Bugcrowd publishes penetration testing prices and HackerOne does not. Bugcrowd's AWS Marketplace listing lists Standard Pen Test units at US$5,000 small, US$8,000 medium and US$15,000 large for web applications, US$5,000 for a cloud configuration test, and US$8,000 or US$13,000 for a mobile app on one or two platforms, all sold on a 12-month contract, with the listing stating plainly that "Pricing for Standard Pen Tests and Basic VDP plans are shown in Pricing Information below." HackerOne publishes no penetration testing figure anywhere: hackerone.com/pricing redirects to the platform overview, and the H1 Pentest page routes to a contact form.
That asymmetry is the first thing to know, and it is not the whole comparison. This is a direct head-to-head written from each company's own current pages, fetched and checked on 5 September 2026. Where a figure is not published, this post says "not published" rather than estimating it. It also sets out a third option at the end, because neither of these platforms is the only shape a penetration test can take.
TL;DR: the decision in one table
If this is you | Pick | Why |
|---|---|---|
You need a number you can put in a purchase order this week | Bugcrowd | Standard Pen Test units are listed publicly on AWS Marketplace from US$5,000 |
You already run a HackerOne bug bounty and want testing on the same platform | HackerOne | H1 Pentest, H1 Bounty, H1 Response and H1 Code share one platform and one Hai layer |
Your remediation runs long and you want retesting to outlast the engagement | Bugcrowd | Web app, network and API tests include 12 months of retesting with one report update |
You want AI agents scaling reconnaissance across a large, changing attack surface | HackerOne | H1 Agentic Pentest is built for exactly that, with humans retaining oversight |
You need CREST-certified testers named in the scope | Bugcrowd | CREST certification is an explicit Plus-tier tester requirement you can request |
You want a fixed price with the scope written on the page before you talk to anyone | Stingrai | US$3,000 Autonomous and US$6,800 Hybrid, each covering one web application and its APIs |
The bugs that matter are IDOR, business logic and broken authorization in one authenticated app | Stingrai | Snipe is built for those classes and certified penetration testers work the engagement alongside it |
You want fixes to arrive as pull requests and vulnerable code blocked at merge | Stingrai | AutoFix pull requests and pull request gating; neither platform publishes an equivalent |
You want the same testers on your application every cycle | Stingrai | Employed testers rather than a community matched per engagement |
Quick comparison, with the source for every row
Every cell below traces to the URL in the final column. All rows last verified 5 September 2026.
Dimension | HackerOne | Bugcrowd | Stingrai | Source |
|---|---|---|---|---|
Founded, HQ | 2012, San Francisco | 2012 in Australia; "our headquarters are located in San Francisco, CA and Sydney, Australia", listed at 300 California Street, Suite 220 | 2021, Toronto with a London, UK office at 1 Coldbath Square, Farringdon | |
Pentest product | H1 Pentest and H1 Agentic Pentest | Pen Testing as a Service, Standard, Plus and Max tiers | Autonomous Pentest and Hybrid Pentest | |
Published pentest price | Not published. hackerone.com/pricing redirects to the platform page | US$5,000 small, US$8,000 medium, US$15,000 large web app; US$5,000 cloud config; US$8,000 or US$13,000 mobile, on a 12-month contract | US$3,000 Autonomous, US$6,800 Hybrid, or US$450 and US$1,275 per month | |
Where the price is published | Nowhere | AWS Marketplace, not bugcrowd.com; bugcrowd.com/pricing resolves to the researcher portal | The public pricing page | |
Scope covered by the published price | Not applicable | A unit by size band: small, medium or large web app, one cloud project, or a mobile app on one or two platforms | One web application and its APIs | |
Who tests | A vetted, globally distributed community of testers matched to your asset type and technology stack | Curated tester teams assembled by CrowdMatch AI, rotated "whenever needed" | Employed certified penetration testers working concurrently with Snipe | |
Tester continuity | Stated as a benefit: results "without the need for tester rotation, ensuring deep familiarity with your systems" | CrowdMatch "rotates testers whenever needed" | The same employed team across engagements by default | |
Time to start | Not published | "Launch within 3 business days" on Standard; the platform promises launch "in less than 72 hours" | Scoped per engagement; Autonomous returns same-day results once launched | |
