{"id":"b406940a-3bf6-4b05-ac3b-a8110ab53e81","engagementId":"cc14cffb-efc9-45a0-bcbc-9575d7fc12a0","data":{"brief":{"id":"4b37d771-dcfe-4d2e-929a-bdde0ab2ef63","name":"Wise (ex-TransferWise)","tagline":"Wise — the global technology company building the best way to move money around the world.","description":"\u003cp\u003eWe are committed to ensuring a safe and secure service for our customers and we value the work done by security researchers in improving the security of our products. We are committed to working with this community to verify, reproduce, and respond to reported vulnerabilities. We encourage the community to participate in our responsible reporting process.\u003c/p\u003e\n\n\u003ch3\u003eExpectations\u003c/h3\u003e\n\n\u003cp\u003eWhen participating in our responsible reporting process, you can expect us to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWork with you to understand and validate your report, including a timely triage of your submission by our partner, Bugcrowd\u003c/li\u003e\n\u003cli\u003eWork to remediate discovered vulnerabilities in line with our internal vulnerability management policy (from 1 to 180 days depending on severity)\u003c/li\u003e\n\u003cli\u003eKeep you informed when the issue is fixed; and\u003c/li\u003e\n\u003cli\u003eIf eligible, reward you accordingly\u003c/li\u003e\n\u003cli\u003e Wise employees are not allowed to participate in your program\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eThird-party bugs\u003c/h3\u003e\n\n\u003cp\u003eIf issues reported to our bug bounty program affect a third-party library, external project, or another vendor, we reserve the right to forward details of the issue along to that party without further discussion with you (the researcher). We will do our best to coordinate and communicate with you throughout the process. However, these bugs will not be rewarded.\u003c/p\u003e\n\n\u003ch3\u003eHouse Rules\u003c/h3\u003e\n\n\u003cp\u003eTo benefit from the knowledge of security researchers, we encourage responsible disclosure of vulnerabilities in our platform. To avoid confusion between legitimate security research through the Bugcrowd program and a malicious attack, we ask that you attempt, in good faith, to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlay by the rules. This includes following our disclosure policy, including Bugcrowd’s standard\ndisclosure terms and any other relevant agreements;\u003c/li\u003e\n\u003cli\u003eHandle the confidentiality of details of any discovered vulnerabilities according to our Disclosure Policy;\u003c/li\u003e\n\u003cli\u003eReport any vulnerability you’ve discovered promptly, provide details of the vulnerability, including\ninformation needed to reproduce and validate the vulnerability and if applicable, a Proof of Concept;\u003c/li\u003e\n\u003cli\u003ePerform testing only on in-scope systems, and respect systems and activities which are out-of-scope;\u003c/li\u003e\n\u003cli\u003eAvoid violating the privacy of others, disrupting our systems, destroying or modifying data not belonging\nto your test account, and/or harming user experience;\u003c/li\u003e\n\u003cli\u003eIf a vulnerability provides unintended access to data: limit the amount of data you access to the\nminimum required for effectively demonstrating a Proof of Concept (PoC); and cease testing. Submit a\nreport immediately if you encounter any user data during testing, such as Personally Identifiable\nInformation (PII), sensitive data, or proprietary information;\u003c/li\u003e\n\u003cli\u003eAlthough usage of automated vulnerability discovery tools is allowed, you should exercise common sense and avoid overly broad\nscans that initiate a huge amount of needless requests. This might result in us rate-limiting or blocking\nyou, or closing your testing account. Do not simply send us a scanner's default output - focus on specific finding and clearly demonstrate impact (PoC). When scanning, use your Bugcrowd testing account (authenticated scans) or make it clear with the \u003ccode\u003eUser-Agent\u003c/code\u003e header that you are a researcher. As we're seeing legitimate attacks, this information is useful for us for triage;\u003c/li\u003e\n\u003cli\u003eYou should only interact with test accounts you own;\u003c/li\u003e\n\u003cli\u003eDo not engage in extortion;\u003c/li\u003e\n\u003cli\u003eUse the official Bugcrowd channel to discuss vulnerability information with us;\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSafe-harbour Compliance\u003c/h3\u003e\n\n\u003cp\u003eWe consider activities conducted consistent with this policy to constitute “authorized” access under anti-hacking laws. To the extent your activities are inconsistent with certain restrictions in our Acceptable Use Policy, we waive those restrictions for the limited purpose of permitting security research under this policy. We will not bring a claim against you for circumventing the technological measures we have used to protect the applications in scope. