Rewards
Rewards for security impact.
Review the affected surface and severity range for your finding. The top of a band is a ceiling, not a default award.
Affected surface
What qualifies, and what it pays.
These examples describe qualifying security impact. Check the full scope and research rules before testing.
Mission Control (avala.ai)
Physical AI data platform. Customer workspaces, sensor datasets, and labeling workflows.
- Cross-tenant data access
- Authentication or authorization bypass
- Account takeover
- Stored XSS with session or data impact
Maximum$750
API / MCP endpoint (api.avala.ai)
Django REST API + read-only MCP server that AI agents query.
- Auth bypass or privilege escalation
- MCP SELECT-only bypass (INSERT / UPDATE / DELETE via the MCP surface)
- SQL injection, command injection, SSRF
- Unauthenticated access to customer data or PII
Maximum$1,000
AI / LLM endpoints
LLM-powered features: annotation review, MCP query planning, agent integrations.
- Prompt injection that exfiltrates customer data
- Indirect prompt injection via uploaded annotations
- Training-data or model exfiltration via the API
- Agent-chain authz bypass (MCP role confusion)
Maximum$1,000
SDKs & packages
Published npm + PyPI packages that customers run inside their own code.
avala (PyPI), @avala-ai/sdk (npm), @avala-ai/mcp-server (npm)
- Supply-chain injection (malicious dep, typosquat we missed)
- Credential exfiltration from SDK internals
- RCE in parser / serializer / client
Maximum$1,000
Mobile app (Arcade)
iOS + Android Flutter app used by annotators in the field.
- Deep-link hijack with session impact
- Insecure storage of auth tokens
- Offline-cache bypass of server-side authz
Maximum$300
Customer-facing web surfaces
about.avala.ai, ir.avala.ai, docs.avala.ai, learning.avala.ai, pipelines.avala.ai.
- Stored XSS on docs.avala.ai or ir.avala.ai
- Admin-route exposure on any listed subdomain
- Identity or auth-gate bypass on learning.avala.ai or pipelines.avala.ai
Maximum$300
Infrastructure (AWS, Cloudflare, DNS, TLS)
Publicly-exposed Avala-owned cloud surfaces.
- Subdomain takeover on any *.avala.ai we own
- Public S3 bucket with customer data (avala-* prefix)
- Misconfigured Lambda / Worker endpoint returning internal state
- Certificate or email-auth (SPF/DKIM/DMARC) spoofing primitives
Maximum$300
Authentication (Auth0 integration)
How we wire Auth0, not Auth0 itself (report Auth0 bugs to Auth0).
- JWT validation bug in our middleware
- API-key scoping flaw (server/apps/apikey/)
- Session-fixation or re-use across tenants
Maximum$750
Severity reference
The CVSS bands.
Use this reference when a finding does not map cleanly to one surface. Your self-assessment is a starting point for triage.
Open the CVSS v3.1 calculator- Informational / LowCVSS v3.1: < 4.0
No cash reward
Hall of fame, CVE credit if applicable
- MediumCVSS v3.1: 4.0 – 6.9
$50 – $100
Swag, hall of fame
- HighCVSS v3.1: 7.0 – 8.9
$150 – $300
Swag, hall of fame
- CriticalCVSS v3.1: 9.0 – 10.0
$300 – $750
Swag, hall of fame
- Exceptional chain / broad impactCVSS v3.1: —
Discretionary bonus
Case-by-case, Avala discretion
Reward tiers shown here apply to reports submitted on or after September 15, 2026. Earlier reports are assessed against the tiers published when they were submitted. Informational and low-severity findings receive recognition but no cash reward.
Assessment
Quality, novelty, and eligibility.
- +25% quality bonus
- Repro steps, impact analysis, and suggested fix in your first submission.
- +25% novel class
- First AI/LLM-specific finding of its kind on our platform, or a genuinely new vulnerability class.
- First-to-report
- The first valid report for a given issue gets the bounty. Duplicates receive CVE credit but no cash.
Not eligible for a reward
- Reports using real customer data (even in PoC). Retest against your own test account.
- Reports that caused service disruption.
- Reports from individuals located in sanctioned countries (OFAC restrictions).
- Reports from current Avala employees, contractors, or their immediate family members.
Payment
Know the payment terms.
Method and timing
Bounties are paid through PayPal, in USD unless otherwise agreed. Approved bounties are queued in the order reports were received and paid when the monthly pool opens; the program status notice below carries the current payment window.
Tax forms
- US researchers need a W-9 before the first payout. A 1099-NEC is issued if you receive $600 or more in a calendar year.
- International researchers need a W-8BEN before the first payout.
- Your researcher profile has payment preferences and tax-form submission instructions.
- Bounty income is reportable on your own tax return under your country's rules.
Monthly bounty pool: $5,000
Reports past the aggregate cap are still triaged and fixed on SLA. Approved bounties are queued and paid in order received when the next pool opens.
Avala is a seed-stage startup, and our bounty amounts reflect that. We've sized rewards to what we can sustainably pay while still recognizing serious work. As the company grows and our security budget grows with it, we plan to raise these tiers meaningfully — and to backfill bonus payments for researchers who helped us in the early days. If you choose to work with us now, thank you. We'll remember it.