HackerOne pentest cost?
HackerOne does not publish a dollar price for a pentest. We checked its pentest page and its pricing page on October 9, 2026, and neither shows one. You get a quote based on your scope.
What it does publish is how the price is built. That is enough to make a quote readable.
The pentest is priced by hours. HackerOne's scoping works out how many testing hours your assets need. The number of features and user roles drives the size. The asset type sets the tier. A mobile app, for example, is a Premium test.
You may also be buying a platform plan. The pricing page describes three platform editions: Professional, Enterprise and Enterprise Plus. It says you start with an edition and then "activate the products you need, such as H1 Bounty and H1 Pentest." It also says "Your team gets a clear, itemized quote before any commitment." So ask for the pentest and the platform plan as separate lines.
The pentest part is a fixed cost. HackerOne's FAQ says pentesters are paid a fixed amount per engagement, there are no bounties, and "the total cost is 100% fixed and predictable." That FAQ is dated July 2024, and the pricing page now describes platform editions on top, so treat "fixed" as describing the test, not your whole bill.
An unknown charge is not a zero. If the quote does not say whether a platform plan is required, your total is incomplete.
What do "P40" and "two weeks" mean for effort?
Two weeks is the calendar window, not the amount of work. HackerOne names each size by the total hours the team will spend.
| Size | Team | Total testing hours |
|---|---|---|
| P40 | 1 lead | 40 |
| P80 | 1 lead + 1 tester | 80 |
| P120 | 1 lead + 2 testers | 120 |
| P160 | 1 lead + 3 testers | 160 |
| P200 | 1 lead + 4 testers | 200 |
| Over P200 | Custom | Custom |
Source: Phases and Terminology, August 21, 2026.
Here is our arithmetic. Two calendar weeks hold about 80 working hours for one full-time person. Each tester is expected to put in 40. So a P40 is about one work-week from one person, spread over two calendar weeks. A P200 is five times that.
That is why two quotes for "a two-week pentest" can describe very different amounts of work. Ask for the size.
Can you buy a single pentest?
Probably, but nothing public confirms the terms, so ask. HackerOne's documents describe a quote for each test. For buyers who need several tests, they describe a "consumption contract," where you buy a set number of hours and draw them down during the contract period. Its Spend Tracker article shows customers their hours purchased next to a subscription expiration date.
So put two questions to sales. What is the smallest commitment for one test? And what happens to hours you bought but did not use?
Are pentest hours the same as Agentic Credits?
No. Agentic Credits are a separate prepaid pool for HackerOne's AI products. Its Agentic Credits article lists three products that use them: Asset Intelligence, Continuous Testing and Remediation. The pentest is not on that list. If a quote for an agentic pentest mentions credits, ask what uses them, when they expire and what happens if you run out.
Need a number today? Some providers do publish prices. See the offers with published prices in our comparison. For the wider budgeting picture, see penetration testing cost.
Is retesting included, and for how long?
Yes. Retesting is included for 30 calendar days on the Essential tier and 90 calendar days on the Premium tier, with unlimited retests inside that period at no extra cost. An older HackerOne FAQ says something different, which is why your quote should state the tier and the window.
A retest is when the testers come back and check that your fix worked. Here is what each HackerOne document says.
| HackerOne document | Dated | Written for | What it says |
|---|---|---|---|
| Manage Pentest Retesting | Mar 24, 2026 | Customers | The remediation period is "typically" 30 or 90 calendar days, depending on the type of pentest. Unlimited retests during it, at no extra cost |
| Retesting Pentests | Jun 13, 2025 | Testers | 30 calendar days for Essential, 90 calendar days for Premium. Unlimited retests during the period |
| Pentest FAQs | Jul 17, 2024 | Customers | A 60-day window to start two retests per report, at no additional cost |
Read together, the two newer documents agree: the tier decides the window. The 2024 FAQ does not fit either tier. It may describe an older package. We can't tell from the outside, and HackerOne has not updated it.
