No more typing reviews! Try our Samantha, our new voice AI agent.

HackerOne vs VAPT comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Vulnerability Management
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
44
Ranking in other categories
Container Security (12th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
HackerOne
Ranking in Vulnerability Management
38th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
11
Ranking in other categories
Application Security Tools (20th), Bug Bounty Platforms (2nd), Penetration Testing Services (2nd), Attack Surface Management (ASM) (7th), AI Observability (17th)
VAPT
Ranking in Vulnerability Management
51st
Average Rating
9.0
Reviews Sentiment
2.2
Number of Reviews
1
Ranking in other categories
Penetration Testing Services (5th), API Security (13th)
 

Mindshare comparison

As of August 2026, in the Vulnerability Management category, the mindshare of Qualys TotalCloud is 1.2%, up from 1.0% compared to the previous year. The mindshare of HackerOne is 0.8%, up from 0.4% compared to the previous year. The mindshare of VAPT is 0.4%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud1.2%
HackerOne0.8%
VAPT0.4%
Other97.6%
Vulnerability Management
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
NitishKumar - PeerSpot reviewer
Consultant at a manufacturing company with 10,001+ employees
Crowdsourced security has strengthened our bug discovery and improved vulnerability response
HackerOne is already doing well, although I believe implementing stricter SLAs for the time to first response and time to bounty would help prevent researchers' burnout, especially regarding duplicate submissions. I suggest systematic bug rewards because currently, if a researcher finds one bug in multiple places, they often only get paid for one. Improving the handling of systemic vulnerabilities would encourage deeper research. Additionally, improving multi-currency and crypto payout options would help make the platform more accessible globally.
Suneel Singh Tomar - PeerSpot reviewer
Assistant Manager, Information Security at Birlasoft IndiaLtd.
Governed layered vulnerability management has improved continuous scanning and remediation
We are using a couple of tools in terms of scanning and remediation. We leverage some of our in-house tools and some cloud tools, so we have a layered security architecture. Some tools work on the transport layer, some on the network layer, and some on the application layer. The team scans across those tool layers. Based on identifying gaps, they fulfill them. Everything feels accurate to me. In today's landscape, we have so many threats and threat actors working around that may damage any available entities. The team scans and finds anything that appears immediately necessary to remediate. They follow the steps accordingly. The team is working around the clock and doing their due diligence on their jobs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud has significantly reduced our workload in terms of managing risks, helping us to be more efficient and save substantial resources."
"Qualys TotalCloud has saved our time by giving us better asset visibility and risk-based prioritization, as it has reduced the time spent manually reviewing CVEs and deciding what to address first."
"While automatic inventory detection upon connection is a helpful feature, a truly valuable capability would be assessing an environment's security posture against Azure and CIS best practices."
"Qualys TotalCloud helps you not just to identify misconfigurations, but you can actually also fix issues."
"One of the most valuable features of Qualys TotalCloud is FlexScan, which is specifically for internet-facing VMs. We found this feature to be very useful. It was a key differentiator for us."
"I like the web API security and IoT scanning features the most. The user-friendly design of TotalCloud's interface enables customers to navigate it and use its full potential easily"
"Generally, Qualys is very good at detections, whether on cloud or on-prem, and the agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us."
"I would definitely recommend Qualys TotalCloud to other users."
"HackerOne has been the right fit for our current situation from both a functionality and cost-effectiveness perspective."
"If you have a very critical vulnerability, some good companies will acknowledge it and pay you accordingly based on severity."
"It helps me to get new sales, profits, and other benefits."
"HackerOne is larger than WebCloud and has a better reputation than BugCloud, which results in a smoother process."
"The fast verification process impacts my motivation significantly because a quick response keeps me motivated, and if I'm going to try and hunt bugs today, I would appreciate a response within the day or at least within a few days."
"One of the biggest strengths is combining a large community of ethical hackers with a structured platform that helps organizations discover, manage, and remediate security vulnerabilities efficiently."
"HackerOne is a very good platform with the trust of different companies including Shopify, PayPal, and Uber, which creates a stronger brand perception and competitive market positioning."
"The most valuable feature of HackerOne is its variety of programs. These programs provide depth into various areas, such as mobile, API, and websites."
"Everything feels accurate to me."
 

