goldmansachs

HackerOneView on HackerOne
RawAI Enhanced
46
In Scope
19
Out of Scope
In-Scope Assets (46)
AssetCategoryBountyQuick Links
*.advisorsolutions.gs.comOTHERYes-
*.ayco.comURLYes
*.claritymoney.comURLNo
*.folioclient.comOTHERYes-
*.foliodigitalwealth.comOTHERYes-
*.foliofirst.comOTHERYes-
*.foliofn.comOTHERYes-
*.folioidentity.comOTHERYes-
*.folioinstitutional.comOTHERYes-
*.folioinvesting.comOTHERYes-
*.global-liquidity.gs.comURLYes
*.goldman.comURLYes
*.goldmanpfm.comURLYes
*.goldmansachs.comURLYes
*.gs-mosaic.gs.comURLYes
*.gs-mosaic.qa.gs.comURLYes
*.gs.comURLYes
*.gs.deURLYes
*.gsam.comURLYes
*.gspublishing.comURLYes
*.gsselect.comURLYes
*.honestdollar.comURLYes
*.marcus.co.ukURLYes
*.marcus.comURLYes
*.nextcapital.comOTHERYes-
*.nnip.comOTHERYes-
*.qaglobal-liquidity.gs.comURLYes
*.vennhypotheken.nlOTHERYes-
GS Select iOS appIOSYes-
api.foliofn.comURLYes
apigw.foliofn.comURLYes
com.gs.gsnow.externalIOSYes-
com.gs.gstrader.externalIOSYes-
com.gs.mobile.gsnowANDROIDYes
com.gs.mobile.traderANDROIDYes
com.gs.pfmg.wellnessANDROIDYes
com.gs.pwmdigital.externalIOSYes-
com.gs.pwmdigital.external.androidANDROIDYes
com.marcus.androidANDROIDYes
com.marcus.android.ukANDROIDYes
com.marcus.ios-ukIOSYes-
com.marcus.ios-usIOSYes-
developer.gs.comURLYes
goldmansachsindices.comURLYes
marquee.gs.comURLYes
research.gs.comURLYes
Out-of-Scope Assets (19)
AssetCategoryBounty
*.communicatie.vennhypotheken.nlOTHERNo
*.events.gs.comWILDCARDNo
*.overrules.vennhypotheken.nlOTHERNo
*.rocaton.com,secure.rocaton.comURLNo
*.scripts.vennhypotheken.nlOTHERNo
18098.nextcapital.comURLNo
3rd party hosted assetsOTHERNo
All .cn domainsOTHERNo
billpay.goldman.comURLNo
deb.nextcapital.comURLNo
email.nextcapital.comURLNo
gsg-uk.goldman.comURLNo
gsg.goldman.comURLNo
gspf.goldman.comURLNo
npm-new.nextcapital.comURLNo
npm.nextcapital.comURLNo
qa-billpay.goldman.comURLNo
repo.nextcapital.comURLNo
rubygems.nextcapital.comURLNo
Scope Changes (189)
Mar 13, 2026
ChangeAssetCategoryScopeTime
Removedwww.fitvermogen.nlURLIn Scope16:39
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedcom.marcus.android.ukANDROIDIn Scope19:09
Addedcom.gs.mobile.gsnowANDROIDIn Scope19:09
Addedgsg.goldman.comURLOut of Scope19:09
Added18098.nextcapital.comURLOut of Scope19:09
Added*.global-liquidity.gs.comWILDCARDIn Scope19:09
Addeddeveloper.gs.comURLIn Scope19:09
Added*.gs-mosaic.qa.gs.comWILDCARDIn Scope19:09
Addedcom.gs.gstrader.externalIOSIn Scope19:09
Added*.overrules.vennhypotheken.nlWILDCARDOut of Scope19:09
Addedcom.gs.pfmg.wellnessANDROIDIn Scope19:09
Addedgsg-uk.goldman.comURLOut of Scope19:09
