HackerOne Mandates ID Verification for Bug Bounty Submissions
Key Takeaways HackerOne now requires all researchers submitting to bug bounty programs (BBPs) to complete identity verification. This new policy is driven by regulatory compliance requirements....
Key Takeaways
- HackerOne now requires all researchers submitting to bug bounty programs (BBPs) to complete identity verification.
- This new policy is driven by regulatory compliance requirements.
- Vulnerability Disclosure Programs (VDPs) that do not offer monetary rewards are exempt from this verification.
- The process involves an annual renewal and uses a third-party identity verification service, Veriff.
- Failure to verify or renew will result in loss of access to reward-based programs.
HackerOne has implemented a mandatory identity verification process for all researchers wishing to submit reports to bug bounty programs (BBPs) on its platform. The company states this significant policy change is necessary to comply with evolving regulatory obligations.
This new requirement differentiates BBPs, which involve financial compensation, from standard vulnerability disclosure programs (VDPs). VDPs, where no monetary rewards are offered, will continue to be accessible to unverified researchers. However, any individual seeking to receive a bounty payout or participate in other reward-centric programs must first complete the identity verification process.
The Verification Process Explained
To initiate identity verification, hackers must navigate to their User profile page and select the ID Verification header. The first step involves signing HackerOne’s Rules of Engagement, a document outlining additional terms associated with the enhanced internal access and credentials granted to verified hackers.
After reviewing the linked policies and confirming agreement, users can proceed by selecting the “Start Verification” option. This action transfers the verification process to HackerOne’s trusted identity partner, Veriff.
Veriff employs real-time image capture technology, requiring applicants to photograph a valid, undamaged government-issued identification document. In most instances, a live selfie is also required, which Veriff then compares against the provided ID for authentication.
HackerOne maintains strict integrity requirements for the verification environment. The use of virtual private networks (VPNs), traffic anonymizers, jailbroken devices, SDK emulators, or Apple’s Private Relay feature is strictly prohibited during this step. Any attempt to use these tools will result in an automatic rejection of the verification attempt.
Accepted identification documents generally include passports, national ID cards, residence permits, and driver’s licenses. It is important to note that eligible document types may vary by country. Veriff exclusively processes physical, undigitized copies; scanned or digital IDs are not accepted.
Upon completion of the session with Veriff, HackerOne typically sends an email confirming the verification status within three business days. If a review is pending for more than 48 hours, researchers may consider contacting support.
Identity verification is not a one-time procedure; it requires annual renewal. Hackers will receive a prompt to re-verify approximately one month before their existing credentials or ID documents are set to expire. Failure to complete this annual renewal will result in the loss of access to programs requiring verification and the removal of the green verification badge from the hacker’s profile.
HackerOne distinguishes its standard ID Verification from the more stringent H1 Clear program. H1 Clear involves a comprehensive criminal background check and is reserved for a select group of thoroughly vetted hackers. The basic ID Verification, however, remains accessible to any eligible researcher.
Hackers who hold Clear status must also prioritize their annual ID Verification renewal, as a lapse in this requirement could jeopardize their Clear privileges.
Most rejections during the verification process are attributed to avoidable technical issues rather than concerns about identity fraud. Common reasons flagged by Veriff’s automated checks include blurry text on the front image, unreadable machine-readable zones (MRZ), missing or cut-off barcodes, expired documents, and submissions of photocopied IDs instead of live photographs.
HackerOne advises applicants to ensure good lighting, remove glasses or headwear, and use supported browsers such as Chrome or Safari, depending on the device, to minimize the likelihood of a failed verification session.
This regulatory-driven shift signifies a tightening of compliance expectations across the vulnerability disclosure ecosystem. For a platform that connects a global community of ethical hackers with enterprise bug bounty programs, researchers actively monetizing their findings should incorporate the 48-hour to three-business-day review window into their operational planning.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.