Cons

"The support process is inefficient due to the excessive number of replies required when submitting tickets."
"Regarding technical support from Qualys, they respond, but the response time can be too long. Sometimes we need to wait weeks for solutions to simple questions."
"We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage."
"From a downside perspective, the UI is not user-friendly and feels dated compared to other tools like Prisma Cloud."
"With the growing integration of AI, I would like Qualys to enhance its service offerings to better accommodate AI-related risks."
"An area for improvement would be to focus on risks related to AI, such as large language models and potential data leakage."
"There is a lack of data segregation according to criticality or inventory."
"TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these."
"The ability to view the conversation between the triagers and the programs will be really good."
"HackerOne provides a "HackBot" which helps identify other relevant reports, including duplicates, public reports from other companies, etc. However, the functionality is limited and it would be nice to integrate it with broader services offered like auto responses, triggers, etc."
"Triage response time is a significant issue. The response time and triage speed are not fast enough, and this is causing many people to leave HackerOne."
"Everything has become slower on HackerOne."
"However, some things can be improved, such as better report deduplication by automatically identifying duplicate vulnerability reports more accurately."
"Response time can be improved. The HackerOne Trust team can be slow to respond sometimes. They're not using AI, which could help reduce the number of duplicate reports."
"One limitation is that if a finding has been reported on HackerOne and was also reported earlier by another user or outsider, the platform is not able to collate that information together."
"However, I reduced my rating by one mark because a proper internal triage team should be in place, not as a replacement for internal security controls."
"There are so many challenges while running this vulnerability program."
 

Pricing and Cost Advice

"Qualys TotalCloud offers cost-effective licensing flexibility."
"Qualys TotalCloud is expensive."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"The tool is open-source and free for bug bounty hunters."
"The solution is free."
Information not available
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
911,493 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
13%
Manufacturing Company
12%
Outsourcing Company
12%
Financial Services Firm
10%
Comms Service Provider
12%
Manufacturing Company
11%
Financial Services Firm
10%
Computer Software Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise5
Large Enterprise32
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise1
Large Enterprise7
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
To be totally honest, I do not have any best features because I have had a bad experience using this tool, especially...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is vulnerability management and exposure management. I use this tool to evalua...
What is your experience regarding pricing and costs for HackerOne?
I'm not very sure about pricing, setup costs, and licensing, as those are managed by our management team.
What needs improvement with HackerOne?
HackerOne can be improved, and the insights can be a little better. I chose a nine for my rating because it has very ...
What is your primary use case for HackerOne?
My main use case for HackerOne is bug bounties and getting paid through that platform. Companies like Fastify and Ora...
What needs improvement with VAPT?
There are so many challenges while running this vulnerability program. It is a very complex program where everyone ha...
What is your primary use case for VAPT?
I am in a position where we govern VAPT and vulnerability management programs. My associates initiate quick scans of ...
What advice do you have for others considering VAPT?
I did not use Redscan at all. I have used formal VAPT services in my SOC role. In terms of focusing on prioritization...
 

Comparisons

 

Also Known As

Qualys TotalCloud with FlexScan
HackerOne Assets, HackerOne Pentesting Services, HackerOne Security Assessments, HackerOne Vulnerability Management
No data available
 

Overview

 

Sample Customers

Information Not Available
Anthropic, Crypto.com, General Motors, GitHub, Goldman Sachs, Uber, and the U.S. Department of Defense
Information Not Available
Find out what your peers are saying about Wiz, Qualys, Tenable and others in Vulnerability Management. Updated: August 2026.
911,493 professionals have used our research since 2012.