Bug Bounties

Courier

Powered by: 

Allows bounty splitting: 

Average time to first program response: 4

Average time to bounty awarded null: 

Average time to report resolved: 

Handle trycourier

Managed program: false

Name: Courier

Offers bounties: false

Offers swag: false

Response efficiency percentage: 100

Submission state: open

Url: https://hackerone.com/trycourier

Website: https://www.courier.com

In scope:

  • Asset identifier: *.ct0.app
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: The ct0.app domains are used for click-through tracking.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: api.courier.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This API is used by Courier customers to programmatically send notifications to their users; this is the core use case for our product, without which Courier is of limited value.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: api.trycourier.app
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This API is used by Courier customers to programmatically send notifications to their users; this is the core use case for our product, without which Courier is of limited value.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: www.courier.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: none
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This is our public-facing website. It is a static site, and open source: https://github.com/trycourier/website
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: www.trycourier.app
  • Asset type: URL
  • Availability requirement: medium
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This is our web application, which customers use to design & configure the notifications they will send via our API.
  • Integrity requirements: high
  • Max severity: critical