We take the security of our platform seriously. If you believe you have found a security vulnerability affecting Avora, we want to hear about it, and we will not take legal action against you for reporting it in good faith under this policy.
Avora pays USD 100 for each valid, previously unknown, in-scope vulnerability report. One reward per unique issue; where several people report the same issue, the reward goes to the first report we receive that includes enough detail to reproduce it.
Avora determines at its sole discretion whether a report is valid, in scope, and previously unknown. Rewards are paid by bank transfer, subject to applicable law and sanctions screening; we cannot pay rewards where doing so would be unlawful. We may pay more than the standard amount for an exceptional finding, entirely at our discretion.
avoraai.ch and www.avoraai.chavoraai.chVulnerabilities we are most interested in: authentication and session handling, access control between organisations, injection, remote code execution, server-side request forgery, insecure direct object references, and exposure of credentials or customer data.
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you in relation to it, and we will help make it known that your actions were authorised if a third party raises a concern. If in doubt about whether an action is permitted, ask us first at security@avoraai.ch.
This policy does not authorise action against third-party infrastructure, and it does not waive the rights of our customers.
Email security@avoraai.ch with a description of the issue, the steps to reproduce it, what an attacker could achieve, and anything else that helps us understand the impact. Screenshots or a short recording help. Please write in English or German.