Integration · Bug Bounty

HailBytes + HackerOne

Researcher findings stop living in a separate system from the rest of vulnerability management.

What you get

  • Scheduled report pull. One program record per HackerOne handle, polled on a schedule — no manual export step and no webhook to maintain.
  • Severity normalisation. HackerOne severities map onto the HailBytes 0–4 scale, so a researcher's Critical and a scanner's Critical mean the same thing in your reporting.
  • Asset back-linking. Each promoted report links to the matching ASM target, which is what makes it appear in the exposure graph rather than as an orphan record.
  • Noise stays out. Triaged, accepted, and resolved reports become vulnerability records. Informative, duplicate, and N/A reports stay informational and never reach the vuln queue.

Why it's worth wiring up

Bug-bounty programs tend to produce excellent findings that then sit in their own console, on their own SLA clock, invisible to the reporting the board sees. Promoted reports flow through the same pipeline as everything else: SIEM forwarding, Jira and ServiceNow ticketing, the exposure graph, and compliance reports.

The practical effect is that a researcher submission and a scanner finding on the same host show up as one exposure story rather than two, and neither gets remediated twice.

Bring your own HackerOne API token. Program fees and researcher payouts stay on your existing engagement.

All bug bounty integrations → API reference → Talk to us →