Platforms, Programs, and Assets
How Nimbus Vault organizes the targets you are hacking on.
The hierarchy
- Platform — where the program lives: a bug bounty platform, a VDP, a private engagement. One record per source of work.
- Program — a scope of testing published by an organization: the rules, the rewards, the boundary.
- Asset — one concrete thing you are testing:
admin.example.com, an API endpoint, an Android app, a source checkout.
You rarely test a "program" directly. Work happens on assets, so that is where observations, components, and suggestions live.
One asset, one focus
The model pushes you to keep assets concrete. "The whole product" is not an asset. api.example.com is. Concrete assets make the Nexus Engine's matching precise — and precision is what ranks a suggestion to the top.
Assets can have children: an app with its API, a host with its services. Hierarchy lets a capability on a child (a vector inside an API) sharpen what the engine knows about the parent without duplicating records.
Getting assets in
- Manual — create an asset and link components as you observe them. This is the map an asset loop.
- CSV import — bring in a target list you already maintain and start linking components to each row.
Asset types
Web, API, Mobile iOS, Mobile Android, Desktop, Browser Extension, Cloud Infrastructure, Network/VPN, Smart Contract, Hardware/IoT, Source Code Repository — pick the closest fit, and Other for anything the list does not cover. The type is descriptive: it tells collaborators what kind of target they are looking at.
One type is special: Wildcard. A wildcard asset is a grouping container, not a tracked target — its name must be a pattern like *.example.com, and concrete URLs live beneath it as Web assets. It organizes a broad scope without pretending the wildcard itself is something you test.
Sharing
Individual assets can be shared outside the workspace with a link — useful when you want a second pair of eyes on one target without inviting someone into everything.
What's next
Learn the vocabulary you will attach to every asset: components.