— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for GoCardless Bug Bounty Program.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 247,
"average_time_to_first_program_response": 9,
"average_time_to_report_resolved": 502,
"handle": "gocardless_bbp",
"id": 0,
"managed_program": true,
"name": "GoCardless Bug Bounty Program",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 96,
"submission_state": "open",
"url": "https://hackerone.com/gocardless_bbp",
"website": "https://gocardless.com",
"targets": {
"in_scope": [
{
"asset_identifier": "*.gocardless-cicd.io",
"asset_type": "WILDCARD",
"availability_requirement": "none",
"confidentiality_requirement": "low",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Non-production environment for infrastructure services.",
"integrity_requirement": "low",
"max_severity": "medium"
},
{
"asset_identifier": "*.gocardless-lab.io",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Testing and experimentation environment for internal tools with no live data.",
"integrity_requirement": "none",
"max_severity": "low"
},
{
"asset_identifier": "*.gocardless.dev",
"asset_type": "WILDCARD",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Playground area for engineers in an isolated environment",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "*.gocardless.io,*.gocardless-banking.io",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "medium",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Internal infrastructure and tools (e.g., performance dashboards).",
"integrity_requirement": "low",
"max_severity": "high"
},
{
"asset_identifier": "api-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Sandbox version of the Merchant Dashboard API component - used to power the Merchant Dashboard (manage.gocardless) and to provide functionality for customers who wish to integrate their services with ours.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "auth0.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "The auth0 authentication endpoint for `bankaccountdata.gocardless.com` - redirected automatically upon visiting. The criticality is capped at `Medium`, because Auth0 is a third-party service and configurable by us only to an extent. If you have found a vulnerability in Auth0, please report it to them first.",
"integrity_requirement": null,
"max_severity": "medium"
},
{
"asset_identifier": "bankaccountdata.gocardless.com",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "!Note that this is a production instance, so you must avoid denial of service, data corruption, and any other destructive or disruptive actions. No automated scanning allowed - manual testing only!\nThis is our Bank Account Data dashboard application and Open Banking API endpoint meant for partners and developers who wish to integrate with our Open Banking APIs.\nAll related findings will be considered Low to Medium impact, since the product is now in maintenance-only mode.",
"integrity_requirement": null,
"max_severity": "high"
},
{
"asset_identifier": "connect-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Sandbox version of the Merchant Dashboard OpenID authentication component.",
"integrity_requirement": null,
"max_severity": "high"
},
{
"asset_identifier": "developer.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Contains only public information, has low business criticality, and has next to no functionality, hence the maximum severity of findings is capped at Low",
"integrity_requirement": null,
"max_severity": "low"
},
{
"asset_identifier": "http://sso-demo.gocardless-staging.io",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "This is a non-production demo app, which does not contain or have access to any production data or services, and hence has no security impact.",
"integrity_requirement": "none",
"max_severity": "low"
},
{
"asset_identifier": "https://github.com/gocardless",
"asset_type": "SOURCE_CODE",
"availability_requirement": "none",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "We require a practical demonstration of exploitability rather than just a code snippet that seems incorrect, because it may be countered by other code operations or integrations.",
"integrity_requirement": "low",
"max_severity": "medium"
},
{
"asset_identifier": "https://ob-sandbox.gocardless.io",
"asset_type": "API",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "This is a sandbox instance for testing the Open Banking (and AIS) flow. Allows to connect to a test institution.",
"integrity_requirement": null,
"max_severity": "medium"
},
{
"asset_identifier": "manage-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": "medium",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Sandbox version of the Merchant Dashboard application's front-end.",
"integrity_requirement": "low",
"max_severity": "high"
},
{
"asset_identifier": "oauth-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The authentication component for GoCardless for Xero (GC4X).",
"integrity_requirement": "medium",
"max_severity": "high"
},
{
"asset_identifier": "ob.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "This is the PRODUCTION endpoint for Account Information Services (AIS) user-facing flow (Bank Account Data (BAcD) and Instant Bank Payments (IBP)). Only gentle manual testing of the workflow can be performed using this instance. No DoS or other destructive testing, no attacks on the infrastructure. Only use sandbox institutions (banks)!",
"integrity_requirement": null,
"max_severity": "medium"
},
{
"asset_identifier": "pay-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Sandbox for the API used to process billing requests, related to the Merchant Dashboard application.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "payer-details-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "This is our new `payer-details` service that allows Payers to update their bank details. It is part of a workflow that is initiated from the Merchant Dashboard (`manage-sandbox.gocardless.com`) by the Merchant to send the Payer a URL that will take them through the `payer-details` workflow to update their details.",
"integrity_requirement": null,
"max_severity": "high"
},
{
"asset_identifier": "www.gocardless.com",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Our public-facing content, without authenticated access to sensitive information related to merchants or payers.",
"integrity_requirement": "low",
"max_severity": "low"
}
],
"out_of_scope": [
{