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. We will not pursue civil action or initiate a complaint to law enforcement for accidental, good faith violations of this policy.\u003c/p\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please reach out to us directly before going any further.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003ePGP Fingerprint: C8A1 9A40 C078 006A 4FD2 5F88 EC52 91DC 8DC2 8D45\nPGP key published at: pgp.mit.edu\nmailto: soc [@] wise.com\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003ch3\u003eDisclosure Policy\u003c/h3\u003e\n\n\u003cp\u003eThis program does not allow disclosure. Although we have chosen to adopt a non-disclosure policy, this is temporary. In the meantime, you MUST not release information to any third party (and the public) about vulnerabilities found and/or remediation measures implemented.\u003c/p\u003e\n\n\u003ch3\u003ePriority Modelling\u003c/h3\u003e\n\n\u003cp\u003eThis program adheres to the Bugcrowd Vulnerability Rating Taxonomy for the severity rating and prioritization of issues.\u003c/p\u003e\n\n\u003ch3\u003eResponsible Disclosure Guidelines\u003c/h3\u003e\n\n\u003cp\u003eWe will investigate legitimate reports and make every effort to quickly correct any vulnerability. To encourage responsible reporting, we will not take legal action against you nor ask law enforcement to investigate you providing you comply with the following Responsible Disclosure Guidelines:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eProvide details of the vulnerability, including information needed to reproduce and validate the vulnerability and a Proof of Concept (POC)\u003c/li\u003e\n\u003cli\u003eMake a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services\u003c/li\u003e\n\u003cli\u003eDo not modify or access data that does not belong to you\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThis program adheres to the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e for the rating/prioritization of issues. \u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003ch3\u003eAccess\u003c/h3\u003e\n\n\u003cp\u003eWhen registering for an account at https://wise.com for testing purposes, use your \u003ccode\u003e@bugcrowdninja\u003c/code\u003e e-mail, i.e. \u003ccode\u003e\u0026lt;bugcrowdusername\u0026gt;@bugcrowdninja.com\u003c/code\u003e.  You can also use alias emails when multiple accounts are required for testing, i.e. \u0026lt;bugcrowdusername\u0026gt;+1@bugcrowdninja.com. \u003c/p\u003e\n\n\u003cp\u003eDo not use any other e-mails, unless testing for a specific bug that requires this. Avoid creating excessive amount of users.\u003c/p\u003e\n\n\u003cp\u003eAccounts and / or IPs that violate this guideline can be blocked.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eWe are constantly updating our services to make transfer of funds low-cost, fair, easy and fast. We rolled out critical functionalities to meet these targets and we would like to get more eyes on them. Please pay more attention on the following areas:\u003c/p\u003e\n\n\u003ch3\u003eMulti-User Access\u003c/h3\u003e\n\n\u003cp\u003eWise offers a feature for business accounts that enables multiple people to access one account. We call it Multi-User Access (MUA).\u003c/p\u003e\n\n\u003cp\u003ePlease focus on the possible misuses of this feature set, such as:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eManaging users (inviting/removing users and changing roles)\u003c/li\u003e\n\u003cli\u003eBypassing role-based permissions, or\u003c/li\u003e\n\u003cli\u003eInteracting with unauthorized accounts (profiles)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTo test this feature, you need to create a Wise for Business account under your testing account. The business account name should clearly identify that this is created for testing purposes, e.g. Test Business Account or My Business Testing Account.\u003c/p\u003e\n\n\u003cp\u003eIf you need your testing business account to be verified for deeper testing, get into the full business account onboarding process by having yourself verified using real documents (i.e. uploading real IDs). Once successfully verified, you will still be bound by its legitimate use set out in our acceptable use policy (\u003ca href=\"https://wise.com/terms-and-conditions\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://wise.com/terms-and-conditions\u003c/a\u003e).\u003c/p\u003e\n\n\u003cp\u003eIf you run into any issues that have no security impact, please redirect your reports to our help page (\u003ca href=\"https://wise.com/help/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://wise.com/help/\u003c/a\u003e).\u003c/p\u003e\n\n\u003ch3\u003eWise API\u003c/h3\u003e\n\n\u003cp\u003eOur API is a less-seen, but critical part of our infrastructure offering. You can find the API docs at \u003ca href=\"https://api-docs.wise.