Ada Health / Ada Health Intigriti


Target Policy
https://app.intigriti.com/api/core/researcher/programs/adahealth/adahealth
Structured Scope
  • Asset Identifier
    Asset Type
    Max Severity
  • https://demo.sso.enterprise.ada.com

    Smart-auth is Ada’s identification management and Single Sign On (SSO).
    This service is based on [SMART on FHIR](https://hl7.org/fhir/smart-app-launch/index.html) implementation and provides a standard way to integrate with other EHR (Electronic Health Record) servers. It is an optional module meaning that not all flows are authentication required.

    URL
    low
  • https://care-navigation-admin-bff.int.eu.enterprise.ada.com

    Backend for frontend (bff) service for Care Navigation Admin interface. BFF is a variant of the API Gateway pattern which provides an additional layer between microservices.

    URL
    low
  • https://demo.handover.enterprise.ada.com

    Handover is a solution for sharing (handing over) the results of the health assessment with the user’s health care provider (HCP) or a health professional. This service has the responsibility to render the HCP report data received from the HCP report bff.

    URL
    low
  • https://demo.enterprise.ada.com

    Our web application helps millions to manage their health. This is the frontend assessment application demo domain which represents the general flow we provide with our enterprise partners. This medical AI symptom checker is trained by real doctors. This endpoint provides both guess and authenticated flow which can be combined with our SSO service.

    This UI is calling the BFF domain which is also in the scope.

    URL
    low
  • https://care-navigation-bff.int.eu.enterprise.ada.com

    Backend for frontend (bff) service for Care Navigation Frontend service. BFF is a variant of the API Gateway pattern which provides an additional layer between microservices.

    URL
    low
  • https://demo-prod-hcp-report-bff.ada-prod-eu.prod.gcp.ada.com

    Handover is a solution for sharing (handing over) the results of the health assessment with the user’s health care provider (HCP) or a health professional. This service has the responsibility to process the data from the hcp-report-backend for the use of handover frontend.

    URL
    low
  • https://care-navigation-admin-fe.int.eu.enterprise.ada.com

    Care Navigation Admin Frontend is a visual tool for managing Connect data including:
    - Connect Care Option mappings,
    - Connect/Assess Feedback service,
    - Connect Sign-up service,
    - Admin Users,
    - Connect Client Configurations

    Test credentials will not be provided. Try to find broken access controls on this endpoint.

    URL
    low
  • https://demo-prod-assessment-bff.ada-prod-eu.prod.gcp.ada.com

    Backend for frontend (bff) service for demo assessment web interface. BFF is a variant of the API Gateway pattern which provides an additional layer between microservices.

    Please see the all endpoints in the Open API documentation (demo_assessment_bff_openapi.json) file

    URL
    low
  • com.ada.app

    Android Mobile Application of Ada Health

    Android
    high
  • https://id.ada.com

    Ada-ID is an identity management service for end user that interacts with Ada's applications. It provides authentication and authorization. Ada-ID serves as web application and API services. Frontend is valid for password reset and account verification process. This endpoint is protected by a Web Application Firewall.

    URL
    medium
  • https://care-navigation-fe.int.eu.enterprise.ada.com

    Care Navigation Frontend service represents Ada Partner care navigation option list available after assessment test is accomplished. Service includes:

    - Configurable care category list
    - Customer location search
    - Customer feedback service (can be injected between the views)
    - Detailed Event tracking
    - Configurable and location-based Partner Care service list
    - Geolocation, Feedback & Signup are linked with care-navigation-bff via an API and Service/Categories are linked with care-navigation-admin-bff via an API.

    URL
    low
  • 1099986434

    IOS Mobile Applicaton of Ada Health

    iOS
    high
  • https://api.mobile.ada.com

    Backend for frontend API endpoint for mobile application activities. This endpoint is protected by a Web Application Firewall.

    URL
    medium
Target Scope Domains
  • api.mobile.ada.com
  • care-navigation-admin-bff.int.eu.enterprise.ada.com
  • care-navigation-admin-fe.int.eu.enterprise.ada.com
  • care-navigation-bff.int.eu.enterprise.ada.com
  • care-navigation-fe.int.eu.enterprise.ada.com
  • demo-prod-assessment-bff.ada-prod-eu.prod.gcp.ada.com
  • demo-prod-hcp-report-bff.ada-prod-eu.prod.gcp.ada.com
  • demo.enterprise.ada.com
  • demo.handover.enterprise.ada.com
  • demo.sso.enterprise.ada.com
  • id.ada.com
Tech Stack

Last Finished Scan:
Scan Name
Fleet
Finished
State
allhttpx
8 months, 2 weeks ago
Finished
  • Fleet: allhttpx
  • Duration: 20 Seconds
  • Finished: 8 months, 2 weeks ago