Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Inter & Co. VDP
Inter & Co. VDP HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Inter & Co. VDP? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 24 Sep 2026.

What it pays, by severity

Critical amount not published 2 reports
High amount not published 12 reports
Medium amount not published 6 reports
Low amount not published 2 reports

Intake & responsiveness · last 90 days

Reports received
6
in 90 days
Resolved
22
all time, last one 8 months ago
Participants
33
hunters engaged
Response efficiency
50%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 16 days 5–7
25 Aug 6 reports 24 Sep

Response targets it sets itself

First response
1 day
Triage
10 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 33 days (18 snapshots): intake down 3 reports; response efficiency down 19 points.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

33 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 arielrachamim 112 2 / 2 100%
2 money- 42 5 / 21 24%
3 and0x00 21 0 / 0
3 drop 21 3 / 3 100%
5 eldruin 14 0 / 3 0%
5 m4rc10sz 14 0 / 0
5 rajdip_1998 14 0 / 2 0%
5 shahwarshah 14 0 / 1 0%
9 0daystolive 7 1 / 1 100%
9 0xvexus 7 1 / 5 20%
9 a7med_m7moued 7 1 / 1 100%
9 ariel1l 7 0 / 0
9 b1d0ws 7 0 / 0
9 br0x1337 7 1 / 1 100%
9 dansec0x 7 1 / 1 100%
9 eh_pavan 7 1 / 1 100%
9 flameeeesec 7 1 / 1 100%
9 gbrlzin 7 0 / 0
9 glitchmak3r 7 1 / 2 50%
9 gpxlnx 7 1 / 1 100%
9 miloud001 7 1 / 4 25%
9 mob_100 7 0 / 2 0%
9 mr-k0anti 7 1 / 1 100%
9 phongvan1337 7 0 / 1 0%
9 rz1027 7 0 / 0

Showing the top 25 of 33 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 17 Sep 2026.

Inter is a platform that makes life easier. Free digital account, shopping, investments, and everything else you need. Credit card and digital account

Responsiveness
57% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Feb 2024
Scope entries
28 HackerOne’s count

Scope

26 assets
AssetTypeEligibilityMax severity
*.bancointer.com.br WILDCARD submit only Critical
*.bmggranito.com.br WILDCARD submit only Critical
*.duogourmet.com.br WILDCARD submit only Critical
*.enviouchegou.com WILDCARD submit only Critical
*.filialbmggranito.com.br WILDCARD submit only Critical
Show all 26 assets
AssetTypeEligibilityMax severity
*.granito.xyz WILDCARD submit only Critical
*.granitopagamentos.com.br WILDCARD submit only Critical
*.granitopdv.com.br WILDCARD submit only Critical
*.granitosistemas.com.br WILDCARD submit only Critical
*.inter.co WILDCARD submit only Critical
*.interpag.co WILDCARD submit only Critical
*.pagocartoes.com.br WILDCARD submit only Critical
*.pagoportal.com.br WILDCARD submit only Critical
*.pontualconnect.com WILDCARD submit only Critical
*.pontualmoneytransfer.com WILDCARD submit only Critical
*.pontualmt.com WILDCARD submit only Critical
*.pontualmt.net WILDCARD submit only Critical
*.pontualreports.net WILDCARD submit only Critical
*.portalgranito.com.br WILDCARD submit only Critical
*.usend.com WILDCARD submit only Critical
*.usendbrazil.com WILDCARD submit only Critical
br.com.Inter.CDPro APPLE STORE APP ID submit only Critical
br.com.intermedium APPLE STORE APP ID submit only Critical
https://apps.apple.com/br/app/portal-granito/id1450658363 APPLE STORE APP ID submit only Critical
https://play.google.com/store/apps/details?id=br.com.granitopagamentos.granitopdv GOOGLE PLAY APP ID submit only Critical
https://play.google.com/store/apps/details?id=pagocartoes.com.br.pago GOOGLE PLAY APP ID submit only Critical

HackerOne lists 28 scope entries; its public listing groups many assets under one label, so identical entries are shown once.