All systems

HackerOne ecosystem Policy

HackerOne Hackbots

The policy layer around AI-assisted vulnerability discovery: human-in-the-loop rules, accountable operators, and bounty eligibility.

0
Indexed entries
0
CVE IDs tracked
0
Critical/high entries
78%
Evidence index

What it is

HackerOne uses “Hackbots” as its term for AI-powered assistants and agents used in vulnerability discovery workflows. The February 2025 HackerOne post is not a single vulnerability finding; it is a policy milestone for how platforms can allow AI-accelerated hacking without dropping accountability.

Why it is in the systems index

Bugflation is partly a technical story and partly a market-structure story. If AI-assisted tools increase submission volume, platforms need rules for scope, oversight, validation, and responsibility.

HackerOne’s public principles are useful because they make the governance layer explicit:

What we do not count

This profile does not add to the findings count. It appears in the systems index because policy infrastructure changes the supply curve: more automated finding attempts become acceptable only when validation and accountability scale with them.

Source