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://api-docs.wise.com\u003c/a\u003e and our sandbox testing environment at \u003ca href=\"https://sandbox.transferwise.tech\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://sandbox.transferwise.tech\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eWe’re encouraging researchers to read our API documentation and to find API misuses that could significantly affect our business or our customers.\u003c/p\u003e\n\n\u003ch3\u003eMulti-factor Authentication\u003c/h3\u003e\n\n\u003cp\u003eWise offers two types of multi-factor authentication (MFA): SMS and app-based authentication. We would like you to identify possible security issues with our MFA workflow, such as device registration and deactivation and bypass vectors.\u003c/p\u003e\n\n\u003cp\u003eSMS and SIM vulnerabilities, like those publicised around SS7, are out of scope because we wish to test our implementation and not the underlying infrastructure.\u003c/p\u003e\n\n\u003cp\u003eIn order to test app-based authentication, you should set up SMS authentication first and then upgrade to app-based authentication via the settings menu on the iOS or Android apps.\u003c/p\u003e\n\n\u003ch3\u003eSCA support for EEA customers\u003c/h3\u003e\n\n\u003cp\u003eOn 14 Sept 2019, the Strong Customer Authentication (SCA) requirement of the EU Revised Directive on Payment Services (PSD2) went into effect. This requirement ensures that payment service providers within the European Economic Area implement MFA on electronic payments. In compliance, we recently rolled-out application-wide (web, mobile) changes affecting all customers with borderless accounts with country of residence within the EEA. The following functionalities will now require a password or biometrics (mobile app) to proceed:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDownloading of statements\u003c/li\u003e\n\u003cli\u003eSending money\u003c/li\u003e\n\u003cli\u003eProfile obfuscation when the user is inactive for X minutes (currently, 5 mins)\u003c/li\u003e\n\u003cli\u003eRevealing PIN or card details\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eUsers who created their account via Facebook / Google within EEA are now required to set a password; this password will be used for confirmation when any of the above actions are triggered.\u003c/p\u003e\n\n\u003cp\u003eWe are interested in application misuses that circumvent PSD2/SCA protections we have in place.\u003c/p\u003e\n\n\u003ch3\u003eWise Card\u003c/h3\u003e\n\n\u003cp\u003eWise has its own debit card - the Wise Card. We would love to have some attention on card management, account services (statement of accounts), and the card freeze features.\u003c/p\u003e\n\n\u003cp\u003eTo test these features, you should set up your own Wise account and have a card issued to you. This involves having a verified Wise account and signing up to our multi-currency account offering. The Wise card is only available in selected countries at the moment - see the full list of countries supported \u003ca href=\"https://wise.com/help/articles/2968915/can-i-get-the-wise-card-in-my-country\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch3\u003eClarifications About Scope\u003c/h3\u003e\n\n\u003cp\u003eReports classified as P5 do not qualify for a monetary reward. Focus on impactful findings: how does this affect confidentiality, integrity or availability of Wise or customers?\u003c/p\u003e\n\n\u003cp\u003eMinor misconfigurations or missing best-practices with low impact typically do not qualify for a reward.\u003c/p\u003e\n\n\u003ch4\u003eOut of Scope\u003c/h4\u003e\n\n\u003cp\u003eThe following types of submissions \u003cstrong\u003ewill not\u003c/strong\u003e be accepted and will be marked as \"Out of Scope\":\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMissing SPF / DMARC records on domains that are not used for sending mail (verify that the domain sends e-mail first)\u003c/li\u003e\n\u003cli\u003eEmail spoofing where SPF / DKIM / DMARC is configured, but recipient ignores validation failures\u003c/li\u003e\n\u003cli\u003eDenial of Service attacks due to excessive amount of requests\u003c/li\u003e\n\u003cli\u003eAttacks against customer support; through contact forms or methods (e.g. \u003ccode\u003ehttps://wise.com/help/contact\u003c/code\u003e or phone lines)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting unsupported browsers or platforms (unsupported meaning the vendor has declared end-of-life)\u003c/li\u003e\n\u003cli\u003eAPI keys that are \u003cem\u003edesigned\u003c/em\u003e to be public. Some 3rd party vendors we adopt use public API keys to identify the customer (for example: as customer ID, for submitting crash reports).