AI-assisted risk selection
HackerOne’s AI technology, Hai, identifies higher-risk code changes and helps filter out low-risk issues so reviewers can focus on the changes most likely to need human attention.
PullRequest is an on-demand code review and code security service with AI-assisted selection and expert human validation to catch bugs, vulnerabilities, and quality issues.
PullRequest, now presented as HackerOne Code, is a code security and review service for development teams that want security feedback inside their normal pull request workflow. It combines AI-based risk selection with expert human review to help teams catch vulnerabilities, bugs, and code-quality issues before code reaches production.
The product is designed to fit existing development tools and processes. The site says it works with major source control platforms, supports all major languages and frameworks, and can be delivered as either a hosted platform or an on-premise installation for enterprise and regulated environments.
HackerOne’s AI technology, Hai, identifies higher-risk code changes and helps filter out low-risk issues so reviewers can focus on the changes most likely to need human attention.
Every finding is manually reviewed and validated by expert engineers before it reaches developers, which is positioned as a way to reduce false positives and improve the quality of feedback.
The service integrates with GitHub, GitLab, Bitbucket, and Azure DevOps, so teams can work in their existing source control tools rather than moving code into a separate system.
Reviewers provide security guidance, bug findings, and code-quality feedback directly in the pull request workflow, helping developers act on issues while the code is still in context.
Project dashboards and weekly digests surface pull request life spans, open pull requests, contribution volume, and comment counts, giving teams review-process visibility.
Enterprise customers can use on-premise installation, SAML single sign-on, API access for custom integrations, and Slack support from the customer success team.
Teams shipping frequent pull requests can use PullRequest to get outside review on important changes without waiting for an internal reviewer to become available.
Security-conscious teams can use the service to catch vulnerabilities earlier in the development cycle, before code is merged and deployed.
Engineering teams dealing with technical debt or review bottlenecks can use the reviewer network to keep work moving while still receiving detailed feedback.
Organizations that need more process visibility can use the dashboards and digests to track pull request activity and spot trends in review throughput.
Enterprise or regulated teams can use the on-premise option and SAML single sign-on to fit stricter infrastructure and access requirements.
PullRequest uses an on-demand code review workflow. The source says reviewers are shown static analysis results and AI-identified risks, then provide actionable feedback on the pull request.
The pricing page says reviews are typically completed during US business hours, and the code review page says reviews are usually completed in less than an hour with a maximum 1-day turnaround depending on size and scope.
The site says it integrates with GitHub, GitLab, Bitbucket, and Azure DevOps, and supports all major languages and frameworks out of the box.
The pricing page says average organizations get around 30-40% of pull requests reviewed with Smart Review Selection, which is designed to focus review effort on the highest-risk changes.
The security policy says PullRequest offers both a hosted SaaS platform and an on-premise solution for behind-the-firewall installation.