Addeddeb.nextcapital.comURLOut of Scope19:09
Addedemail.nextcapital.comURLOut of Scope19:09
Added*.gs-mosaic.gs.comWILDCARDIn Scope19:09
Addedcom.marcus.ios-ukIOSIn Scope19:09
Addedcom.marcus.androidANDROIDIn Scope19:09
Addedcom.gs.gsnow.externalIOSIn Scope19:09
Added*.rocaton.com,secure.rocaton.comWILDCARDOut of Scope19:09
Added*.goldmanpfm.comWILDCARDIn Scope19:09
Added*.marcus.co.ukWILDCARDIn Scope19:09
Added*.folioclient.comWILDCARDIn Scope19:09
Added*.foliodigitalwealth.comWILDCARDIn Scope19:09
Added*.foliofirst.comWILDCARDIn Scope19:09
Addednpm.nextcapital.comURLOut of Scope19:09
Addedrepo.nextcapital.comURLOut of Scope19:09
Addedall .cn domainsOTHEROut of Scope19:09
Added*.gsselect.comWILDCARDIn Scope19:09
Added*.folioinvesting.comWILDCARDIn Scope19:09
Added*.vennhypotheken.nlWILDCARDIn Scope19:09
Addedcom.gs.pwmdigital.external.androidANDROIDIn Scope19:09
Addedcom.gs.mobile.traderANDROIDIn Scope19:09
Added*.goldman.comWILDCARDIn Scope19:09
Added*.communicatie.vennhypotheken.nlWILDCARDOut of Scope19:09
Addednpm-new.nextcapital.comURLOut of Scope19:09
Addedapi.foliofn.comURLIn Scope19:09
Addedwww.fitvermogen.nlURLIn Scope19:09
Addedbillpay.goldman.comURLOut of Scope19:09
Added*.folioidentity.comWILDCARDIn Scope19:09
Addedrubygems.nextcapital.comURLOut of Scope19:09
Added*.events.gs.comWILDCARDOut of Scope19:09
Addedqa-billpay.goldman.comURLOut of Scope19:09
Addedgoldmansachsindices.comURLIn Scope19:09
Addedresearch.gs.comURLIn Scope19:09
Added*.gsam.comWILDCARDIn Scope19:09
Addedcom.marcus.ios-usIOSIn Scope19:09
Addedapigw.foliofn.comURLIn Scope19:09
Added*.gspublishing.comWILDCARDIn Scope19:09
Added*.qaglobal-liquidity.gs.comWILDCARDIn Scope19:09
Addedcom.gs.pwmdigital.externalIOSIn Scope19:09
Added*.ayco.comWILDCARDIn Scope19:09
Added*.gs.comWILDCARDIn Scope19:09
Added*.advisorsolutions.gs.comWILDCARDIn Scope19:09
Added*.foliofn.comWILDCARDIn Scope19:09
Added*.folioinstitutional.comWILDCARDIn Scope19:09
Added*.nnip.comWILDCARDIn Scope19:09
Addedgs select ios appIOSIn Scope19:09
Added*.nextcapital.comWILDCARDOut of Scope19:09
Addedgspf.goldman.comURLOut of Scope19:09
Added*.scripts.vennhypotheken.nlWILDCARDOut of Scope19:09
Added*.marcus.comWILDCARDIn Scope19:09
Addedmarquee.gs.comURLIn Scope19:09
Added*.claritymoney.comWILDCARDIn Scope19:09
Added3rd party hosted assetsOTHEROut of Scope19:09
Added*.honestdollar.comWILDCARDIn Scope19:09
Added*.gs.deWILDCARDIn Scope19:09
Added*.gs.deWILDCARDIn Scope19:09
Added*.gs.deWILDCARDIn Scope19:09
Added*.gs.deWILDCARDIn Scope19:09
Added*.gs.deWILDCARDIn Scope19:09
Added*.goldmansachs.comWILDCARDIn Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Added*.nextcapital.comWILDCARDIn Scope00:40
