Resources · Security
Bug bounty program.
Security is a shared responsibility. If you’ve found a vulnerability in A8 Core™, we want to hear from you — and we pay for valid reports.
Rewards
Bounties are determined by impact and report quality. Final severity is assessed using CVSS plus the financial-services context of the finding.
| Severity | Reward range | Examples |
|---|---|---|
| Critical | $3,000 – $15,000 | RCE, auth bypass, mass data exposure, funds-movement flaws. |
| High | $1,000 – $3,000 | Privilege escalation, IDOR on account data, stored XSS in app. |
| Medium | $300 – $1,000 | CSRF with impact, sensitive info disclosure, SSRF. |
| Low | $100 – $300 | Limited-impact issues, security misconfigurations. |
In scope
- api.a8core.io and all documented endpoints
- app.a8core.com dashboard
- a8core.com/ marketing site
- Official A8 Core™ SDKs and sample code
Out of scope
- Denial-of-service / volumetric attacks
- Social engineering of A8 Core™ staff or customers
- Reports from automated scanners without a working PoC
- Third-party services not operated by A8 Core™
- Best-practice suggestions without a demonstrable vulnerability
How to report
Submit through our HackerOne program, or email security@a8core.com using our PGP key. Please include clear reproduction steps and a proof of concept. We acknowledge within two business days and aim to triage within five.
Safe harbor for good-faith researchNo testing against other users’ dataCoordinated disclosure
Report a vulnerability
Reports go directly to the security team. Include clear reproduction steps; if your proof of concept is sensitive, say so and we’ll arrange a secure channel before you send it.
Report received.
We acknowledge within two business days and aim to triage within five.