Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Affirm
Affirm HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Affirm? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 2 Oct 2026.

What it pays, by severity

Critical amount not published 2 reports
High $2,356 avg 16 reports indicative
Medium $736 avg 52 reports firm
Low $300 avg 26 reports firm

$90,465 paid to researchers in total, $24,984 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
57
in 90 days
Resolved
109
all time, last one 11 days ago
Participants
137
hunters engaged
Response efficiency
75%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 16 days 56–71
4 Sep 57 reports 2 Oct

Response targets it sets itself

First response
2 days
Triage
10 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 42 days (23 snapshots): intake down 2 reports; 90-day payout up $7,055.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

141 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 ganeshbagaria 361 11 / 15 73%
2 no_01 260 3 / 3 100%
3 pesticide 146 3 / 4 75%
4 n1had 118 4 / 12 33%
5 nightmaresthereallol 114 2 / 3 67%
6 yogesh_ojha 94 2 / 4 50%
7 pungente 89 2 / 2 100%
8 mikey96 86 3 / 3 100%
9 godiego 68 4 / 7 57%
9 gujjuboy10x00 22 1 / 3 33%
10 1sequalt0 64 2 / 14 14%
11 obi 61 3 / 4 75%
12 bsysop 57 1 / 3 33%
12 deeevv 57 1 / 4 25%
12 kaiksi 57 0 / 0
12 mason0x01 57 1 / 1 100%
12 morwnbrgr 57 1 / 1 100%
12 petrescu 57 1 / 1 100%
18 insiderinvests 54 2 / 10 20%
19 astrounder 50 0 / 2 0%
19 bugfix22 50 0 / 0
19 uiltonlopes 50 0 / 0
20 unnamedx 32 1 / 1 100%
20 kushagra 22 1 / 1 100%
22 jakehhunter 46 3 / 4 75%

Showing the top 25 of 141 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 30 Sep 2026.

Responsiveness
75% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Aug 2020
Scope entries
16 HackerOne’s count

Scope

15 assets
AssetTypeEligibilityMax severity
com.affirm.central.audit GOOGLE PLAY APP ID ✓ bounty Critical
com.affirm.internal.hackerone APPLE STORE APP ID ✓ bounty Critical
hackerone.affirm-odin.com URL ✓ bounty Critical
helpcenter.affirm.ca URL ✓ bounty Critical
helpcenter.affirm.com URL ✓ bounty Critical
Show all 15 assets
AssetTypeEligibilityMax severity
sandbox.affirm.com URL ✓ bounty Critical
*.affirm.com WILDCARD out None
*.return.ly WILDCARD out None
*.returnly.com WILDCARD out None
dashboard.dev.return.ly URL out None
dashboard.returnly.com URL out None
direct-hackerone.affirm-odin.com URL submit only None
test-store-subdomain.dev.return.ly URL out None
test-store-subdomain.returnly.com URL out None
vcn-hackerone.affirm-odin.com URL submit only None

HackerOne lists 16 scope entries; its public listing groups many assets under one label, so identical entries are shown once.