Rules & safe harbor
Research within clear boundaries.
These rules define how to test, handle evidence, and coordinate disclosure. Read them alongside the scope before you begin.
Testing
Research rules.
- Monthly bounty pool is capped at $5,000 aggregate while we are seed-stage. Reports past the cap are still triaged and fixed on SLA — approved bounties are queued and paid in order received when the next pool opens.
- Conduct research in good faith and within the scope defined above.
- Stop at proof-of-concept. Do not exfiltrate data beyond what is needed to demonstrate impact.
- Do not access, modify, or destroy data that is not yours.
- Do not degrade availability (no load or DDoS testing).
- Do not pivot into internal networks after establishing an initial foothold.
- Do not use automated scanners against production without prior written approval.
- Report findings within 48 hours of discovery.
- Honor a 90-day coordinated disclosure window after report submission; extensions by mutual agreement.
- Do not publicly disclose before the agreed-upon release date.
- Do not use social engineering against Avala staff, customers, or contractors.
- Do not submit reports generated primarily by automated tools or LLMs without independent validation.
Policy
Safe harbor.
Avala considers security research and vulnerability disclosure activities conducted consistent with this policy to be "authorized" conduct under the Computer Fraud and Abuse Act (CFAA), the DMCA, and applicable anti-hacking laws.
We will not pursue civil action or file a complaint with law enforcement for accidental, good-faith violations of our policy. If legal action is initiated by a third party against someone acting in compliance with our policy, we will take reasonable steps to make it known that the activities were authorized.
You must still comply with all applicable laws. Safe harbor does not extend to activities that exceed the program scope or rules, or to research conducted outside good-faith security testing.
This policy is modeled on the disclose.io open framework. It is not a substitute for legal advice. If you have legal questions, consult counsel before testing.
Publication
Coordinate the disclosure.
Honor the 90-day coordinated disclosure window after report submission. Do not publish before the agreed release date. Extensions are by mutual agreement.
Use your report thread to coordinate a publication date and researcher credit. Public recognition is optional; you can choose your attribution preference.
For qualifying issues, we request a CVE on the researcher's behalf through MITRE.
Read published advisoriesResponse SLA
What to expect from us.
Follow progress in your private report thread. The program's response targets are listed here.
- Initial acknowledgment
- Within 48 hours
- Severity assessment & triage
- Within 5 business days
- Status update cadence
- Every 7 days until resolved
- Fix deployment (critical)
- Within 72 hours
- Fix deployment (high)
- Within 14 days
- Fix deployment (medium/low)
- Within 30 days
- Bounty decision
- On fix-deployed or determination of non-applicability
- Bounty payment
- Queued in order received; paid when the monthly pool opens — see the program status notice for the current payment window