One more clue. HackerOne's August 2026 Phases and Terminology article says customers on its newer platform plans use the Premium tier. If that applies to you, the published window would be 90 days. That is our reading of two documents side by side, not a promise from HackerOne. Confirm it.
What the window means on a calendar
The customer guide says retesting support is available after the testing phase ends. Confirm the remediation period's exact start and end dates.
Say testing ends on March 6, the agreed remediation clock treats that date as day zero, and your team needs 45 days to ship the fixes. That puts your retest request on April 20.
- On a 30-day period, the included window closes April 5. Your April 20 request is too late.
- On a 90-day period, the window closes June 4. Your request is inside it.
The same test and the same fixes give two different outcomes, and the only difference is the tier.
What happens after the window closes?
You can still get a retest, but you pay for it. The customer guide says you set a fee for the testing team, with a minimum of $50 per request, and the full amount goes to the pentester. Two conditions apply. Your HackerOne service must still be active, and you need a credit card on file or a pentester fee balance above $50. HackerOne suggests setting a higher fee for findings that are harder to reproduce, so $50 is a floor, not the expected price.
Two smaller points from the same guide. Once a tester picks up your retest request, results usually arrive within 72 hours. And you can ask for a free review of a code fix, before or after the window.
Send this before you sign:
Which tier is this quote, Essential or Premium? How many calendar days is the remediation period, and on what date does it start? Is retesting unlimited inside it? What does a retest cost after it ends, and what do we need in place to request one?
Who does the testing?
Vetted members of HackerOne's researcher community do the testing. They are not HackerOne employees. A HackerOne staff member, the Technical Engagement Manager, runs each engagement.
HackerOne's FAQ puts it plainly: "Pentesters are not HackerOne employees. Tests are conducted by our community." Its vetting article (July 17, 2024) lists what a pentester needs, in HackerOne's words:
- At least three years of professional experience and security testing certifications.
- An identity check and a criminal background check; the article says the background verification is renewed "biannually."
- A probation period covering their first three pentests.
The same article says HackerOne assigns testers based on "their skills, certifications, citizenship, and other customer requirements." So you can ask for restrictions. Every test has a lead who checks and de-duplicates the team's findings before you see them.
These are HackerOne's descriptions of its own process. We have not checked any individual tester's credentials.
The dealbreaker: if your contract, your customer or your insurer requires testers who are employees of the testing company, this model does not meet that requirement as published. Two providers in our comparison, BreachLock and NetSPI, describe in-house testing teams.
Send this before you sign:
Who will test our systems, and what certifications do they hold? Can you limit the team to a specific country or citizenship? Will you name the team before kickoff?
How long until you have the report?
Plan on roughly three to five weeks from the start of scoping to the final report, going by HackerOne's own stated durations and the assumptions below. Fixing and retesting can begin during the test.
| Step | HackerOne's stated duration |
|---|---|
| Scoping and setup | 48 hours to 7 business days |
| Kickoff call | 30 minutes |
| Staffing the team | As little as 3 working days after kickoff |
| Testing | 14 calendar days |
| Final report | 3 to 5 business days after testing |
| Fixes and retests | 30 to 90 days |
Source: Phases and Terminology, August 21, 2026.
Our sum assumes a Monday start, business-day counts that exclude the starting date, three working days for staffing, and no holidays or gaps between stages. Scoping, staffing, testing and reporting take 2 + 5 + 14 + 3 calendar days in the shorter path or 9 + 5 + 14 + 7 in the longer one: about 24 to 35 days including the 30-minute kickoff. It does not include signing the contract or getting test accounts ready on your side, and both can add time.
These are published process times. They are not a booked slot. If you have a deadline, ask for the kickoff date, the test start date and the report date in writing.
A worked example. Say your auditor wants a report by March 31 that shows your fixes were retested. Allow five weeks to the final report and about three weeks to fix and retest. That is eight weeks, so scoping should start by early February, plus however long your contract takes.
Will the report satisfy your auditor or customer?
It may, but only the person receiving the report can say. HackerOne supplies two documents, and you should ask your recipient which one they need.