Retesting | "HackerOne provides retesting to confirm that the fixes have been correctly implemented"; term not published | "12 months of retesting (with 1 report update)" for web apps, networks and APIs on Standard, all asset types on Plus | Included in the engagement; automated retests on the Autonomous tier | |
AI layer | H1 Agentic Pentest, "A coordinated system of AI agents and human experts" | Savant Pathseeker, "agentic pentesting on the Bugcrowd Platform", in early access | Snipe, an autonomous web application pentest agent | |
What the AI is allowed to do | "agentic systems may assist with reconnaissance and repeatable validation under strict guardrails", with human testers retaining full oversight and reviewing every agent finding | Not published in detail; the platform describes combining "automated scanners" with "experienced human testers" | Black-box dynamic testing and white-box source review, hunting IDOR, business logic and broken authorization | |
CREST | CREST appears in the compliance logo set on the pentest page | "global CREST accreditation for pen testing"; CREST certification is a named Plus-tier tester requirement | CREST-accredited penetration testing service provider at firm level | |
Compliance framing | Report "Meet standards for SOC 2, ISO 27001, GDPR, and more"; compliance logos include AICPA SOC 2, ISO 27001, CREST, NIST CSF 2.0, FISMA, NIST 800-53, GDPR and DORA | "Meet compliance goals (PCI, HIPAA, GDPR, ISO 27001)" | Reports support SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, NIST SP 800-53 and 800-171, DORA and NIS2 programs | |
Source code review | H1 Code and H1 Code Security Audit are separate products; the pentest page lists Code Security Audit as a testing type | Not published as part of PTaaS | Included: Snipe reads application source alongside dynamic testing | |
Fix automation | H1 Remediation offers "Source code-informed fix plans, delivered straight to engineering" | Not published | AutoFix pull requests | |
Merge protection | Not published | Not published | Gating check on every pull request | |
Outcome guarantee | Not published | Not published | "No High or Critical Finding = Don't Pay" on the Autonomous tier | |
Integrations | "Integrate pentest results into Jira, Slack, GitHub, or ServiceNow" | Prioritised findings flow "directly into existing DevSec tools and processes" | PTaaS portal with Jira, GitHub and Slack |

Pricing: one platform publishes, one does not, and the published one hides it in a marketplace
HackerOne publishes nothing. There is no pricing page. The URL hackerone.com/pricing resolves to the platform overview, and every route from the H1 Pentest page ends at a contact form with the note "Our team typically responds within 1 business day". For a buyer trying to size a budget line before opening a procurement cycle, that is a hard stop.
Bugcrowd publishes, on someone else's website. bugcrowd.com/pricing resolves to the Bugcrowd researcher portal rather than a customer pricing page, so the site itself looks equally opaque. The figures live on the AWS Marketplace listing, where Bugcrowd states: "Pricing for Standard Pen Tests is shown below; for customized testing, contact us about a Plus Pen Test." The listing explains the unit model directly: "You buy each dimension as a separate contract unit, not as a subscription with escalating tiers... Five standard pen test options scale by scope: web app complexity (small, medium, large), one cloud project, or a mobile app on one platform or two platforms." Vulnerability disclosure programmes are also priced there, at US$3,588 for VDP Basic 15 and US$11,988 for VDP Basic 75, while Managed Bug Bounty is "Contact us for pricing."
The listing also states what a Standard unit includes: "Each standard pen test launches within three business days and provides a platform-generated report and the PTaaS dashboard for real-time findings. It integrates with your development workflow. Web app, network, and API tests include 12 months of retesting with one report update."
What this means practically. If you are comparing quotes, Bugcrowd gives you a real anchor and HackerOne does not. If you are comparing what the money buys, note that Bugcrowd's Standard tier delivers a "Platform-generated report" while custom scoping and a custom report sit in the Plus tier, along with the ability to specify tester requirements covering "Geolocation/testing time restrictions, special skill sets, CREST certification, etc."
Staffing: two community models with different continuity promises
Both platforms activate a community rather than an employed bench, and they market opposite properties of that model.
