Service status ·A8 Core™ · The Operating System for Financial Accounts ·The account operating system · API-first
Resources · Security

Bug bounty program.

Security is a shared responsibility. If you’ve found a vulnerability in A8 Core™, we want to hear from you — and we pay for valid reports.

Rewards

Bounties are determined by impact and report quality. Final severity is assessed using CVSS plus the financial-services context of the finding.

SeverityReward rangeExamples
Critical$3,000 – $15,000RCE, auth bypass, mass data exposure, funds-movement flaws.
High$1,000 – $3,000Privilege escalation, IDOR on account data, stored XSS in app.
Medium$300 – $1,000CSRF with impact, sensitive info disclosure, SSRF.
Low$100 – $300Limited-impact issues, security misconfigurations.

In scope

  • api.a8core.io and all documented endpoints
  • app.a8core.com dashboard
  • a8core.com/ marketing site
  • Official A8 Core™ SDKs and sample code

Out of scope

  • Denial-of-service / volumetric attacks
  • Social engineering of A8 Core™ staff or customers
  • Reports from automated scanners without a working PoC
  • Third-party services not operated by A8 Core™
  • Best-practice suggestions without a demonstrable vulnerability

How to report

Submit through our HackerOne program, or email security@a8core.com using our PGP key. Please include clear reproduction steps and a proof of concept. We acknowledge within two business days and aim to triage within five.

Safe harbor for good-faith researchNo testing against other users’ dataCoordinated disclosure

Report a vulnerability

Reports go directly to the security team. Include clear reproduction steps; if your proof of concept is sensitive, say so and we’ll arrange a secure channel before you send it.

Safe harbor applies to good-faith research as described above. By submitting, you agree to our privacy policy.

Report received.

We acknowledge within two business days and aim to triage within five.

Scroll to Top