- A final PDF report. It covers an executive summary, a technical summary, each finding with a severity score and its retest status, the scope, the methodology, the tools used and the testing team.
- A Letter of Attestation. A short document that confirms the test took place and what it covered, without listing the findings. HackerOne says customers use it to show third parties they were tested.
After all reported findings are retested and confirmed fixed by the pentester, you can ask for an updated final report that shows the findings as Fixed. Source: Pentest Deliverables, July 17, 2024.
HackerOne's product page says its reports help you "Meet standards for SOC 2, ISO 27001, GDPR, and more." That is HackerOne's claim. It is not approval from your auditor. We have not read a HackerOne sample report, so ask for one and show it to the person who will rely on it.
Before you buy from anyone, ask your recipient three things. Which systems must the test cover? Is AI-assisted testing acceptable? Do you need proof that the findings were fixed? Our questions for your report recipient has the full list, and what to check in a penetration testing report covers the document itself.
Will your findings stay private?
HackerOne's rules for its pentesters say they should. Its Pentest Rules of Engagement bar testers from disclosing any vulnerability report from a pentest, or even naming the customer, without the customer's explicit written approval. That document is written for testers. Your own confidentiality terms live in your contract, so read those too.
A worked Purchase Check: one SaaS buyer
For a small software company that needs audit evidence, HackerOne is worth a quote. Four answers decide it: the scope, the report date, the retest terms and the total commitment for a single test.
The Purchase Check is how we test an offer. We list what a buyer needs, hold each need against the published terms, and record what the evidence supports.
Say you run a 30-person SaaS company. You have one web app with an API and two user roles. Your auditor asked for a pentest report. Your team will need about 45 days to fix what the test finds. This buyer is made up, and HackerOne has not quoted for it.
| What this buyer needs | How firm | What HackerOne's published terms show | Finding |
|---|---|---|---|
| People do the testing | Must have | A human team. Agents may assist on supported web app tests, with human review | Supported |
| A report and a short letter | Must have | PDF report and Letter of Attestation | Supported |
| The web app and its API in one test | Must have | Both are listed asset types. The quote decides what is included | Unresolved |
| Fixes retested on day 45 | Must have | A request on day 45 of the remediation period is inside a 90-day Premium period and outside a 30-day Essential period. The completion date needs agreement | Unresolved until the quote confirms the tier, the window's start and end dates, and the retest completion date |
| The report by a set date | Must have | Published process times, not a booked date | Unresolved |
| A price before a sales call | Nice to have | None published | Unresolved |
| One test, no ongoing plan | Nice to have | Platform editions and hour contracts are described. The minimum for one test is not | Unresolved |
"Supported" means the published page supports that one need. It is not a rating of HackerOne's testing, and it is not a promise your auditor will accept the report.
What this buyer should do. Ask for a quote. Nothing here rules HackerOne out, but several conditions remain unresolved. But don't sign until four things are in writing:
- The tier. A request on day 45 of a confirmed 90-day Premium period is covered; get the retest completion date in writing. On Essential, budget for paid retests or ask for a longer window.
- The scope. The quote should name the app, the API and both roles.
- The total. If one test requires a platform plan, that changes the comparison with a provider that sells a single test at a listed price.
- The report date. Get the required report date confirmed in writing.
If your own must-haves are different, swap them in. A must-have that the terms can't meet removes the offer for you, however good the rest looks.
When is another route better?
Go another way when something you already have does the job, or when HackerOne can't meet one of your must-haves.
| Your situation | Better route | Where to go |
|---|---|---|
| You are already a HackerOne customer | Check the hours you have before buying more. Existing customers start a new pentest from inside the platform | HackerOne's request steps |
| Your current pentest firm or an included test already covers the request | You may not need to buy anything | Ask your recipient to confirm the scope and the report date they will accept |
| You need a published price | Astra, Pentest-Tools.com and Synack list prices | Our comparison |
| You need provider-employed testers | BreachLock and NetSPI describe in-house teams | Our comparison |
| You want credits for several tests a year from another vendor | Cobalt sells annual credit packages, with its own retest cutoff | Our comparison |
| Your real goal is finding as many serious bugs as you can | A bug bounty, from HackerOne or another platform | Ask about H1 Bounty by name |
| You want to work as a HackerOne pentester | This page is for buyers | HackerOne's pentester application |
The providers are listed A to Z within each row. This is not a ranking. Each one has its own conditions, which are on the comparison page with sources and check dates. Once you have quotes in hand, compare written proposals line by line.
