Bug Bounties

Ro

Powered by: 

Allows bounty splitting: 

Average time to first program response: 7

Average time to bounty awarded null: 

Average time to report resolved: 1014

Handle ro

Managed program: true

Name: Ro

Offers bounties: false

Offers swag: true

Response efficiency percentage: 100

Submission state: open

Url: https://hackerone.com/ro

Website: https://ro.co

In scope:

  • Asset identifier: *.getroman.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: *.hellorory.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: *.modernfertility.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: *.myplenity.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: none
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: none
  • Max severity: low



  • Asset identifier: *.ro.co
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: *.ropharmacy.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: 1514854156
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: The latest version of iOS app installed from the official store at: https://apps.apple.com/us/app/ro/id1514854156
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: 1585858911
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: The latest version of iOS app installed from the official store at: https://apps.apple.com/us/app/ro/id1585858911
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: login.ro.co
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: Our custom domain for SSO through Auth0
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: my.ro.co
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: Must have an account that is created through an Online Visit (OV). For example, through the online visit at https://www.getroman.com/
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: ro.co/derm
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: ro.co/mind
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: ro.co/pharmacy
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: ro.co/spermkit
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: start.ro.co
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: Online visits from any of our products (getroman.com, ro.co/mind, etc) will redirect to start.ro.co. Navigating directly to start.ro.co without beginning from an OV only redirects to ro.co
  • Integrity requirements: high
  • Max severity: critical