Addedcom.gs.mobile.traderANDROIDIn Scope00:40
Added18098.nextcapital.comURLOut of Scope00:40
Added*.qaglobal-liquidity.gs.comWILDCARDIn Scope00:40
Added*.folioinvesting.comWILDCARDIn Scope00:40
Added*.communicatie.vennhypotheken.nlWILDCARDOut of Scope00:40
Added*.folioclient.comWILDCARDIn Scope00:40
Added*.folioidentity.comWILDCARDIn Scope00:40
Added*.vennhypotheken.nlWILDCARDIn Scope00:40
Added*.gs-mosaic.gs.comWILDCARDIn Scope00:40
Addeddeveloper.gs.comURLIn Scope00:40
Addedcom.gs.pwmdigital.externalIOSIn Scope00:40
Added*.goldmansachs.comWILDCARDIn Scope00:40
Added*.goldman.comWILDCARDIn Scope00:40
Addedgoldmansachsindices.comURLIn Scope00:40
Addedcom.gs.pwmdigital.external.androidANDROIDIn Scope00:40
Addedgspf.goldman.comURLOut of Scope00:40
Added*.marcus.co.ukWILDCARDIn Scope00:40
Added*.gsselect.comWILDCARDIn Scope00:40
Added*.foliodigitalwealth.comWILDCARDIn Scope00:40
Addedgsg-uk.goldman.comURLOut of Scope00:40
Added*.advisorsolutions.gs.comWILDCARDIn Scope00:40
Added*.foliofirst.comWILDCARDIn Scope00:40
Addedcom.gs.pfmg.wellnessANDROIDIn Scope00:40
Addedcom.gs.mobile.gsnowANDROIDIn Scope00:40
Added*.rocaton.com,secure.rocaton.comWILDCARDOut of Scope00:40
Added*.rocaton.com,secure.rocaton.comWILDCARDOut of Scope00:40
Added*.gspublishing.comWILDCARDIn Scope00:40
Added*.events.gs.comWILDCARDOut of Scope00:40
Added*.marcus.comWILDCARDIn Scope00:40
Addedgsg.goldman.comURLOut of Scope00:40
Added*.overrules.vennhypotheken.nlWILDCARDOut of Scope00:40
Addeddeb.nextcapital.comURLOut of Scope00:40
Addedrubygems.nextcapital.comURLOut of Scope00:40
Added3rd party hosted assetsOTHEROut of Scope00:40
Added*.honestdollar.comWILDCARDIn Scope00:40
Addedgs select ios appIOSIn Scope00:40
Added*.gs.deWILDCARDIn Scope00:40
Added*.gs.deWILDCARDIn Scope00:40
Added*.gs.deWILDCARDIn Scope00:40
Added*.gs.deWILDCARDIn Scope00:40
Added*.gs.deWILDCARDIn Scope00:40
Addednpm-new.nextcapital.comURLOut of Scope00:40
Addednpm.nextcapital.comURLOut of Scope00:40
Addedqa-billpay.goldman.comURLOut of Scope00:40
Added*.gsam.comWILDCARDIn Scope00:40
Addedcom.gs.gstrader.externalIOSIn Scope00:40
Addedcom.gs.gsnow.externalIOSIn Scope00:40
Added*.claritymoney.comWILDCARDIn Scope00:40
Addedcom.marcus.androidANDROIDIn Scope00:40
Added*.scripts.vennhypotheken.nlWILDCARDOut of Scope00:40
Added*.global-liquidity.gs.comWILDCARDIn Scope00:40
Added*.gs.comWILDCARDIn Scope00:40
Addedwww.fitvermogen.nlURLIn Scope00:40
Addedall .cn domainsOTHEROut of Scope00:40
Added*.foliofn.comWILDCARDIn Scope00:40
Addedcom.marcus.ios-usIOSIn Scope00:40
Added*.ayco.comWILDCARDIn Scope00:40
