HackerOne Introduces H1 Remediation to Help Reduce Growing Exposure Backlogs

HackerOne has introduced H1 Remediation, a new capability in the H1 Platform that turns validated security findings into code-specific fix plans for engineering teams.

The product is designed to shorten the time between confirming that a vulnerability is exploitable and completing a verified fix. It analyzes the customer’s source code, identifies the lines linked to the issue and sends remediation guidance into the development and ticketing tools already in use.

The launch comes as security teams face mounting pressure to keep pace with faster vulnerability discovery. HackerOne said its platform data shows that unresolved critical findings increased 29-fold over the past year, despite a more than 50% improvement in mean time to remediate critical issues.

That imbalance has become a central concern for Continuous Threat Exposure Management programs. Finding more vulnerabilities can increase awareness of risk, but it does not reduce exposure unless engineering teams can validate priorities and act on the findings.

H1 Remediation aims to make that handoff more direct. Fix plans are created only for findings whose exploitability and severity have been confirmed, giving developers a clearer basis for action than a severity score alone.

“Boards no longer want to hear how many vulnerabilities were found. They need to know the magnitude of the exposure debt you’re carrying and what you are doing about it,” said Kara Sprague, CEO at HackerOne. “H1 Remediation gives security leaders a defensible answer to both. Every finding carries a documented trail from validated exploitable vulnerability to verified fix, with exposure duration as a measurable, reportable metric. Closing that gap faster is both an operational improvement and a governance imperative.”

Each remediation plan can include root-cause analysis, details on where unsafe input enters the application, the point where it causes damage and code-change recommendations for the relevant programming language.

The plans are grounded in the organization’s own codebase and can be enriched with asset information, incident history and other context drawn from Jira, Linear and Confluence.

H1 Remediation supports repositories hosted on GitHub, GitLab, Azure DevOps and Bitbucket. Completed guidance can be sent to Jira, Linear and ServiceNow as structured tickets, while updates are synchronized with the H1 Platform.

“The value for us is in speed to resolution. H1 Remediation hands our engineers clear technical steps already grounded in our own code, so they can move straight to a fix,” said Connor Knabe, Application Security Architect at Veterans United Home Loans. “This results in time saved for the security and product teams. It’s clear this isn’t generic guidance. It’s based on our actual code and fits right into how our team already works, so there’s no new process, just better information showing up exactly where we need it.”

The capability also connects with development environments and AI coding tools through HackerOne’s Model Context Protocol server. Supported tools include Claude Code and Cursor, allowing engineers to review remediation guidance without leaving their existing workflow.

H1 Remediation works across findings produced through HackerOne’s bug bounty, agentic pentesting and continuous testing services. Once a finding is validated, Hai, HackerOne’s agentic AI orchestrator, reviews the affected code and produces the fix plan.

This process is intended to distinguish the product from general AI coding assistants, which may generate code changes without first confirming that a reported issue is exploitable. HackerOne’s model starts with a validated finding and uses the customer’s environment to shape the recommended response.

“Every customer conversation comes back to the same problem: validated findings sitting unresolved because engineering lacks the context to act on them quickly,” said Nidhi Aggarwal, Chief Product Officer at HackerOne. “H1 Remediation extends the workflow from discovery to verified fix. When a fix plan starts from a validated, exploitable finding traced to the actual source code, is informed by the customer’s context, and is delivered into the engineering workflows teams already use, the friction that stalls remediation disappears. Combining agentic capabilities with human ingenuity from the security research community is what gives teams the confidence that what they are fixing is real. That is what turns remediation from a backlog problem into a continuous improvement process that drives measurable risk reduction.”

H1 Remediation also gives security leaders access to reporting on resolution rates, remediation times, findings volume and exposure backlog trends. Peer comparisons and year-over-year data are included to support executive and board reporting.

The addition extends HackerOne’s CTEM approach beyond identifying and validating exposures into the remediation process itself. H1 Remediation is generally available through the H1 Platform.

 

Join our LinkedIn group Information Security Community!

No posts to display