Learn how to request a pentest with HackerOne. Whether you've run 100 or 0, this guide walks you through requesting pentests no matter what your current status is.
New Customer
Not a current HackerOne customer? No problem! Contact HackerOne to talk to a sales rep, and they will send you a scoping form to discuss the best options for your team and use case.
Current Non-Pentest Customer
These instructions apply if you're currently a HackerOne customer but have never run a pentest before.
Go to Engagements > Pentest.
Click Get started
Click Start a pentest scope
Name your new pentest and add a desired start date, then click Next
The scoping form asks for details such as your goals, desired outcomes, hacker restrictions, and other helpful information. Fill out the form to the best of your abilities, then click Continue. The form auto-saves, so you don't have to worry about losing your progress.
Begin adding information about the assets you want to test. Fill out as much information as you can about each asset. To add another asset, click + Add asset in the left sidebar. The asset type you select determines what fields pop up.
Click Continue.
Review and submit the form for our team to review.
Current Pentest Customer
If you have already run a pentest with us, you can easily request a new one from within the platform.
Go to Engagements > Pentest.
Click New pentest.
Choose to start a new test from scratch or clone a previous one and which subscription you would like to use. Click Next.
The scoping form asks for details such as your goals, desired outcomes, hacker restrictions, and other helpful information. Fill out the form to the best of your abilities, then click Continue. The form auto-saves, so you don't have to worry about losing your progress.
Begin adding information about the assets you want to test. Fill out as much information as you can about each asset. To add another asset, click + Add asset in the left sidebar. The asset type you select determines what fields pop up.
Click Continue.
Review and submit the form for our team to review.
Tip: If you need to run the same pentest regularly, set a calendar reminder to clone your existing one a couple of weeks before it should start!