Skip to content
AvalaSecurity

Rewards

Rewards for security impact.

Review the affected surface and severity range for your finding. The top of a band is a ceiling, not a default award.

Affected surface

What qualifies, and what it pays.

These examples describe qualifying security impact. Check the full scope and research rules before testing.

Mission Control (avala.ai)

Physical AI data platform. Customer workspaces, sensor datasets, and labeling workflows.

  • Cross-tenant data access
  • Authentication or authorization bypass
  • Account takeover
  • Stored XSS with session or data impact

Maximum$750

API / MCP endpoint (api.avala.ai)

Django REST API + read-only MCP server that AI agents query.

  • Auth bypass or privilege escalation
  • MCP SELECT-only bypass (INSERT / UPDATE / DELETE via the MCP surface)
  • SQL injection, command injection, SSRF
  • Unauthenticated access to customer data or PII

Maximum$1,000

AI / LLM endpoints

LLM-powered features: annotation review, MCP query planning, agent integrations.

  • Prompt injection that exfiltrates customer data
  • Indirect prompt injection via uploaded annotations
  • Training-data or model exfiltration via the API
  • Agent-chain authz bypass (MCP role confusion)

Maximum$1,000

SDKs & packages

Published npm + PyPI packages that customers run inside their own code.

avala (PyPI), @avala-ai/sdk (npm), @avala-ai/mcp-server (npm)

  • Supply-chain injection (malicious dep, typosquat we missed)
  • Credential exfiltration from SDK internals
  • RCE in parser / serializer / client

Maximum$1,000

Mobile app (Arcade)

iOS + Android Flutter app used by annotators in the field.

  • Deep-link hijack with session impact
  • Insecure storage of auth tokens
  • Offline-cache bypass of server-side authz

Maximum$300

Customer-facing web surfaces

about.avala.ai, ir.avala.ai, docs.avala.ai, learning.avala.ai, pipelines.avala.ai.

  • Stored XSS on docs.avala.ai or ir.avala.ai
  • Admin-route exposure on any listed subdomain
  • Identity or auth-gate bypass on learning.avala.ai or pipelines.avala.ai

Maximum$300

Infrastructure (AWS, Cloudflare, DNS, TLS)

Publicly-exposed Avala-owned cloud surfaces.

  • Subdomain takeover on any *.avala.ai we own
  • Public S3 bucket with customer data (avala-* prefix)
  • Misconfigured Lambda / Worker endpoint returning internal state
  • Certificate or email-auth (SPF/DKIM/DMARC) spoofing primitives

Maximum$300

Authentication (Auth0 integration)

How we wire Auth0, not Auth0 itself (report Auth0 bugs to Auth0).

  • JWT validation bug in our middleware
  • API-key scoping flaw (server/apps/apikey/)
  • Session-fixation or re-use across tenants

Maximum$750

Severity reference

The CVSS bands.

Use this reference when a finding does not map cleanly to one surface. Your self-assessment is a starting point for triage.

Open the CVSS v3.1 calculator
Informational / LowCVSS v3.1: < 4.0

No cash reward

Hall of fame, CVE credit if applicable

MediumCVSS v3.1: 4.0 – 6.9

$50 – $100

Swag, hall of fame

HighCVSS v3.1: 7.0 – 8.9

$150 – $300

Swag, hall of fame

CriticalCVSS v3.1: 9.0 – 10.0

$300 – $750

Swag, hall of fame

Exceptional chain / broad impactCVSS v3.1:

Discretionary bonus

Case-by-case, Avala discretion

Reward tiers shown here apply to reports submitted on or after September 15, 2026. Earlier reports are assessed against the tiers published when they were submitted. Informational and low-severity findings receive recognition but no cash reward.

Assessment

Quality, novelty, and eligibility.

+25% quality bonus
Repro steps, impact analysis, and suggested fix in your first submission.
+25% novel class
First AI/LLM-specific finding of its kind on our platform, or a genuinely new vulnerability class.
First-to-report
The first valid report for a given issue gets the bounty. Duplicates receive CVE credit but no cash.

Not eligible for a reward

  • Reports using real customer data (even in PoC). Retest against your own test account.
  • Reports that caused service disruption.
  • Reports from individuals located in sanctioned countries (OFAC restrictions).
  • Reports from current Avala employees, contractors, or their immediate family members.

Payment

Know the payment terms.

Method and timing

Bounties are paid through PayPal, in USD unless otherwise agreed. Approved bounties are queued in the order reports were received and paid when the monthly pool opens; the program status notice below carries the current payment window.

Tax forms

  • US researchers need a W-9 before the first payout. A 1099-NEC is issued if you receive $600 or more in a calendar year.
  • International researchers need a W-8BEN before the first payout.
  • Your researcher profile has payment preferences and tax-form submission instructions.
  • Bounty income is reportable on your own tax return under your country's rules.

Monthly bounty pool: $5,000

Reports past the aggregate cap are still triaged and fixed on SLA. Approved bounties are queued and paid in order received when the next pool opens.

Avala is a seed-stage startup, and our bounty amounts reflect that. We've sized rewards to what we can sustainably pay while still recognizing serious work. As the company grows and our security budget grows with it, we plan to raise these tiers meaningfully — and to backfill bonus payments for researchers who helped us in the early days. If you choose to work with us now, thank you. We'll remember it.

Next steps

Ready to report?