Scope
Where to look.
The cash-bounty scope is listed below. We also accept legitimate reports about other Avala-owned assets for coordinated disclosure, even when they are not currently eligible for payouts.
In scope
Core product
- avala.ai — Mission Control (Physical AI data platform)
- api.avala.ai — Django API + MCP endpoint
- Arcade mobile app (iOS/Android)
Customer-facing web surfaces
- about.avala.ai — marketing site
- ir.avala.ai — investor relations site
- docs.avala.ai — developer docs
- learning.avala.ai — learning platform
- pipelines.avala.ai — data pipelines site
Infrastructure
- Publicly-exposed Avala-owned AWS / Cloudflare surfaces (ALB, S3 buckets with avala-* prefix, Lambda/Worker endpoints)
- DNS, TLS, and email authentication misconfigurations on Avala-owned domains
SDKs & packages
- avala (PyPI)
- @avala-ai/sdk (npm)
- @avala-ai/mcp-server (npm)
AI / LLM-specific
- Prompt injection in LLM-powered endpoints
- MCP server (server/apps/mcp/) authz bypass or SELECT-only bypass
- Training data or model exfiltration via API
- Indirect prompt injection via uploaded annotation data
Authentication
- Auth0 integration flaws in our configuration
- API key scoping (server/apps/apikey/)
- JWT validation bugs
Disclosure welcome · no cash bounty
Please report legitimate issues involving these Avala-owned properties. We'll triage them, fix validated vulnerabilities, and coordinate disclosure with you. They are not currently listed for cash payouts; the security team makes the final eligibility decision after reviewing the exact asset, impact, and circumstances.
- pay.avala.ai — payment portal
- security.avala.ai — security and bug-bounty portal
- trust.avala.ai — compliance trust center
Out of scope
Not eligible for cash. We'll still triage and fix legitimate issues.
- Vulnerabilities in third-party service products themselves (Auth0, Supabase, Vanta, AWS, Cloudflare, Sentry, Resend, Intercom, Stripe). Report those directly to the vendor. Avala-owned configuration and integration flaws on an in-scope asset remain in scope.
- Non-production environments (dev.alala.ai, *.dev.alala.ai) unless they expose production data
- Volumetric DoS, rate-limiting concerns without demonstrated impact
- Social engineering, phishing, physical attacks on Avala staff or offices
- Spam/abuse reports (account signup, email deliverability, bounce handling)
- Missing security headers without a working exploit chain
- Self-XSS without amplification
- Clickjacking on pages without auth-state-changing actions
- Open redirects without demonstrable impact
- CSRF on unauthenticated endpoints
- Software version disclosure without a known exploit
- Vulnerabilities in unsupported versions (Mission Control < 1.25, Django < 4.2)
- Theoretical issues without a working proof of concept
- Reports generated by automated tools without manual validation
Edge case?
Email security@avala.ai before testing, or submit a report and we'll tell you.
Submit a report