Addedemail.nextcapital.comURLOut of Scope00:40
Addedrepo.nextcapital.comURLOut of Scope00:40
Addedbillpay.goldman.comURLOut of Scope00:40
Addedresearch.gs.comURLIn Scope00:40
Addedapigw.foliofn.comURLIn Scope00:40
Added*.goldmanpfm.comWILDCARDIn Scope00:40
Addedapi.foliofn.comURLIn Scope00:40
Added*.folioinstitutional.comWILDCARDIn Scope00:40
Addedcom.marcus.ios-ukIOSIn Scope00:40
Added*.gs-mosaic.qa.gs.comWILDCARDIn Scope00:40
Addedmarquee.gs.comURLIn Scope00:40
Added*.nnip.comWILDCARDIn Scope00:40
Addedcom.marcus.android.ukANDROIDIn Scope00:40
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removed*.marcus.comURLIn Scope21:38
Removed*.honestdollar.comURLIn Scope21:38
Removed*.goldmanpfm.comURLIn Scope21:38
Removed*.marcus.co.ukURLIn Scope21:38
Removedresearch.gs.comURLIn Scope21:38
Removed*.gsam.comURLIn Scope21:38
Removed*.gsselect.comURLIn Scope21:38
Removed*.gs-mosaic.qa.gs.comURLIn Scope21:38
Removed*.gs-mosaic.gs.comURLIn Scope21:38
Removed*.qaglobal-liquidity.gs.comURLIn Scope21:38
Removed*.global-liquidity.gs.comURLIn Scope21:38
Removeddeveloper.gs.comURLIn Scope21:38
Removedgoldmansachsindices.comURLIn Scope21:38
Removedmarquee.gs.comURLIn Scope21:38
Removedapigw.foliofn.comURLIn Scope21:38
Removedapi.foliofn.comURLIn Scope21:38
Removed*.advisorsolutions.gs.comOTHERIn Scope21:38
Removed*.folioclient.comOTHERIn Scope21:38
Removed*.foliodigitalwealth.comOTHERIn Scope21:38
Removed*.foliofirst.comOTHERIn Scope21:38
Removed*.foliofn.comOTHERIn Scope21:38
Removed*.folioidentity.comOTHERIn Scope21:38
Removed*.folioinstitutional.comOTHERIn Scope21:38
Removed*.folioinvesting.comOTHERIn Scope21:38
Removed*.nnip.comOTHERIn Scope21:38
Removed*.vennhypotheken.nlOTHERIn Scope21:38
Removedcom.marcus.ios-usIOSIn Scope21:38
Removedcom.marcus.ios-ukIOSIn Scope21:38
Removedcom.marcus.android.ukANDROIDIn Scope21:38
Removedcom.marcus.androidANDROIDIn Scope21:38
Removedcom.gs.pwmdigital.external.androidANDROIDIn Scope21:38
Removedcom.gs.pwmdigital.externalIOSIn Scope21:38
Removedcom.gs.pfmg.wellnessANDROIDIn Scope21:38
Removedcom.gs.mobile.traderANDROIDIn Scope21:38
Removedcom.gs.gstrader.externalIOSIn Scope21:38
Removedcom.gs.mobile.gsnowANDROIDIn Scope21:38
Removedcom.gs.gsnow.externalIOSIn Scope21:38
Removedgs select ios appIOSIn Scope21:38
Removed*.goldmansachs.comURLIn Scope21:38
Removed*.nextcapital.comOTHERIn Scope21:38
Removed*.ayco.comURLIn Scope21:38
Removed*.gs.comURLIn Scope21:38
Removed*.goldman.comURLIn Scope21:38
Removed*.gspublishing.comURLIn Scope21:38
Removed*.gs.deURLIn Scope21:38
Removedwww.fitvermogen.nlURLIn Scope21:38
Added*.claritymoney.comURLIn Scope19:11