deriv

HackerOneView on HackerOne
RawAI Enhanced
18
In Scope
11
Out of Scope
In-Scope Assets (18)
AssetCategoryBountyQuick Links
*.deriv.cloudWILDCARDYes
*.deriv.comWILDCARDYes
*.derivws.comWILDCARDYes
academy.deriv.comURLNo
api.deriv.comURLYes
app.deriv.comURLYes
cashier.deriv.comURLYes
ct.deriv.comURLNo
deriv.partnersURLNo
derivws.comURLYes
dx-demo.deriv.comURLNo
dx.deriv.comURLNo
github.com/binary-comCODEYes-
github.com/deriv-comOTHERYes-
oauth.deriv.comURLYes
partners.deriv.comURLNo
secure-dfadmin.deriv.comURLYes
smarttrader.deriv.comURLYes
Out-of-Scope Assets (11)
AssetCategoryBounty
*.api-core.deriv.comWILDCARDNo
*.home.deriv.comWILDCARDNo
Any 3rd party managed domainOTHERNo
besquare.deriv.comURLNo
community.deriv.comURLNo
deriv.aeURLNo
deriv.slack.comURLNo
help.deriv.comURLNo
https://deriv.atlassian.net/servicedesk/customer/user/signupURLNo
trade.mql5.comURLNo
tradingview.deriv.comURLNo
Scope Changes (76)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedapp.deriv.comURLIn Scope19:09
Addedcashier.deriv.comURLIn Scope19:09
Addedsecure-dfadmin.deriv.comURLIn Scope19:09
Addedderiv.aeURLOut of Scope19:09
Added*.home.deriv.comWILDCARDOut of Scope19:09
Added*.deriv.cloudWILDCARDIn Scope19:09
Addedgithub.com/binary-comCODEIn Scope19:09
Addedderivws.comURLIn Scope19:09
Addedct.deriv.comURLIn Scope19:09
Addedtrade.mql5.comURLOut of Scope19:09
Added*.api-core.deriv.comWILDCARDOut of Scope19:09
Added*.deriv.comWILDCARDIn Scope19:09
Addedsmarttrader.deriv.comURLIn Scope19:09
Addedgithub.com/deriv-comOTHERIn Scope19:09
Addedderiv.partnersURLIn Scope19:09
Addedderiv.slack.comURLOut of Scope19:09
Addedhelp.deriv.comURLOut of Scope19:09
Addedtradingview.deriv.comURLOut of Scope19:09
Addedcommunity.deriv.comURLOut of Scope19:09
Addedhttps://deriv.atlassian.net/servicedesk/customer/user/signupURLOut of Scope19:09
Addedapi.deriv.comURLIn Scope19:09
Addeddx.deriv.comURLIn Scope19:09
Addedbesquare.deriv.comURLOut of Scope19:09
Addedoauth.deriv.comURLIn Scope19:09
Added*.derivws.comWILDCARDIn Scope19:09
Addedacademy.deriv.comURLIn Scope19:09
Addeddx-demo.deriv.comURLIn Scope19:09
Addedpartners.deriv.comURLIn Scope19:09
Addedany 3rd party managed domainOTHEROut of Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedtrade.mql5.comURLOut of Scope00:40
Addedderiv.aeURLOut of Scope00:40
Addedhelp.deriv.comURLOut of Scope00:40
Addedsmarttrader.deriv.comURLIn Scope00:40
Addedsecure-dfadmin.deriv.comURLIn Scope00:40
Addedacademy.deriv.comURLIn Scope00:40
Addeddx.deriv.comURLIn Scope00:40
Addedpartners.deriv.comURLIn Scope00:40
Added*.api-core.deriv.comWILDCARDOut of Scope00:40
Addedgithub.com/deriv-comOTHERIn Scope00:40
Addedbesquare.deriv.comURLOut of Scope00:40
Addedhttps://deriv.atlassian.net/servicedesk/customer/user/signupURLOut of Scope00:40
Addedcashier.deriv.comURLIn Scope00:40
Added*.derivws.comWILDCARDIn Scope00:40
Addedct.deriv.comURLIn Scope00:40
Addedtradingview.deriv.comURLOut of Scope00:40
Addedapp.deriv.comURLIn Scope00:40
Added*.deriv.cloudWILDCARDIn Scope00:40
Addedoauth.deriv.comURLIn Scope00:40
Addedderiv.partnersURLIn Scope00:40
Added*.home.deriv.comWILDCARDOut of Scope00:40
Addedderivws.comURLIn Scope00:40
Addedderiv.slack.comURLOut of Scope00:40
Addedany 3rd party managed domainOTHEROut of Scope00:40
Added*.deriv.comWILDCARDIn Scope00:40
Addedapi.deriv.comURLIn Scope00:40
Addedgithub.com/binary-comOTHERIn Scope00:40
Addeddx-demo.deriv.comURLIn Scope00:40
Addedcommunity.deriv.comURLOut of Scope00:40
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removed*.deriv.comWILDCARDIn Scope21:38
Removedapp.deriv.comURLIn Scope21:38
Removedsmarttrader.deriv.comURLIn Scope21:38
Removedcashier.deriv.comURLIn Scope21:38
Removed*.deriv.cloudWILDCARDIn Scope21:38
Removedoauth.deriv.comURLIn Scope21:38
Removedapi.deriv.comURLIn Scope21:38
Removedgithub.com/deriv-comOTHERIn Scope21:38
Removedgithub.com/binary-comCODEIn Scope21:38
Removedderivws.comURLIn Scope21:38
Removed*.derivws.comWILDCARDIn Scope21:38
Removedsecure-dfadmin.deriv.comURLIn Scope21:38
Addedacademy.deriv.comURLIn Scope19:11
Addedct.deriv.comURLIn Scope19:11
Addeddx-demo.deriv.comURLIn Scope19:11
Addeddx.deriv.comURLIn Scope19:11
Addedderiv.partnersURLIn Scope19:11
Addedpartners.deriv.comURLIn Scope19:11