Summary
HackerOne has 3 registry-verified rows in the CertReports index, last verified 17 Sep 2026. The strongest row is FedRAMP: FedRAMP Authorized. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, HackerOne is listed in the FedRAMP registry with a status of FedRAMP Authorized, originally issued 6 May 2020, with Schellman Compliance, LLC as auditor. As of 17 Sep 2026, HackerOne is listed in the CSA STAR registry at STAR Level 1 self-assessment (CAIQ), issued 15 Nov 2020. As of 17 Sep 2026, HackerOne is listed in the EU-US Data Privacy Framework registry as Active for EU-US Certification, SW-US Certification, and UK Extension Certification, with an expiry date of 6 May 2027. As of 17 Sep 2026, no public evidence found for SOC 2 or ISO 27001 frameworks. As of 17 Sep 2026, no public evidence found regarding HIPAA compliance or a business associate agreement (BAA).
- FedRAMP: listed in FedRAMP registry as FedRAMP Authorized (issued 6 May 2020; auditor Schellman Compliance, LLC), as of 17 Sep 2026.
- CSA STAR: listed in CSA STAR registry at Level 1 self-assessment (CAIQ), issued 15 Nov 2020, as of 17 Sep 2026.
- EU-US Data Privacy Framework: listed in DPF registry as Active (EU-US, SW-US, UK Extension Certifications), expiring 6 May 2027, as of 17 Sep 2026.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among security vendors
3verified rows
Category median 1, across 174 indexed security vendors. HackerOne has more verified rows than 100 percent of them.
bug bountysecurity coordinationthreat intelligencevulnerability management
Compare with similar vendors
Pick your own comparisonCompliance grid
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this.
Subprocessors
No subprocessor list captured yet.
Similar vendors with evidence
Related by product tags and the Security category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.