HackerOne sells continuity. The H1 Pentest page describes connecting you to "a vetted pool" of testers and states the approach "delivers fresh insights and consistent, high-quality results without the need for tester rotation, ensuring deep familiarity with your systems", with testers "carefully matched to your asset type and technology stack".
Bugcrowd sells matching and rotation. Its platform's "CrowdMatch AI technology curates qualified, engaged teams for your precise requirements (and rotates testers whenever needed)". Bugcrowd frames the alternative as the problem: "Other pen test providers take a cookie-cutter approach to pen testing regardless of your specific assets, environment, or needs."
Neither claim is wrong. They are answers to different buyer anxieties. If your concern is that a new tester relearns your authorization model every year, HackerOne's framing speaks to you. If your concern is getting a specialist in an unusual technology on short notice, Bugcrowd's does.
Agentic testing: HackerOne draws the boundary in public
This is the section where the two platforms diverge most usefully for a buyer.
H1 Agentic Pentest is described as "built on the proven foundation of H1 Pentest" and taking "a fundamentally different approach from both traditional services and fully autonomous tools. A coordinated system of AI agents and human experts scales reconnaissance, setup, exploitation, and validation across large and changing attack surfaces while preserving judgment, accountability, and trust."
Then HackerOne adds a caveat most vendors would leave out, and it deserves quoting rather than paraphrasing: "For supported web application tests, agentic systems may assist with reconnaissance and repeatable validation under strict guardrails", and human testers "retain full oversight and review all agent findings for quality, accuracy, and relevance".
That is a precise and honest description of a deliberate product boundary. The agents do reconnaissance and repeatable validation on supported web application tests. People do the rest.
Bugcrowd's Savant Pathseeker is announced on the homepage as "agentic pentesting on the Bugcrowd Platform", with an "Apply for Early Access" call to action. Because it is in early access, Bugcrowd does not yet publish a comparable statement of what the agents are permitted to do inside a paid engagement. Ask for that in writing if agentic coverage is part of why you are buying.
Where Stingrai draws it. Snipe is an autonomous web application pentest agent that runs the attack chain itself: black-box dynamic testing and white-box source code review, purpose-built to hunt IDOR, business logic flaws and broken authorization rather than known-class findings, trained on more than 6,000 HackerOne Hacktivity disclosure reports plus methodology distilled from Stingrai's own team. Certified penetration testers work the same engagement at the same time, directing where Snipe focuses and extending the attack paths it opens, with both contributing findings across every severity. Snipe also generates AutoFix pull requests and can run as a gating check that blocks vulnerable code from merging. Neither HackerOne nor Bugcrowd publishes an equivalent to merge gating.
Compliance evidence: what the report is actually for
Both platforms position the pentest report as audit evidence, and both are used that way in practice.
HackerOne states that its final report lets you "Meet standards for SOC 2, ISO 27001, GDPR, and more with a report that proves security due diligence", and its pentest page carries a compliance strip covering AICPA SOC 2, ISO 27001, CREST, NIST CSF 2.0, FISMA, NIST 800-53, GDPR and DORA.
Bugcrowd states that PTaaS helps you "Meet compliance goals (PCI, HIPAA, GDPR, ISO 27001) and surpass them when needed", and it publishes "global CREST accreditation for pen testing" as a platform-level credential. Notably, CREST certification for the individual testers on your engagement is a Plus-tier request rather than a Standard-tier default, which is worth checking if your assessor asks who tested.
Stingrai's penetration testing supports SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, NIST SP 800-53 and 800-171, DORA and NIS2 programs, whether you buy a single annual engagement or a continuous program, and Stingrai holds a firm-level CREST accreditation as a penetration testing service provider. For what an examiner actually asks for, see the pentest evidence auditors accept and will an auditor accept an AI pentest in 2026.
What our own engagement data says about the choice
Stingrai published its platform data in The State of Penetration Testing 2026, and three of those numbers bear directly on this decision. Across 55 penetration tests producing 1,206 verified findings, 92.7% of tests surfaced at least one High or Critical issue, which is the argument against treating any single test as a formality. The verified-finding false-positive rate was 0.74%, which is the number to benchmark any agentic product against when a vendor tells you validation is handled. And Critical findings closed at a median of 10.5 days, which is why retest terms and pull-request-level remediation are worth pricing rather than treating as an afterthought.