\nWhen finding a vendor API key, please check from the vendor's documentation how the key should be used and secured; and whether our implementation violates those guidelines.\nIf the key is used only to identify the request sender; but does not grant any unauthorized access, the finding is out of scope.\u003c/li\u003e\n\u003cli\u003eSubmissions relating to the following HTTP Security Headers:\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ccode\u003eX-Frame-Options\u003c/code\u003e - this header is deprecated and replaced by CSP; we won't be implementing it\u003c/li\u003e\n\u003cli\u003e\n\u003ccode\u003eX-XSS-Protection\u003c/code\u003e header\u003c/li\u003e\n\u003cli\u003eAny other missing HTTP security header, unless accompanied by a impactful PoC\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSample secrets (private keys, passwords) in GitHub repositories, if the included documentation clearly states this to be a sample/unused password;\nor it's clear from the code these secrets are only used during automated testing (CI)\u003c/li\u003e\n\u003cli\u003eSelf-XSS, or XSS attacks that require local access\u003c/li\u003e\n\u003cli\u003ePhysical attacks against Wise premises or employees\u003c/li\u003e\n\u003cli\u003eAttacks that require a rooted / jailbroken phone to work; or attacks that require an already compromised system (debugger installed, memory dump possible).\nIf a client device is already compromised to that level, meaningful protection of our processes is not feasible.\u003c/li\u003e\n\u003cli\u003eAvailable typosquatting / punycode / unicode identifiers (such as domain names, e-mail addresses); or identifiers with the name \"\u003cem\u003eWise\u003c/em\u003e\" in them.\nFor example: unregistrered domain name \u003ccode\u003ethis-is-wise-testing-site.com\u003c/code\u003e; or unclaimed S3 bucket name \u003ccode\u003etr4nsferwis3-staging\u003c/code\u003e.\nReports typically state phishing risk, but we can't claim every conceivable variation of the name. Reports can still be accepted, if the identifier is in\nactual use by our production systems (hijacking - with a PoC)\u003c/li\u003e\n\u003cli\u003eAttacks that depend on a man-in-the-middle actor in the network path, IF a 3rd party CA is installed to the system\u003c/li\u003e\n\u003cli\u003eDefault output of security scanners, without any specific accompanying proof-of-concept attack\u003c/li\u003e\n\u003cli\u003eFindings related to publicly exposed prometheus endpoints\u003c/li\u003e\n\u003cli\u003eKYC related reports\u003c/li\u003e\n\u003cli\u003ePublic reports or databases of leaked credentials (which we proactively monitor), unless the credentials belong to a Wise employee and the researcher demonstrates a successful login to a Wise internal system\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eFindings that require a clear proof-of-concept with impact\u003c/h4\u003e\n\n\u003cp\u003eThe following categories of findings are usually rejected or qualified as a P5 \u003cem\u003eunless\u003c/em\u003e the submission includes a \u003cem\u003eworking\u003c/em\u003e and \u003cem\u003eimpactful\u003c/em\u003e proof-of-concept, affecting availability, confidentiality or integrity.\u003c/p\u003e\n\n\u003cp\u003ePlease include a specific proof of concept that clearly demonstrates significant impact.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eFor example, it is not enough to say that due to a missing \u003ccode\u003eX-Frame-Options\u003c/code\u003e header, clickjacking might be possible - you would need to submit a proof-of-concept abuse that is specifically crafted to target Wise; more than an \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e on the page; requires minimal interaction; and clearly demonstrates significant effect for the victim.\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInternal DNS / IP / path (file or class) disclosures\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (stack traces, application errors)\u003c/li\u003e\n\u003cli\u003eClickjacking due to lax framing source policies (CSP \u003ccode\u003eframe-ancestors\u003c/code\u003e).\nReports without a PoC that directly impacts customers (disables 2FA, sets up a transfer...) will be rejected as out of scope\u003c/li\u003e\n\u003cli\u003eMissing best practices in TLS configuration (ie TLS1.2 support; BEAST attack; weak cipher suites enabled)\u003c/li\u003e\n\u003cli\u003eNot stripped EXIF metadata on files, such as images and PDF-s - unless having a serious and clear impact.\nFor example: author name on a stock image - no impact; GPS coordinates on a profile photo uploaded by \u003cem\u003eanother\u003c/em\u003e customer - valid impact\u003c/li\u003e\n\u003cli\u003eBroken links to any destination that can be hijacked (example: link to an expired domain from our blog).\nUnless the link is similar enough to \u003ccode\u003eWise.com\u003c/code\u003e and can be considered phishing risk; this would be a P5.