The program
Research with purpose. Report with confidence.
Help protect the data and workflows that train robots and autonomous vehicles. We reward eligible findings with demonstrated security impact and work with researchers through triage, remediation, and disclosure.
Before testing
Know the program.
The scope, reward schedule, and research rules explain what qualifies and what to expect.
Scope
Check the exact asset before testing. Products, APIs, packages, and Avala-owned integrations have published eligibility boundaries.
Rewards
Review amounts by affected surface and severity, quality and novelty multipliers, payment terms, and the monthly bounty pool.
Rules and safe harbor
Follow the research rules and read the full safe-harbor policy. Stop at proof of concept and coordinate public disclosure with us.
Useful findings
Show the impact.
A useful report demonstrates how a vulnerability affects data, authentication, authorization, or system integrity on an eligible asset. This includes qualifying AI and LLM issues, such as prompt injection with data exfiltration or an MCP authorization bypass.
Validate findings independently. A scanner result, missing header, or theoretical issue without a working proof of concept is not enough. Use your own test account and stop once the impact is established.
Read the full scope and exclusionsSign in with your email
Use a magic link to access your researcher workspace. Each report has a private conversation with the security team.
Describe the finding
Identify the affected asset, give reproducible steps, and explain expected behavior, actual behavior, and security impact. Add a CVSS estimate if you have one.
Include evidence
Attach screenshots, video, or redacted code from your own test account. Do not include real customer data. Each attachment can be up to 500 MB.
Follow the response
After submission, use the report thread for questions, status updates, and coordinated disclosure. The response targets are published in the program rules.