HackerOne · VDP

Fidelity Vulnerability Disclosure Program

Complete guide to Fidelity's vulnerability disclosure program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

Fidelity runs a vulnerability disclosure program on HackerOne. The program has 20 in-scope assets and is managed by HackerOne's triage team.

20
In-Scope Assets
3h
Avg Response
92%
Efficiency

In-Scope Assets

AssetTypeMax SeverityEligible
*.advisorchannel.comWILDCARDCriticalNo Bounty
*.fidelity.comURLCriticalNo Bounty
*.mystreetscape.comWILDCARDCriticalNo Bounty
*.streetscape.comWILDCARDCriticalNo Bounty
*.wealthscape.comWILDCARDCriticalNo Bounty
com.fidelity.androidGOOGLE_PLAY_APP_IDCriticalNo Bounty
com.fidelity.hcg.healthAPPLE_STORE_APP_IDCriticalNo Bounty
com.fidelity.hcg.healthGOOGLE_PLAY_APP_IDCriticalNo Bounty
com.fidelity.nbmobileAPPLE_STORE_APP_IDCriticalNo Bounty
com.fidelity.sqrlAPPLE_STORE_APP_IDCriticalNo Bounty
com.fidelity.sqrlGOOGLE_PLAY_APP_IDCriticalNo Bounty
com.fidelity.watchlistAPPLE_STORE_APP_IDCriticalNo Bounty
com.fidelity.wi.activityGOOGLE_PLAY_APP_IDCriticalNo Bounty
com.fmr.eca.android.wealthscapeGOOGLE_PLAY_APP_IDCriticalNo Bounty
com.fmr.eca.android.wealthscapeinvestorGOOGLE_PLAY_APP_IDCriticalNo Bounty
mobi.wealthscapeAPPLE_STORE_APP_IDCriticalNo Bounty
mobi.wealthscapeinvestorAPPLE_STORE_APP_IDCriticalNo Bounty
web.fidsafe.comURLCriticalNo Bounty
www.fidelityprivateshares.comURLCriticalNo Bounty
www.fidsafe.comURLCriticalNo Bounty

Out-of-Scope Assets

  • about.fidelity.com
  • activate.fidelity.com
  • activate1.fidelity.com
  • advisorlearning.fidelity.com
  • alertmanagerams.streetscape.com
  • alertstreaming.fidelity.com
  • alertstreaming.streetscape.com
  • alumni.fidelity.com
  • boundless.fidelity.com
  • buildnow.fidelity.com
  • china.fidelity.com
  • corporatearchives.fidelity.com
  • dmt.fidelity.com
  • dmtfi.fidelity.com
  • esgpro.fidelity.com
  • event.fidelity.com
  • fcone.fidelity.com
  • fctms.fidelity.com
  • fidelitydigitalassets.fidelity.com
  • fidtwcms.fidelity.com

Tips for Hacking Fidelity

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking Fidelity?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does Fidelity pay bounties?

No, Fidelity runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.

What types of vulnerabilities does Fidelity accept?

Fidelity accepts reports for vulnerabilities found in their 20 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.