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eAttacks against our Android/iOS apps that require a malicious (other) application on the device, if there is no feasible defense we could implement\u003c/li\u003e\n\u003cli\u003eMissing \u003ccode\u003eSecure\u003c/code\u003e; \u003ccode\u003eHttpOnly\u003c/code\u003e; or \u003ccode\u003eSameSite\u003c/code\u003e flags for cookies not used for secret storage\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner / version disclosure\u003c/li\u003e\n\u003cli\u003eCSRF attacks against publicly available forms\u003c/li\u003e\n\u003cli\u003eIssues relating to browser \"autocomplete\" and \"save password\" functionality\u003c/li\u003e\n\u003cli\u003eData leakage issues from local devices due to \u003ccode\u003eCache-Control: private\u003c/code\u003e header \u003c/li\u003e\n\u003cli\u003eInformation disclosure for non-sensitive information\u003c/li\u003e\n\u003cli\u003eMissing best-pracices without a realistic attack scenario\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eCommon findings that are not bugs\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you have enabled 2FA and you are not asked for it during 2nd login, please check if you have “Remember Me” checkbox enabled on login screen. This sets a cookie about using trusted device.\u003c/li\u003e\n\u003cli\u003eRate limiting and DDoS concerns - while no service guarantees 100% protection and we are open to any valid finding, please keep in mind, that we use Cloudflare rate limiting and DDoS protection service. So your initial test might show no rate limiting, but it kicks in from certain threshold, based on our risk assessment.\u003c/li\u003e\n\u003cli\u003eCredentials in Github repos - while we discourage using passwords and especially leaving them in configuration files, we do keep some sample passwords in our public repos. If the password is called “password”, “changeit”, “secret” or similar easy phrase, please read the full code and try to understand if this is really a mistake or maybe left there as an example or placeholder. Findings about sample passwords in GitHub repositories are not valid.\u003c/li\u003e\n\u003cli\u003eNot asking for password / 2FA on account deactivation\u003c/li\u003e\n\u003cli\u003eWebhook functionality making requests to \u003cem\u003eexternal\u003c/em\u003e IPs / domains\u003c/li\u003e\n\u003cli\u003eAbility to log in after account creation, without verifying the e-mail first\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eNotes\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAvoid submitting the same underlying issue multiple times. For example, if the same issue exists in our testing and production site, send both with one submission \u003c/li\u003e\n\u003cli\u003eSome of the pay-in methods incur a transaction charge. Should the researcher chose to use them, Wise won't be able to refund these charges. Pay-in using bank transfers will result in no extra charges for the researchers.\u003c/li\u003e\n\u003cli\u003eTest transactions should be less than £20 or equivalent in value. Unless you plan to test by actually transferring funds between your test accounts, the transactions should be cancelled through the UI (and money marked as \"not sent\") once the flow has been completed.\u003c/li\u003e\n\u003cli\u003eWe have layered protection and not all our security checks happen synchronously and seen in the front end. There are background verification and fraud checks regarding monetary transactions, so we encourage you to do a PoC and verify if you can actually bypass our procedures.\u003c/li\u003e\n\u003cli\u003eMany Android researchers like to use Drozer to initially evaluate the attack surface of the app. Please submit a PoC including details and not just the output after running the tool. We also need the environment configuration that was used (e.g. Virtual and the Android version).\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"6c910c1e-d6f3-4c42-9a30-892eada4881a","name":"In scope targets","targets":[{"id":"07c307e9-2459-44a0-bceb-e4c69f113d45","uri":"https://transferwise.com","name":"transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"25fb30a0-4778-4bab-9cf7-62d4486726a1","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"07c307e9-2459-44a0-bceb-e4c69f113d45"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"07c307e9-2459-44a0-bceb-e4c69f113d45"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"07c307e9-2459-44a0-bceb-e4c69f113d45"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"07c307e9-2459-44a0-bceb-e4c69f113d45"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"07c307e9-2459-44a0-bceb-e4c69f113d45"}],"recentChangeFlags":null},{"id":"0d180bbc-dfd4-4f16-a48f-a48170c2e603","uri":null,"name":"*.transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7db8e1e0-ec67-4a4d-af58-3b06d1767042","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