Skip to content
AvalaSecurity

Rules & safe harbor

Research within clear boundaries.

These rules define how to test, handle evidence, and coordinate disclosure. Read them alongside the scope before you begin.

Testing

Research rules.

  1. Monthly bounty pool is capped at $5,000 aggregate while we are seed-stage. Reports past the cap are still triaged and fixed on SLA — approved bounties are queued and paid in order received when the next pool opens.
  2. Conduct research in good faith and within the scope defined above.
  3. Stop at proof-of-concept. Do not exfiltrate data beyond what is needed to demonstrate impact.
  4. Do not access, modify, or destroy data that is not yours.
  5. Do not degrade availability (no load or DDoS testing).
  6. Do not pivot into internal networks after establishing an initial foothold.
  7. Do not use automated scanners against production without prior written approval.
  8. Report findings within 48 hours of discovery.
  9. Honor a 90-day coordinated disclosure window after report submission; extensions by mutual agreement.
  10. Do not publicly disclose before the agreed-upon release date.
  11. Do not use social engineering against Avala staff, customers, or contractors.
  12. Do not submit reports generated primarily by automated tools or LLMs without independent validation.

Policy

Safe harbor.

Avala considers security research and vulnerability disclosure activities conducted consistent with this policy to be "authorized" conduct under the Computer Fraud and Abuse Act (CFAA), the DMCA, and applicable anti-hacking laws.

We will not pursue civil action or file a complaint with law enforcement for accidental, good-faith violations of our policy. If legal action is initiated by a third party against someone acting in compliance with our policy, we will take reasonable steps to make it known that the activities were authorized.

You must still comply with all applicable laws. Safe harbor does not extend to activities that exceed the program scope or rules, or to research conducted outside good-faith security testing.

This policy is modeled on the disclose.io open framework. It is not a substitute for legal advice. If you have legal questions, consult counsel before testing.

Publication

Coordinate the disclosure.

Honor the 90-day coordinated disclosure window after report submission. Do not publish before the agreed release date. Extensions are by mutual agreement.

Use your report thread to coordinate a publication date and researcher credit. Public recognition is optional; you can choose your attribution preference.

For qualifying issues, we request a CVE on the researcher's behalf through MITRE.

Read published advisories

Response SLA

What to expect from us.

Follow progress in your private report thread. The program's response targets are listed here.

Initial acknowledgment
Within 48 hours
Severity assessment & triage
Within 5 business days
Status update cadence
Every 7 days until resolved
Fix deployment (critical)
Within 72 hours
Fix deployment (high)
Within 14 days
Fix deployment (medium/low)
Within 30 days
Bounty decision
On fix-deployed or determination of non-applicability
Bounty payment
Queued in order received; paid when the monthly pool opens — see the program status notice for the current payment window

Get started

Have a finding to share?