Public pricing side by side
HackerOne | Bugcrowd | Stingrai | |
|---|---|---|---|
Web application test, small | Not published | US$5,000 | US$3,000 Autonomous, US$6,800 Hybrid, one web app and its APIs |
Web application test, medium | Not published | US$8,000 | Scoped through Get a Quote |
Web application test, large | Not published | US$15,000 | Scoped through Get a Quote |
Cloud configuration test | Not published | US$5,000 | Scoped through Get a Quote |
Mobile app, one platform | Not published | US$8,000 | Scoped through Get a Quote |
Mobile app, two platforms | Not published | US$13,000 | Scoped through Get a Quote |
Vulnerability disclosure programme | Not published | US$3,588 (Basic 15), US$11,988 (Basic 75) | Not offered |
Bug bounty | Not published | "Contact us for pricing" | Not offered |
Continuous programme, monthly | Not published | Not published | US$450 Autonomous, US$1,275 Hybrid |
Contract term on the published price | Not applicable | 12 months | One-time, or a 12-month engagement |
Retesting | Provided; term not published | 12 months with one report update, web app, network and API | Included |
Outcome guarantee | Not published | Not published | Autonomous tier only |
Sources: Bugcrowd on AWS Marketplace, HackerOne and Stingrai pricing, all verified 5 September 2026. For engagement-level benchmarks beyond these three, see the 2026 penetration testing cost guide.
Best fit by company profile
HackerOne fits you if:
You already run a bug bounty or vulnerability disclosure programme on HackerOne and want testing, response, code security and AI red teaming orchestrated by the same platform layer.
Your attack surface is large and changing, and you want AI agents scaling reconnaissance across it with human testers retaining oversight.
Tester familiarity across cycles matters more to you than a published price.
You want a single vendor across bounty, pentest, code audit and AI red teaming rather than a specialist.
Bugcrowd fits you if:
You need a defensible number before a procurement conversation, and a US$5,000 to US$15,000 band by scope size is enough to build a budget on.
You want to buy through AWS Marketplace and draw down committed cloud spend.
Your remediation cycles run long and 12 months of retesting is a material line item.
You want CREST-certified testers or geographic and timing restrictions written into the scope, and you can buy the Plus tier to get them.
You want methodology-driven testing and bug bounty discovery from the same supplier, which is what the Max tier is for.
Stingrai fits you if:
The test has to be the audit artifact, and you want the price, the scope and the guarantee visible before you speak to anyone.
The bugs that would actually hurt you are authorization and business logic bugs inside one authenticated, multi-tenant application.
You want an AI agent and certified penetration testers on the same engagement at the same time, with source code review inside the engagement rather than sold as a separate product.
You want remediation to arrive as a pull request, and vulnerable code blocked at merge rather than queued in a backlog.
You want the same team on your application every cycle, and both annual one-time tests and continuous programmes available from that team.
None of the three is the answer if you need a US federal 3PAO or a FedRAMP-authorized assessment. That is a different purchase with different vendors.
Frequently Asked Questions
How much does a HackerOne pentest cost in 2026?
HackerOne does not publish a price. The URL hackerone.com/pricing redirects to the platform overview page, and the H1 Pentest product page routes to a contact form with the note "Our team typically responds within 1 business day". No dollar figure for H1 Pentest or H1 Agentic Pentest appears anywhere on hackerone.com. For published comparison points, Bugcrowd lists Standard Pen Test units from US$5,000 on AWS Marketplace, and Stingrai publishes US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest, each covering one web application and its APIs.
How much does a Bugcrowd pentest cost in 2026?
Bugcrowd publishes Standard Pen Test unit prices on its AWS Marketplace listing: US$5,000 for a small web application, US$8,000 for medium, US$15,000 for large, US$5,000 for a cloud configuration test, and US$8,000 or US$13,000 for a mobile app on one or two platforms, all on a 12-month contract. Plus and Max tier pricing is not published; the listing says "for customized testing, contact us about a Plus Pen Test." Note that bugcrowd.com/pricing resolves to the researcher portal rather than a customer pricing page, so the marketplace listing is the place to look.
