Avala
Security

Bug Bounty & Vulnerability Disclosure

Help us secure the data platform for Physical AI.

Thousands of hours of AV, robotics, and Physical AI training data flow through our systems every week. We pay researchers who find bugs in it. Cash bounties up to $1,500 for findings that merit it, with discretionary bonuses for exceptional chains, plus recognition in our hall of fame.

48-hour acknowledgmentSafe harbor guaranteed90-day coordinated disclosure

Rewards at a glance

What we pay for high-impact findings

SeverityCVSS v3.1Cash
Informational / Low< 4.0$25
Medium4.0 – 6.9$100 – $150
High7.0 – 8.9$250 – $500
Critical9.0 – 10.0$500 – $1,500
Exceptional chain / broad impactDiscretionary bonus

Response SLA

What to expect after you submit.

Initial acknowledgment
Within 48 hours
Severity assessment & triage
Within 5 business days
Status update cadence
Every 7 days until resolved
Fix deployment (critical)
Within 72 hours
Fix deployment (high)
Within 14 days
Fix deployment (medium/low)
Within 30 days
Bounty decision
On fix-deployed or determination of non-applicability
Bounty payment
Within 30 days of decision

Found something?

Sign in with a magic link, submit your report, and we'll take it from there.