Bug Bounties

Nord Security

Powered by: 

Allows bounty splitting: 

Average time to first program response: 

Average time to bounty awarded null: 

Average time to report resolved: 

Handle nordsecurity

Managed program: true

Name: Nord Security

Offers bounties: true

Offers swag: false

Response efficiency percentage: 93

Submission state: open

Url: https://hackerone.com/nordsecurity

Website: https://nordsecurity.com/

In scope:

  • Asset identifier: *.nordvpn.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Third-party services under our subdomains are out of scope **(please read full policy for details).**
  • Integrity requirements: low
  • Max severity: critical



  • Asset identifier: 1486322860
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: NordPass - [Apple App Store](https://apps.apple.com/us/app/nordpass-password-manager/id1486322860?ls=1&referrer=client_id=eba15f5b-e4a3-42ca-ba68-e16c170f39e0) Please make sure you are testing the latest version.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: 905953485
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: none
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: NordVPN - [Apple App Store](https://apps.apple.com/US/app/id905953485?mt=8) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: All Mobile Assets
  • Asset type: OTHER
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: iOS: App Store (905953485) NordVPN - [Apple App Store](https://apps.apple.com/US/app/id905953485?mt=8) Please make sure you are testing the latest version. iOS: App Store (1486322860) NordPass - [Apple App Store](https://apps.apple.com/us/app/nordpass-password-manager/id1486322860?ls=1&referrer=client_id=eba15f5b-e4a3-42ca-ba68-e16c170f39e0) Please make sure you are testing the latest version. Android .apk: com.nordvpn.android NordVPN - [Android Sideload Download](https://nordvpn.com/download/android/) Please make sure you are testing the latest version. Android Play Store: com.nordvpn.android NordVPN - [Google Play Store](https://play.google.com/store/apps/details?id=com.nordvpn.android) Please make sure you are testing the latest version. Android Play Store: com.nordpass.android.app.password.manager NordPass - [Google Play Store](https://play.google.com/store/apps/details?id=com.nordpass.android.app.password.manager&launch=true&referrer=client_id=eba15f5b-e4a3-42ca-ba68-e16c170f39e0) Please make sure you are testing the latest version.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: NordLocker - MacOS Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download](https://nordlocker.com/download/mac/) Please make sure you are testing the latest version
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: NordLocker - Windows Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download](https://nordlocker.com/download/windows/) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: NordPass - Linux Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download](https://nordpass.com/download/linux/) Please make sure you are testing the latest version
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: NordPass - MacOS Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download](https://nordpass.com/download/macos/) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: NordPass - Windows Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download](https://nordpass.com/download/windows/) Please make sure you are testing the latest version.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: NordVPN - Linux Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: none
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download](https://nordvpn.com/download/linux/) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: NordVPN - MacOS Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: none
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download](https://nordvpn.com/download/mac/) [MacOS App Store](https://apps.apple.com/us/app/nordvpn-vpn-fast-secure/id905953485) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: NordVPN - Windows Executable
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Direct Web Download]( https://nordvpn.com/download/windows/) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: NordVPN Browser Extension
  • Asset type: OTHER
  • Availability requirement: none
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: * Chrome: https://nordvpn.com/download/chrome-extension/ * Firefox: https://nordvpn.com/download/firefox-extension/ Please make sure you are testing the latest version.
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: com.nordpass.android.app.password.manager
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: NordPass - [Google Play Store](https://play.google.com/store/apps/details?id=com.nordpass.android.app.password.manager&launch=true&referrer=client_id=eba15f5b-e4a3-42ca-ba68-e16c170f39e0) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.nordvpn.android
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: none
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: NordVPN - [Google Play Store](https://play.google.com/store/apps/details?id=com.nordvpn.android) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.nordvpn.android
  • Asset type: OTHER_APK
  • Availability requirement: none
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: NordVPN - [Android Sideload Download](https://nordvpn.com/download/android/) Please make sure you are testing the latest version.
  • Integrity requirements: high
  • Max severity: critical