What to send HackerOne before you ask for a quote
Send one short scope and ask for written answers to the terms that can change your purchase. A scope brief works because it asks every provider the same question, so their answers line up.
Copy this, fill in the brackets, and send it.
We are considering HackerOne for a penetration test. Please quote against the scope below and list any assumptions or exclusions.
Why we need it and who will read the report: [auditor, customer, internal team]
Scope: [applications, APIs and versions, environments, user roles, tenant boundaries, key workflows, anything excluded]
Dates: [report needed by; fixes expected to be ready by; proof of fixes needed by]
Please confirm in writing:
- 1. The product (H1 Pentest or H1 Agentic Pentest), the tier (Essential or Premium) and the size in hours.
- 2. How many testers, and how the hours are split between the app and the API.
- 3. Whether AI agents will be used on this test, and for what.
- 4. The total commitment: the test, any required platform plan, the payment schedule, the minimum term, renewal, and what happens to unused hours.
- 5. The kickoff date, the test start date and the final report date.
- 6. The retest period in calendar days, when it starts, whether retests are unlimited inside it, and the cost afterward.
- 7. A sample report and a sample attestation letter.
- 8. Who will test, where they are located, and how our access, data-handling and confidentiality requirements will be met.
This is a buying checklist. It does not give anyone permission to test. Written authorization has to name the real targets and the allowed activities, and it belongs in your contract. Do not put passwords or keys in this message.
If you don't have a written scope yet, start there. Find My PenTest Match walks you through what needs testing and gives you a scope checklist to copy or print and send to whichever providers you choose. It is free and asks for no contact details. It does not pick a provider for you.
Scope already written? Send it with the questions above.
Contact HackerOne about your scope
How we checked this page
On October 9, 2026, we read HackerOne's pentest product page, its pricing page, its pentest contact page, its pentester rules and twelve help-center articles. We lined up what each one says and noted the date each article shows. We also checked CREST's own supplier listing.
Everything in the tables above is HackerOne's published statement unless we say otherwise. The hours arithmetic, the timeline sum, the calendar example and the Purchase Check are our own work on those statements. We did not buy a test, talk to HackerOne, or read a sample report, and no one has confirmed these terms to us in writing. Your contract is what counts.
The PenTest Index does not sell penetration testing, and the links to HackerOne on this page are ordinary links. More on how we check offers and how we make money.
Sources
All checked October 9, 2026. Dates in brackets are the dates HackerOne shows on each article.
- HackerOne, H1 Pentest product page
- HackerOne, H1 Pricing
- HackerOne, Pentest contact page
- HackerOne, Pentest Rules of Engagement (no date shown)
- HackerOne Help Center, Pentest FAQs (July 17, 2024)
- HackerOne Help Center, Manage Pentest Retesting (March 24, 2026)
- HackerOne Help Center, Retesting Pentests (June 13, 2025)
- HackerOne Help Center, Pentest Phases and Terminology (August 21, 2026)
- HackerOne Help Center, Pentest Deliverables (July 17, 2024)
- HackerOne Help Center, Pentester Selection and Vetting Process (July 17, 2024)
- HackerOne Help Center, Your Pentest Team (April 7, 2025)
- HackerOne Help Center, H1 Pentest: Enhanced Pentest Delivery (May 29, 2026)
- HackerOne Help Center, H1 Continuous Testing and Agentic Pentest: Reasoning and Context (June 3, 2026)
- HackerOne Help Center, Request a Pentest (September 15, 2025)
- HackerOne Help Center, Spend Tracker (January 29, 2026)
- HackerOne Help Center, Agentic Credits (August 25, 2026)
- CREST, supplier listing for HackerOne