HackerOne today launched H1 Remediation, a new capability in the H1 Platform designed to accelerate the path from validated exposure to verified fix. The feature delivers developer-ready fix plans for findings that have already been validated as exploitable. Each plan is traced to specific lines of code in the customer’s own repositories, enriched with business context, and delivered directly into the tools engineering teams already use — including issue trackers and AI coding agents via Model Context Protocol (MCP).
The launch addresses a widening remediation gap. As AI accelerates vulnerability discovery, the resolution rate for critical-severity findings has fallen even as mean time to remediate improved. According to HackerOne platform data, the backlog of unresolved critical issues has grown significantly over the past year. The bottleneck is often friction between security and engineering: security lacks compelling prioritization data, engineers are skeptical of severity ratings they cannot easily verify, and the two teams operate from different risk frameworks.
H1 Remediation works only from validated, exploitable findings generated across the H1 Platform — including H1 Bounty research, H1 Agentic Pentesting, and H1 Continuous Testing. HackerOne’s agentic AI orchestrator (Hai) traces root cause to actual lines of code and generates fix plans informed by the customer’s environment. Plans can be delivered into Jira, Linear, ServiceNow, and AI coding tools such as Claude Code and Cursor, so engineers can act without waiting for additional security follow-up.
"Boards no longer want to hear how many vulnerabilities were found. They need to know the magnitude of the exposure debt you’re carrying and what you are doing about it,”
“H1 Remediation gives security leaders a defensible answer to both. Every finding carries a documented trail from validated exploitable vulnerability to verified fix, with exposure duration as a measurable, reportable metric. Closing that gap faster is both an operational improvement and a governance imperative."
Kara Sprague, CEO of HackerOne
The capability is generally available in the H1 Platform today.
Conditions Driving the Change
AI is accelerating vulnerability discovery far faster than most security and engineering teams can validate and remediate findings, creating a growing backlog of unresolved critical issues.
Platform data shows that while mean time to remediate critical findings has improved, the overall resolution rate has declined and the backlog of unresolved critical exposures has expanded significantly over the past year.
Security teams often lack the detailed, code-level context needed to make a compelling prioritization case that engineering teams will trust and act on quickly.
Engineering teams remain skeptical of severity ratings and generic guidance when they cannot easily verify root cause or see the issue traced to specific lines in their own codebase.
Security and engineering frequently operate from different risk frameworks and tools, creating friction that slows the path from validated finding to verified fix.
Boards and executives increasingly demand measurable answers about exposure debt and remediation progress rather than simple counts of vulnerabilities discovered.
Developer-ready fix plans must be grounded in the customer’s actual source code and business context, then delivered into the issue trackers and AI coding agents engineers already use, or adoption stalls.
Continuous Threat Exposure Management (CTEM) requires not only continuous discovery and validation but also a faster, lower-friction path to verified remediation if organizations are to reduce real risk rather than accumulate exposure debt.
What Vulnerability Remediation Looked Like Before
Before capabilities such as H1 Remediation, the journey from a validated security finding to a verified fix was frequently slow, fragmented, and full of friction between security and engineering. Security teams identified and validated exploitable issues through bug bounty programs, agentic or traditional penetration testing, and continuous exposure signals. Once validated, findings were typically handed to engineering teams accompanied by severity ratings and relatively generic remediation guidance. Engineers often lacked the precise, code-level detail they needed — specifically, which lines in their own repositories contained the vulnerable logic and how a risky input traveled through the application to cause damage.
The two groups operated from different systems and risk frameworks. Security worked primarily inside exposure and vulnerability platforms; engineering lived in issue trackers, IDEs, and AI coding tools. Business context such as asset criticality, incident history, or operational impact was incomplete or required manual follow-up conversations. As AI accelerated discovery, the volume of validated findings grew faster than the capacity to close them. Even when mean time to remediate improved for some critical issues, overall resolution rates declined and the backlog of unresolved critical exposures expanded significantly. Boards and executives increasingly asked not just how many vulnerabilities had been found, but what the organization was doing about its exposure debt and how quickly real risk was being reduced. Security leaders struggled to provide a clear, defensible trail from validated finding through to verified fix.