"0d180bbc-dfd4-4f16-a48f-a48170c2e603"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"0d180bbc-dfd4-4f16-a48f-a48170c2e603"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"0d180bbc-dfd4-4f16-a48f-a48170c2e603"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"0d180bbc-dfd4-4f16-a48f-a48170c2e603"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0d180bbc-dfd4-4f16-a48f-a48170c2e603"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"0d180bbc-dfd4-4f16-a48f-a48170c2e603"}],"recentChangeFlags":null},{"id":"7225fd09-0412-4a4f-a721-ac9acc3ee2d3","uri":"https://wise.com","name":"wise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8f8bb2bf-1f44-4181-8d10-6b5ef16decc2","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"7225fd09-0412-4a4f-a721-ac9acc3ee2d3"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"7225fd09-0412-4a4f-a721-ac9acc3ee2d3"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"7225fd09-0412-4a4f-a721-ac9acc3ee2d3"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"7225fd09-0412-4a4f-a721-ac9acc3ee2d3"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"7225fd09-0412-4a4f-a721-ac9acc3ee2d3"}],"recentChangeFlags":null},{"id":"6ba69314-4dc4-48d5-a46c-1de1cbfe1292","uri":"","name":"*.wise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"52411f77-7865-43ed-b6b1-80dc3d18bef0","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"6ba69314-4dc4-48d5-a46c-1de1cbfe1292"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"6ba69314-4dc4-48d5-a46c-1de1cbfe1292"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"6ba69314-4dc4-48d5-a46c-1de1cbfe1292"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"6ba69314-4dc4-48d5-a46c-1de1cbfe1292"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6ba69314-4dc4-48d5-a46c-1de1cbfe1292"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"6ba69314-4dc4-48d5-a46c-1de1cbfe1292"}],"recentChangeFlags":null},{"id":"31a4fd62-d326-47f8-bc99-7c117b215139","uri":"https://apps.apple.com/us/app/wise-ex-transferwise/id612261027","name":"Latest version of Wise iOS App","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1b4a8d0e-ecf9-46c1-8ad2-b0163f768f2d","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"31a4fd62-d326-47f8-bc99-7c117b215139"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"31a4fd62-d326-47f8-bc99-7c117b215139"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"31a4fd62-d326-47f8-bc99-7c117b215139"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"31a4fd62-d326-47f8-bc99-7c117b215139"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"31a4fd62-d326-47f8-bc99-7c117b215139"}],"recentChangeFlags":null},{"id":"6570836e-e034-48fd-bcef-c5b9c68b1b25","uri":"https://play.google.com/store/apps/details?id=com.transferwise.android\u0026hl=en_US\u0026gl=US","name":"Latest version of Wise Android App","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e3e4a968-feba-4dc4-9d68-5e587c63035e","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"6570836e-e034-48fd-bcef-c5b9c68b1b25"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"6570836e-e034-48fd-bcef-c5b9c68b1b25"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"6570836e-e034-48fd-bcef-c5b9c68b1b25"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"6570836e-e034-48fd-bcef-c5b9c68b1b25"}],"recentChangeFlags":null},{"id":"da62e0f8-e41e-4400-b056-18583f3c87ab","uri":null,"name":"AWS infrastructure and services in use by Wise (eg: S3 buckets)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2233024f-a4db-472f-9a07-75aba4858f1a","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"da62e0f8-e41e-4400-b056-18583f3c87ab"}],"recentChangeFlags":null},{"id":"a6434cf0-1e49-4c23-8120-6f13b277be9b","uri":"https://github.com/transferwise/*","name":"github.com/transferwise/*","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a152d415-d9b6-445d-8eb0-8bdc46392c48","sortOrder":0},"sortOrder":0,"tags":[{"id":"20f6988d-5b8c-41bb-9ca8-d9b271b7874d","name":"Github","targetId":"a6434cf0-1e49-4c23-8120-6f13b277be9b"},{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"a6434cf0-1e49-4c23-8120-6f13b277be9b"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"8072d6d7-6ca5-43a1-9762-063183848433","p1MaxCents":400000,"p1MinCents":300000,"p2MaxCents":150000,"p2MinCents":100000,"p3MaxCents":50000,"p3MinCents":30000,"p4MaxCents":15000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":600000},"descriptionHtml":null,"rewardRangeData":{"1":{"min":3000,"max":4000},"2":{"min":1000,"max":1500},"3":{"min":300,"max":500},"4":{"min":100,"max":150},"5":{"min":null,"max":null},"programMax":6000},"recentChangeFlags":null},{"id":"402d0a81-49e8-4684-a1ac-f2264cfbf771","name":"Out of scope targets","targets":[{"id":"38068401-b70b-4ee5-a6a7-0b935bf39347","uri":null,"name":"Wise Affiliate