The Venture Codex Logo

The Venture Codex

HackerOne

22 4th Street, 5th Floor, San Francisco, California, 94103, United States

Overview

HackerOne operates a bug bounty and penetration testing platform that mediates between hackers who find security issues and companies that fix them. The company said it identified over 17,000 high- or critical-severity vulnerabilities in the past year, with over 2,000 vulnerabilities dropped in December following the disclosure of the Log4j bug. HackerOne attributed recent growth to massive cloud adoption during work-from-home orders and a rise in zero-day vulnerabilities, and said the number of cloud misconfigurations that can expose systems or user data doubled in the past year. Customers cited include the U.S. Department of Defense, Google, Dropbox, Microsoft and Twitter. The company plans to use the new funding to invest in research and development and to expand its go-to-market efforts. Financially, HackerOne raised $49 million in a Series E, bringing total capital raised to close to $160 million since its 2012 founding. HackerOne is a seven-year-old, San Francisco–based company that mediates between ethical hackers and organizations to identify and remediate online security vulnerabilities via bug-bounty programs. Its core product is a managed marketplace and platform that coordinates vulnerability disclosure and bounty payments between customers and a large community of security researchers. The company says it works with more than 1,500 customers, including Google, Intel, Airbnb, Alibaba, General Motors and the U.S. Department of Defense, and with hundreds of thousands of individual hackers. HackerOne reports that the average bounty it paid for critical vulnerabilities rose to $3,384 over the last year (a 48% increase), and six hackers on its platform have earned more than $1 million each in lifetime awards. The company is also expanding into blockchain-related work, building a bug-bounty program for Facebook and its partners on the Libra project. Financially, HackerOne has raised a total of $110 million to date following its latest financing. HackerOne operates a bug bounty platform that lets customers offer payments to security researchers to find vulnerabilities in their software. The platform has attracted customers including Snapchat, Uber, GM and the Pentagon and currently supports 700 customers with access to over 100,000 hackers. To date the platform has paid $14 million to hackers (half of that in 2016), with average bounties around $500, minimums of $100 and maximums up to $50,000 (highest paid so far $30,000). Last year the hacker community on the platform tripled and sales grew even faster, according to CEO Mårten Mickos. The company plans to invest in artificial intelligence and machine learning to reduce noise on the platform and increase actionable signal for customers. CEO Mickos said the company did not strictly need the money but accepted the capital to give the business flexibility to pursue new opportunities. HackerOne operates a bug-bounty platform that mixes social features and gamification to surface exploits and share detailed reports among users. Companies offer rewards to hackers who find vulnerabilities, and the platform records participants' skills, reputations and vulnerability details. According to CTO Alex Rice, the platform has uncovered almost 10,000 vulnerabilities and has paid hackers over $3 million. The company serves 250 customers, including Twitter, Slack, Adobe, Yahoo and Airbnb. The three-year-old company says the new funding will help it keep growing as security information-sharing becomes more mainstream. To date the company has raised $34 million across two rounds. HackerOne provides a platform to share security and bug information and to give companies an organized way to set up bug tracking and bounty programs. The service lets organizations offer monetary rewards optionally, or recognize finders via Hall of Fame entries, public thanks, or other non‑monetary rewards. HackerOne takes a 20% cut of any bounty payment when a payment is made. The company has existing clients but this funding round coincides with the first public announcement of the service. As part of the company's growth, former Microsoft lead security strategist Katie Moussouris joined as Chief Policy Officer. Founders include co‑founder and CTO Alex Rice (formerly of Facebook) and co‑founder and CEO Merijn Terheggen.

Total raised
$159M
Funding rounds
5
Latest round
Series E
Latest activity
Jan 2022

Industries

  • Computer
  • Internet
  • Network Security
Visit website

Recent funding

  1. Series E

    Jan 2022

    $49M

  2. Series D

    Sep 2019

    $36M

  3. Series C

    Feb 2017

    $40M

  4. Series B

    Jun 2015

    $25M

  5. Series A

    May 2014

    $9M

Team