Opens in a new tab
vmblog logo 2024 wht (updated)

HackerOne Adds Remediation Capability to Move Validated Security Findings Into Engineering Workflows

Share: 

David Marshall | Published: July 29, 2026

HackerOne has launched H1 Remediation, a new capability designed to help security and engineering teams move validated vulnerabilities from discovery to verified resolution.

Available through the H1 Platform, the capability creates developer-ready fix plans based on a customer’s source code and delivers them into the issue-tracking tools and AI coding agents engineers already use. The plans trace the root cause of a vulnerability to specific lines of code and include technical guidance intended to reduce the back-and-forth that can delay remediation.

The launch comes as organizations face a growing gap between the number of vulnerabilities they can identify and the number they can resolve. According to HackerOne platform data, the backlog of unresolved critical findings grew 29-fold over the past year, despite a more than 50% improvement in mean time to remediate critical issues.

HackerOne said the figures reflect a broader challenge within Continuous Threat Exposure Management, or CTEM. Faster discovery does not necessarily lead to faster risk reduction when security teams cannot provide developers with enough evidence or context to prioritize and resolve a finding.

H1 Remediation is intended to address that problem by generating fix plans only after exploitability and severity have been validated. The guidance is tied to the affected codebase and can include root-cause analysis, language-specific code recommendations, business context and implementation details.

“Boards no longer want to hear how many vulnerabilities were found. They need to know the magnitude of the exposure debt you’re carrying and what you are doing about it,” said Kara Sprague, CEO at HackerOne. “H1 Remediation gives security leaders a defensible answer to both. Every finding carries a documented trail from validated exploitable vulnerability to verified fix, with exposure duration as a measurable, reportable metric. Closing that gap faster is both an operational improvement and a governance imperative.”

The capability can connect with source-code repositories hosted in GitHub, GitLab, Azure DevOps and Bitbucket. It can also draw information from Jira, Linear and Confluence to account for incident history, asset details and other organizational context.

Fix plans can then be delivered as structured tickets in Jira, Linear and ServiceNow, with status updates synchronized back to the H1 Platform. Through HackerOne’s Model Context Protocol server, the same guidance can be accessed within supported development environments and AI coding tools, including Claude Code and Cursor.

“The value for us is in speed to resolution. H1 Remediation hands our engineers clear technical steps already grounded in our own code, so they can move straight to a fix,” said Connor Knabe, Application Security Architect at Veterans United Home Loans. “This results in time saved for the security and product teams. It’s clear this isn’t generic guidance. It’s based on our actual code and fits right into how our team already works, so there’s no new process, just better information showing up exactly where we need it.”

H1 Remediation works with findings generated through HackerOne’s bug bounty, agentic pentesting and continuous testing offerings. Once a finding has been validated, Hai, HackerOne’s agentic AI orchestrator, analyzes the relevant source code and produces a remediation plan.

That validation step is central to HackerOne’s approach. While general-purpose AI coding tools can suggest fixes, H1 Remediation begins with a vulnerability that has already been confirmed as exploitable. The company said this gives developers more confidence that the issue warrants action and that the proposed guidance is tied to a verified security risk.

“Every customer conversation comes back to the same problem: validated findings sitting unresolved because engineering lacks the context to act on them quickly,” said Nidhi Aggarwal, Chief Product Officer at HackerOne. “H1 Remediation extends the workflow from discovery to verified fix. When a fix plan starts from a validated, exploitable finding traced to the actual source code, is informed by the customer’s context, and is delivered into the engineering workflows teams already use, the friction that stalls remediation disappears. Combining agentic capabilities with human ingenuity from the security research community is what gives teams the confidence that what they are fixing is real. That is what turns remediation from a backlog problem into a continuous improvement process that drives measurable risk reduction.”

The platform also includes reporting on resolution rates, mean time to remediate, findings volume and exposure backlog trends. Peer benchmarking and year-over-year comparisons are available for security leaders tracking CTEM performance and reporting risk-reduction progress to executives and boards.

H1 Remediation is generally available through the H1 Platform.