Program","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8a12b1af-1247-4e6f-9e71-195a074a6eac","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"38068401-b70b-4ee5-a6a7-0b935bf39347"}],"recentChangeFlags":null},{"id":"02cc6304-948d-4cd8-91a9-f75ea55cf7ca","uri":null,"name":"Third party services not hosted by Wise","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ed860afc-a80d-4a3a-bc9b-1702cc5a2c1d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"02cc6304-948d-4cd8-91a9-f75ea55cf7ca"}],"recentChangeFlags":null},{"id":"d2584723-4dd8-471a-bb5a-a70597cb9264","uri":null,"name":"Any Github asset not under the “transferwise” organization","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"15d2cdf7-d80e-486f-9503-aff5622be0c4","sortOrder":0},"sortOrder":0,"tags":[{"id":"20f6988d-5b8c-41bb-9ca8-d9b271b7874d","name":"Github","targetId":"d2584723-4dd8-471a-bb5a-a70597cb9264"},{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"d2584723-4dd8-471a-bb5a-a70597cb9264"}],"recentChangeFlags":null},{"id":"a1f50bdb-9cae-412b-80a9-d44a960fd7b6","uri":null,"name":"Third party authentication services (eg: Facebook and Google)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f70c1118-3aef-4567-8e1e-76ccc389c14b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a1f50bdb-9cae-412b-80a9-d44a960fd7b6"}],"recentChangeFlags":null},{"id":"926272b9-9f14-4d0a-aa05-69c5655bd7c8","uri":null,"name":"https://transferwise.com/help/contact","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"cf3d986d-fbf8-403d-a6af-1dc3813580c7","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"926272b9-9f14-4d0a-aa05-69c5655bd7c8"}],"recentChangeFlags":null},{"id":"ef3748a9-3aa8-4f09-9e4c-581ee8d06e64","uri":"","name":"https://wise.com/help/contact","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5043917a-993d-4174-8d24-d93cf4adc3fa","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ef3748a9-3aa8-4f09-9e4c-581ee8d06e64"}],"recentChangeFlags":null},{"id":"9bc201c5-5b83-40eb-b820-1efa0f1ff6bf","uri":null,"name":"*.tw.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b625f815-24eb-488a-b45c-0bbfa27b6d17","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9bc201c5-5b83-40eb-b820-1efa0f1ff6bf"}],"recentChangeFlags":null},{"id":"fcfb68f8-288f-4bea-aa60-898104fecf73","uri":null,"name":"*.tw.ee","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"43be64ae-d7f5-4555-b05e-c750b6474eb0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fcfb68f8-288f-4bea-aa60-898104fecf73"}],"recentChangeFlags":null},{"id":"19a6622e-aaf8-4743-a698-ba8c8c7abb12","uri":null,"name":"Non-current version of the Android app","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"13fcba47-8c3c-49de-82d4-5c54280a0495","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"19a6622e-aaf8-4743-a698-ba8c8c7abb12"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"19a6622e-aaf8-4743-a698-ba8c8c7abb12"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"19a6622e-aaf8-4743-a698-ba8c8c7abb12"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"19a6622e-aaf8-4743-a698-ba8c8c7abb12"}],"recentChangeFlags":null},{"id":"65827457-3dc2-41f4-9a2d-a89da78b476c","uri":null,"name":"Non-current version of the iOS app","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"73d8c9db-a125-4163-bae8-c2f193d22b02","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"65827457-3dc2-41f4-9a2d-a89da78b476c"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"65827457-3dc2-41f4-9a2d-a89da78b476c"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"65827457-3dc2-41f4-9a2d-a89da78b476c"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"65827457-3dc2-41f4-9a2d-a89da78b476c"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"65827457-3dc2-41f4-9a2d-a89da78b476c"}],"recentChangeFlags":null},{"id":"422a0682-eb5b-4a26-bcdd-46d7bc7be265","uri":null,"name":"*.transferwise.tech","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"71df21f4-d267-44d2-961d-680a66f1da24","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"422a0682-eb5b-4a26-bcdd-46d7bc7be265"}],"recentChangeFlags":null},{"id":"9609d7dd-ce20-42d3-aa25-c7b7e37f9adc","uri":"","name":"brand.wise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"889b1b84-3711-4c01-806e-f96616521d8c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9609d7dd-ce20-42d3-aa25-c7b7e37f9adc"}],"recentChangeFlags":null},{"id":"004b8b3d-c58a-47ca-942f-a170b38dc449","uri":"","name":"links.wise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e2473a9d-1d15-4a28-8358-8e5760bb8dd0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"004b8b3d-c58a-47ca-942f-a170b38dc449"}],"recentChangeFlags":null},{"id":"7dda7bb5-06fb-40e1-885e-8037791570b1","uri":"","name":"widgets.transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"69b67205-ef30-4ad0-8add-bfecd98e8e0f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7dda7bb5-06fb-40e1-885e-8037791570b1"}],"recentChangeFlags":null},{"id":"2a77f8fc-34b6-4f02-9a9c-70039e3bc67c","uri":"","name