Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3943ac6615745c8a34b683b799a3b83ad27731945
GraphQL introspection enabled at /graphql Types: 475 (by kind: ENUM: 52, INPUT_OBJECT: 190, INTERFACE: 3, OBJECT: 224, SCALAR: 6) Operations: - Query: Query | fields: checkSlug, clients, companies, company, crcPurposes - Mutation: Mutation | fields: addAccountMember, approveEnrollment, approveJobApplication, archiveClient, archiveDocuments Directives: deprecated, include, oneOf, skip (total: 4)
Open service 99.83.217.1:443 · admin.payoutpartner.com
2026-01-09 08:36
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://admin.payoutpartner.com/partner/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KA8rFj7YPD5wtqC%2BUdYgr7Req0zjkbmuUF9B2iDuCfU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767947794"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KA8rFj7YPD5wtqC%2BUdYgr7Req0zjkbmuUF9B2iDuCfU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767947794"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: f763073e-390a-4dfd-a5d6-777b94921a19
X-Runtime: 0.004891
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 08:36:34 GMT
Content-Length: 117
Connection: close
<html><body>You are being <a href="https://admin.payoutpartner.com/partner/session/new">redirected</a>.</body></html>
Open service 99.83.217.1:443 · admin.payoutpartner.com
2026-01-02 08:51
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://admin.payoutpartner.com/partner/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=qfZ9lPU2IBtLRYtogvXNqaBKMV%2FNKuBNg32wt17wK9g%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767343895"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=qfZ9lPU2IBtLRYtogvXNqaBKMV%2FNKuBNg32wt17wK9g%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767343895"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: fbd62d64-ebb0-4b22-bcba-2d95cab385be
X-Runtime: 0.004644
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 08:51:35 GMT
Content-Length: 117
Connection: close
<html><body>You are being <a href="https://admin.payoutpartner.com/partner/session/new">redirected</a>.</body></html>
Open service 99.83.217.1:443 · admin.payoutpartner.com
2025-12-22 21:18
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://admin.payoutpartner.com/partner/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=XLj1ubIgZ%2B1Nz75uGWyd4JATmx2pl%2FF3gLCnnXHkVh4%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766438329"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=XLj1ubIgZ%2B1Nz75uGWyd4JATmx2pl%2FF3gLCnnXHkVh4%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766438329"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0869b4dc-8522-4bee-bb04-aba462e42f01
X-Runtime: 0.005327
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 21:18:49 GMT
Content-Length: 117
Connection: close
<html><body>You are being <a href="https://admin.payoutpartner.com/partner/session/new">redirected</a>.</body></html>
Open service 99.83.217.1:443 · admin.payoutpartner.com
2025-12-21 00:11
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://admin.payoutpartner.com/partner/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=hZlKJWZBlUdu8YnnOuQv%2BlfEBVcQoprdEqicQvDPy2w%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766275886"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=hZlKJWZBlUdu8YnnOuQv%2BlfEBVcQoprdEqicQvDPy2w%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766275886"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: b8c33b1c-0c28-415b-afb6-cb84b6a43ce8
X-Runtime: 0.004829
X-Xss-Protection: 0
Date: Sun, 21 Dec 2025 00:11:26 GMT
Content-Length: 117
Connection: close
<html><body>You are being <a href="https://admin.payoutpartner.com/partner/session/new">redirected</a>.</body></html>