Security & vulnerability disclosure
We take the security of our platform seriously. If you believe you have found a security vulnerability affecting Avora, we want to hear about it, and we will not take legal action against you for reporting it in good faith under this policy.
Report to security@avoraai.ch
We acknowledge reports within 5 business days and aim to give you an assessment within 10 business days. Please do not disclose the issue publicly until we have had a reasonable opportunity to fix it.
Reward
Avora pays USD 100 for each valid, previously unknown, in-scope vulnerability report. One reward per unique issue; where several people report the same issue, the reward goes to the first report we receive that includes enough detail to reproduce it.
Avora determines at its sole discretion whether a report is valid, in scope, and previously unknown. Rewards are paid by bank transfer, subject to applicable law and sanctions screening; we cannot pay rewards where doing so would be unlawful. We may pay more than the standard amount for an exceptional finding, entirely at our discretion.
What is in scope
This programme covers Avora's production systems only:
avoraai.chandwww.avoraai.ch- The Avora web application on the production subdomains of
avoraai.chthat Avora operates for its customers and for its own demonstration environment - The Avora field application (iOS and Android) as published in the app stores
Anything that is not a production system is not in scope, whatever its hostname. That includes development, test, staging and internal tooling hosts (everything under avoraai.tech is internal), and any host that serves an unreleased build. Avora decides which of its systems are production.
Vulnerabilities we are most interested in: authentication and session handling, access control between organisations, injection, remote code execution, server-side request forgery, insecure direct object references, and exposure of credentials or customer data.
What is out of scope
- Findings from automated scanners submitted without a working proof of concept and a described impact
- Missing security headers, cookie flags, TLS configuration preferences, or lack of rate-limiting, absent a demonstrated exploit
- Denial of service, volumetric testing, brute force, spam, or anything that degrades service for others
- Social engineering, phishing, or physical attacks against Avora staff, users or offices
- Reports about software versions without a demonstrated vulnerability in our use of it
- Issues in third-party services we do not operate
- Self-inflicted issues requiring a compromised device, rooted phone, or attacker-supplied browser extension
- Email configuration findings (SPF, DKIM, DMARC) that do not permit a demonstrated spoof
Rules of engagement
- Only test against accounts and data you own. Do not access, modify, download or retain any other party's data.
- If you encounter customer data, stop immediately, do not save it, and tell us in your report.
- Do not degrade, disrupt or reduce the availability of our services.
- Give us a reasonable time to remediate before any public disclosure.
- Do not use the finding for any purpose other than reporting it to us.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you in relation to it, and we will help make it known that your actions were authorised if a third party raises a concern. If in doubt about whether an action is permitted, ask us first at security@avoraai.ch.
This policy does not authorise action against third-party infrastructure, and it does not waive the rights of our customers.
How to report
Email security@avoraai.ch with a description of the issue, the steps to reproduce it, what an attacker could achieve, and anything else that helps us understand the impact. Screenshots or a short recording help. Please write in English or German.