":"brand.transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ce28c544-a639-4d20-9c3a-0c0729a98385","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2a77f8fc-34b6-4f02-9a9c-70039e3bc67c"}],"recentChangeFlags":null},{"id":"dd1d591d-2b00-4f85-a829-bf8259d7735f","uri":"","name":"bootstrap.transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f975625c-4ec5-4e67-ad47-e024ce02383d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"dd1d591d-2b00-4f85-a829-bf8259d7735f"}],"recentChangeFlags":null},{"id":"50be33b1-7a4c-4868-b4b4-73f183853ca0","uri":"","name":"links.transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"10097e50-2a2e-4deb-93ab-645223f63ae1","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"50be33b1-7a4c-4868-b4b4-73f183853ca0"}],"recentChangeFlags":null},{"id":"bf4e1b56-1ef6-4665-92e6-296fbeda9a49","uri":"","name":"status.wise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f1239f44-7e6b-40b1-b873-d23e248d2eeb","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bf4e1b56-1ef6-4665-92e6-296fbeda9a49"}],"recentChangeFlags":null},{"id":"2aa7f37b-e9b2-4c42-8b6b-14d0a4bb3d81","uri":"","name":"status.transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6614b184-4cf4-433a-a171-cbe111f867e6","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2aa7f37b-e9b2-4c42-8b6b-14d0a4bb3d81"}],"recentChangeFlags":null},{"id":"0edce5dc-45f9-4e57-a11e-28f4efdf5bba","uri":"","name":"tech.transferwise.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4647d96a-960d-492e-a4c7-a7ba36fab6d5","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0edce5dc-45f9-4e57-a11e-28f4efdf5bba"}],"recentChangeFlags":null},{"id":"872e6155-2015-463e-9658-f9ea6c1bb724","uri":null,"name":"docs.wise.com ","category":"other","ipAddress":"https://docs.wise.com ","description":null,"engagementBriefTargetGroupTarget":{"id":"9fcac53c-6909-4ea1-b3fc-f85fbd095460","sortOrder":20},"sortOrder":20,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"872e6155-2015-463e-9658-f9ea6c1bb724"}],"recentChangeFlags":null},{"id":"526678d9-43d9-4805-a743-4b55bb00a990","uri":"https://github.com/transferwise/pipelinewise","name":"github.com/transferwise/pipelinewise","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"182fe6d0-bc6a-4217-a26e-2bd501d77ac4","sortOrder":21},"sortOrder":21,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"526678d9-43d9-4805-a743-4b55bb00a990"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"701bd006-3c36-4e5f-b168-1b4c7f8852f9","name":"Sandbox environment","targets":[{"id":"704eb438-c09c-415d-8a3c-f3f2c15c0d91","uri":"https://wise-sandbox.com/","name":"*.wise-sandbox.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2f93621c-e807-47e4-9533-6048a8173aed","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"704eb438-c09c-415d-8a3c-f3f2c15c0d91"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"704eb438-c09c-415d-8a3c-f3f2c15c0d91"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"704eb438-c09c-415d-8a3c-f3f2c15c0d91"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"704eb438-c09c-415d-8a3c-f3f2c15c0d91"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"704eb438-c09c-415d-8a3c-f3f2c15c0d91"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThis environment is a development sandbox for Wise partners. It closely mirrors production but does not require KYC, making testing potentially easier. Please note that testing here is subject to the same restrictions as the live production environment (particularly concerning automated testing). Any findings exclusive to this environment will likely be rated P5 (Informational).\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"cc14cffb-efc9-45a0-bcbc-9575d7fc12a0","code":"wise","state":"in_progress","endsAt":null,"bountyId":"e926073f-7736-428f-a9aa-023f88abdf18","startsAt":"2017-06-06T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/0c2c/9c3c/5b3e5c76/c5d476023996c36e0d6dfa6468fd98c5_Wise_FastFlag_ForestGreen-svg.png","logoBackgroundColor":"#9FE870","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2017-06-06T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/wise","changelogs":"/engagements/wise/changelog","submissions":null,"announcements":"/engagements/wise/announcements","hallOfFame":"/engagements/wise/hall_of_fames","crowdstream":"/engagements/wise/crowdstream"},"announcementsCount":14,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/wise/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=wise\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/wise/engagement_subscribers","engagementChangelogsUrl":"/engagements/wise/changelog","publishedAt":"2026-05-19T09:35:32.812Z","engagementChangelogUrl":"/engagements/wise/changelog/b406940a-3bf6-4b05-ac3b-a8110ab53e81","createUserFeedbacksUrl":"/engagements/wise/feedbacks","engagementCrowdstreamUrl":"/engagements/wise/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}