"asset_identifier": "*.gocardless-staging.io",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Staging environment for GoCardless applications, APIs, and internal tools being developed or supported. Commonly used for testing and development, is identical to the Sandbox environment, in which we prefer the testing to be done.",
"integrity_requirement": "low",
"max_severity": "none"
},
{
"asset_identifier": "api-staging.gocardless.com",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Staging version of the Dashboard API. Please test the Sandbox deployment instead.",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "api.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Production version of the Merchant Dashboard API component.\nPlease test the Sandbox deployment instead.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "brand.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"Webflow\". However, if you think there may be issues related to the configuration of the asset that may be under our control, we will consider the report.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "connect.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Production version of the Merchant Dashboard OpenID authentication component.\nPlease test the Sandbox deployment instead.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "gc4x-api-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": "medium",
"confidentiality_requirement": "medium",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "GC4X users are managed either as Merchant Dashboard (manage-sandbox.gocardless.com) users or with username and password. Read_only Dashboard users don't have access to GC4X, while read_write and admin preserve their permissions. Users who already have a username and password outside of Merchant Dashboard should be able to log in, but no new users should be able to create a username and password not tied to a Merchant Dashboard account.",
"integrity_requirement": "medium",
"max_severity": "none"
},
{
"asset_identifier": "gocardless-status.com, status.gocardless.com",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"Incident.io\".",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "gocardless.atlassian.net",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://github.com/gocardless/woocommerce-gateway-gocardless",
"asset_type": "SOURCE_CODE",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "learn.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"PayTo University\".",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "manage.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "\nProduction version of the Merchant Dashboard application.\nPlease test the Sandbox deployment instead.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "oauth-staging.gocardless.com",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Staging version of the OAuth API. Please test the Sandbox deployment instead.",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "oauth.gocardless.com",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Production version of the authentication component of the GC4X application.\nPlease test the Sandbox deployment instead.",
"integrity_requirement": "medium",
"max_severity": "none"
},
{
"asset_identifier": "outgrow.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"Outgrow\".",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "partnerportal.gocardless.com, gocardless.my.site.com",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"Salesforce\". However, if you think there may be issues related to the configuration of the asset that may be under our control, we will consider the report.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "pay.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "\nProduction version of the API used to process billing requests, related to the Merchant Dashboard application.\nPlease test the Sandbox deployment instead.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "payer-details.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is the production version of our new `payer-details` service that allows Payers to update their bank details. Please do not test against this resource and use the Sandbox version instead.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "privacy.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"Transcend\".",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "qbo-api.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is an API endpoint for a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"Quickbooks\".",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "storybook.gocardless.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a third-party application, which is not developed or maintained by us. Please report vulnerabilities related to this asset directly to \"Storybook\". ",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "support.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is our Zendesk instance. However, it is not under our control, and vulnerabilities should reported directly to Zendesk. If you think there is an issue that is caused specifically by our implementation of Zendesk that is not present in other instances, do let us know, and we can consider issuing a reward.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "xero-sandbox.gocardless.com",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "medium",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "GoCardless integration with Xero (GC4X). Users and permissions are managed through the Dashboard application (manage.gocardless). ReadOnly users cannot access GC4X; ReadWrite and Admin users have the same level of access on GC4X.",
"integrity_requirement": "low",
"max_severity": "none"
},
{
"asset_identifier": "xero-staging.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Testing environment for the GoCardless integration with Xero. Frequently used by merchants for testing implementations.\nPlease test the Sandbox deployment instead.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "xero.gocardless.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Production version of the GoCardless integration with Xero. \nPlease test the Sandbox deployment instead.",
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}*.gocardless.dev· none*.gocardless.io,*.gocardless-banking.io· highapi-sandbox.gocardless.com· criticalauth0.gocardless.com· mediumconnect-sandbox.gocardless.com· highdeveloper.gocardless.com· lowsso-demo.gocardless-staging.io· lowmanage-sandbox.gocardless.com· highoauth-sandbox.gocardless.com· highob.gocardless.com· mediumpay-sandbox.gocardless.com· criticalpayer-details-sandbox.gocardless.com· highgocardless-status.com, status.gocardless.compartnerportal.gocardless.com, gocardless.my.site.com