“The value for us is in speed to resolution. H1 Remediation hands our engineers clear technical steps already grounded in our own code, so they can move straight to a fix,”
"This results in time saved for the security and product teams. It's clear this isn't generic guidance. It's based on our actual code and fits right into how our team already works, so there's no new process, just better information showing up exactly where we need it.”
Connor Knabe, Application Security Architect at Veterans United Home Loans
What Vulnerability Remediation Looks Like Now
With the launch of H1 Remediation, the workflow now extends continuously from validated, exploitable findings all the way to developer-ready fix plans that engineering teams can act on with far less friction. Fix plans are generated only for findings that have already been confirmed as exploitable through HackerOne’s research community, agentic pentesting, or continuous testing. Root cause analysis connects directly to the customer’s source code repositories (GitHub, GitLab, Azure DevOps, Bitbucket) and traces each issue to the specific lines where vulnerable logic exists. Plans include a clear remediation approach, root-cause explanation, language-specific code change suggestions, business context, and implementation guidance.
"Every customer conversation comes back to the same problem: validated findings sitting unresolved because engineering lacks the context to act on them quickly,"
"H1 Remediation extends the workflow from discovery to verified fix. When a fix plan starts from a validated, exploitable finding traced to the actual source code, is informed by the customer’s context, and is delivered into the engineering workflows teams already use, the friction that stalls remediation disappears. Combining agentic capabilities with human ingenuity from the security research community is what gives teams the confidence that what they are fixing is real. That is what turns remediation from a backlog problem into a continuous improvement process that drives measurable risk reduction.”
Nidhi Aggarwal, Chief Product Officer at HackerOne
Context is further enriched from connected systems such as Jira, Linear, and Confluence, incorporating incident history and asset information so that guidance reflects the customer’s actual environment. Plans are delivered where engineers already work: as structured tickets in issue trackers with automatic status syncing back to the H1 Platform, and directly into AI coding agents such as Claude Code and Cursor via the H1 Platform MCP server. This removes the need for repeated security follow-up and gives engineers the specificity and confidence to act immediately. A dedicated remediation dashboard tracks resolution rate, mean time to remediate by severity, findings flow, and exposure backlog trends, providing security leaders with measurable, board-ready visibility into risk reduction over time. The net result is a lower-friction, more continuous path from validated exposure to verified fix.
Our Take
AI Security Take
HackerOne’s launch of H1 Remediation directly targets one of the most persistent and growing problems in modern security operations: the widening gap between vulnerability discovery and verified remediation. As AI accelerates the pace at which findings are generated, the ability to close validated, exploitable issues has not kept up. The result is expanding exposure debt even when mean time to remediate improves on individual critical findings.
The core contribution of H1 Remediation is removing friction at the point where security and engineering meet. By generating fix plans only for findings that have already been validated as exploitable, tracing root cause to specific lines of code in the customer’s own repositories, enriching those plans with business context, and delivering them into the tools engineers already use (issue trackers and AI coding agents via MCP), the platform reduces the skepticism and follow-up that traditionally slow remediation. Engineers receive actionable specificity rather than generic severity ratings; security teams gain a measurable trail from validated exposure to verified fix.
For security leaders, the practical value extends beyond operational speed. Boards increasingly ask about the magnitude of exposure debt and the concrete actions being taken to reduce it. A remediation dashboard that tracks resolution rates, mean time to remediate by severity, and backlog trends provides a defensible, quantifiable answer. This shifts remediation from a recurring backlog problem into a continuous risk-reduction process that aligns with Continuous Threat Exposure Management (CTEM) goals.
The broader implication is clear. Discovery and validation alone are no longer sufficient. Organizations that cannot rapidly convert validated findings into verified fixes will accumulate risk faster than they can manage it. Solutions that ground remediation guidance in actual source code, respect existing engineering workflows, and measure exposure reduction over time will become essential components of a mature security program. H1 Remediation is a concrete step in that direction — using agentic capabilities and human research together to close the loop from discovery to durable risk reduction.