onfido

YesWeHackView on YesWeHack
RawAI Enhanced
13
In Scope
7
Out of Scope
In-Scope Assets (13)
AssetCategoryBountyQuick Links
*.identity.entrust.comWILDCARDYes
*.onfido.comWILDCARDYes
*.onfido.partnersWILDCARDYes
https://api.eu-west-1.pre-prod.onfido.xyz/URLYes
https://dashboard-api.eu-west-1.pre-prod.onfido.xyzURLYes
https://dashboard.eu-west-1.pre-prod.onfido.xyzURLYes
https://dashboard.eu-west-1.pre-prod.onfido.xyz/users/sign_up?email=URLYes
https://github.com/EntrustCorporation/IdvSDK-Android/OTHERYes-
https://github.com/EntrustCorporation/IdvSDK-ReactNativeOTHERYes-
https://github.com/EntrustCorporation/IdvSDK-iOSOTHERYes-
https://id.eu-west-1.pre-prod.onfido.xyzURLYes
https://onfido-pre-prod.appURLYes
https://superset.eu-west-1.pre-prod.onfido.xyz/URLYes
Out-of-Scope Assets (7)
AssetCategoryBounty
"Flag an Issue" is the function to send ticket to our ticketing system. Please do not create new tickets when testing and consider it out of scope.OTHERYes
"Leave us some feedback" is a button to send feedback about analytics to a 3rd party integration. Please consider it as out of scope.OTHERYes
Any Third Parties or Software we don't ownOTHERYes
Any asset not explicitly in scopeOTHERYes
In this staging environment we enabled a feature that allows all checks to be completed and get a result (eg. passed or consider). This outcome, however, **is to be considered out of scope** as the checking process is not actually entirely performed, but only serves to mark a check as complete and allow researchers to use functions that are only available when a check is in this status (such as generate a report).OTHERYes
Known issues detailed belowOTHERYes
Only `*.identity.entrust.com` is within the scope of this program so please note that assets under the broader `*.entrust` domain are out of scopeOTHERYes