Powered by: Allows bounty splitting:
Average time to first program response: 12
Average time to bounty awarded null:
Average time to report resolved: 2404
Handle nubank
Managed program: true
Name: Nubank
Offers bounties: false
Offers swag: false
Response efficiency percentage: 96
Submission state: open
Url: https://hackerone.com/nubank
Website: http://nubank.com.br
In scope: Asset identifier: *.cognitect.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.datomic.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.easynvest.com.brAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.investidores.nuAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.investnews.com.brAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.nu.com.arAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.nu.com.coAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.nu.com.mxAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.nubank.com.brAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.nuinternational.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.nuinvest.com.brAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.olivia.aiAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.plataformatec.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.plataformatec.com.brAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.somoszetta.org.brAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.spinpay.com.brAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: 1065904944Asset type: APPLE_STORE_APP_IDAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: 814456780Asset type: APPLE_STORE_APP_IDAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: All other Nubank assetsAsset type: OTHERAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: The scope of this program considers **all Nubank assets**.
Program participants should feel encouraged to report vulnerabilities in assets that are uncertain whether they belong to Nubank. The internal team will analyze all cases and determine whether or not the assets belongs to Nubank.
Below is a list of some examples of other assets from Nubank:
- Other mobile apps developed by Nubank
- Other assets related to Nubank which are from acquisitions or owned by third parties.
- *.nu.bank
- *.nu.com.br
- *.nubank.com.mx
- *.nubank.world
- *.contanu.com
- *.easynvest.io
- *.juntosglobal.com
- *.nubankdev.com
- *.thinkrelevance.com
- *.titulo.com.brIntegrity requirements: Max severity: criticalAsset identifier: br.com.easynvest.rendafixaAsset type: GOOGLE_PLAY_APP_IDAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: com.nu.productionAsset type: GOOGLE_PLAY_APP_IDAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: critical