HackerOne has confirmed that all hackers must now complete identity verification before submitting reports to any bug bounty program (BBP) on its platform, a move the company says is necessary to meet regulatory requirements.
The policy distinguishes bug bounty programs from vulnerability disclosure programs (VDPs), which remain open to unverified researchers since no monetary reward is involved. Anyone hoping to collect a bounty payout or access other reward-based programs will therefore need to go through the verification process first.
How the Verification Process Works
To begin, hackers must visit their User profile page, click the ID Verification header, and first sign HackerOne’s Rules of Engagement, a document covering additional terms tied to increased internal access and credentials that verified hackers may receive.
After reviewing the linked policies and ticking the agreement box, users unlock the Start Verification option, which hands the process over to HackerOne’s identity partner, Veriff.
Veriff relies on real-time image capture, asking applicants to photograph a valid, undamaged government ID and, in most cases, take a live selfie that gets compared against the document.
HackerOne is strict about environment integrity during this step: applicants cannot use a VPN, traffic anonymizer, jailbroken device, SDK emulator, or Apple’s private relay feature, and using any of these will cause an automatic rejection.
Passports, national ID cards, residence permits, and driver’s licenses are generally accepted, though eligible document types vary by country, and only physical, undigitized copies work since Veriff does not process scanned or digital IDs.
Once a session with Veriff concludes, HackerOne typically emails a confirmation of verification status within three business days, and pending reviews can take up to 48 hours before hackers need to consider contacting support.
Verification isn’t a one-time event either — it must be renewed annually, with hackers prompted to re-verify roughly a month before their existing credentials or ID documents expire. Missing that renewal window results in losing access to programs that require verification and the removal of the green verification badge from the hacker’s profile.
HackerOne separates standard ID Verification from its more rigorous H1 Clear program, which layers on a stringent criminal background check and is reserved for a smaller subset of vetted hackers, while basic ID Verification remains open to any eligible researcher.
Hackers who hold Clear status still need to prioritize their annual ID Verification renewal, since lapsing on this requirement puts their Clear privileges at risk too.
Rejections tend to stem from avoidable technical issues rather than identity fraud concerns. Blurry front-image text, unreadable machine-readable zones (MRZ), missing or cut-off barcodes, expired documents, and photocopied IDs instead of live photographs are among the most frequent causes flagged by Veriff’s automated checks.
HackerOne recommends good lighting, removing glasses or headwear, and using supported browsers like Chrome or Safari depending on the device to minimize the risk of a failed session.
For a platform that connects a global community of ethical hackers with enterprise bug bounty programs, this regulatory-driven shift signals tightening compliance expectations across the vulnerability disclosure economy, and researchers actively monetizing their findings should factor the 48-hour to three-business-day review window into their workflow planning.