HackerOne vs Bugcrowd: which is better for penetration testing?
They optimise for different things. Bugcrowd gives you a published unit price, a three-business-day launch and 12 months of retesting with one report update, with CREST-certified testers available as a Plus-tier request. HackerOne gives you tester continuity across cycles, an agentic layer designed for large and changing attack surfaces, and one platform spanning pentest, bounty, disclosure, code audit and AI red teaming. Choose Bugcrowd for a fast, priced, repeatable unit of testing. Choose HackerOne if the pentest is one product inside a platform relationship you already have.
Does HackerOne use AI to run penetration tests?
Partly, and it publishes the boundary. H1 Agentic Pentest is described as "A coordinated system of AI agents and human experts" that "scales reconnaissance, setup, exploitation, and validation across large and changing attack surfaces". The page then states the limit directly: "For supported web application tests, agentic systems may assist with reconnaissance and repeatable validation under strict guardrails", and human testers "retain full oversight and review all agent findings for quality, accuracy, and relevance". So the agents assist on reconnaissance and repeatable validation for supported web application tests, and people keep oversight.
Does Bugcrowd have an agentic pentest product?
It has one in early access. Bugcrowd's homepage announces "Savant Pathseeker, agentic pentesting on the Bugcrowd Platform" with an "Apply for Early Access" call to action. Because it is in early access, Bugcrowd does not yet publish a detailed statement of what the agents are permitted to do inside a paid engagement, so ask for that in writing if agentic coverage is part of your reason for buying.
Do HackerOne and Bugcrowd include retesting?
Both provide it, and only Bugcrowd publishes a term. Bugcrowd states that "Web app, network, and API tests include 12 months of retesting with one report update" on the Standard tier, extended to all asset types on Plus. HackerOne states that "After vulnerabilities are identified and remediated, HackerOne provides retesting to confirm that the fixes have been correctly implemented", but does not publish a window. Stingrai includes retesting in both published tiers, with automated retests on the Autonomous tier.
Is Bugcrowd CREST accredited?
Bugcrowd states that its CrowdMatch approach brings "high-quality results that have earned us global CREST accreditation for pen testing". Separately, the ability to require "CREST certification" of the individual testers on your engagement is listed as a Plus-tier tester requirement rather than a Standard-tier default. HackerOne displays CREST in the compliance logo set on its pentest page. Verify any accreditation on the CREST Marketplace yourself, because accreditations renew on a cycle. Stingrai holds a firm-level CREST accreditation as a penetration testing service provider.
Which platform is better for SOC 2 or ISO 27001 evidence?
Both produce reports used as audit evidence, and both say so. HackerOne states its report helps you "Meet standards for SOC 2, ISO 27001, GDPR, and more". Bugcrowd states PTaaS helps you "Meet compliance goals (PCI, HIPAA, GDPR, ISO 27001)". What actually matters at audit is whether the report documents scope, methodology, severity ratings and retested findings against the exact control your assessor cites, and who performed the testing. Ask for a redacted sample report from either platform, and check whether CREST-certified testers are included at the tier you are buying.
What is the third option, and when does it beat both?
Stingrai. It is the in-house, fixed-price alternative: employed certified penetration testers working the same engagement as Snipe, its autonomous web application pentest agent, at published prices of US$3,000 for an Autonomous Pentest or US$450 per month and US$6,800 for a Hybrid Pentest or US$1,275 per month, each covering exactly one web application and its APIs with retesting included and a "No High or Critical Finding = Don't Pay" guarantee on the Autonomous tier. It beats both when the interesting bugs live in authorization and business logic inside one authenticated application, when you want white-box source review inside the engagement rather than as a separate product, when you want fixes as AutoFix pull requests with a merge gate, and when you want the same team every cycle. For deeper one-to-one comparisons see HackerOne Pentest vs Stingrai 2026 and Bugcrowd alternatives 2026.
Related Reading
Talk to Stingrai
If you are holding a quote from either platform and want to know what it does and does not cover on your most complex application, that is a short scoping conversation with a specific answer. Stingrai scopes against your real architecture: how many tenants, how many roles, where money moves, and what your auditor will ask for. Book a free scoping call, get a quote, or read the published pricing.



