Bug Bounty Program
Help us keep Venice secure. We reward security researchers who responsibly disclose vulnerabilities in our products.
Process
How the Program Works
Our bug bounty program provides a structured way for security researchers to report vulnerabilities and earn rewards.
Discover
Find a security vulnerability in a Venice product within scope.
Document
Create a detailed report with proof of concept and reproduction steps.
Report
Submit your findings through our secure reporting form.
Reward
Eligible bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV at Venice's discretion.
Rewards
Rewards
Eligible bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV at Venice's discretion. Rewards are based on demonstrated impact, exploitability, novelty, reproducibility, and report quality.
Minor but real security issues with clear reproduction, such as limited information disclosure or low-risk configuration gaps with demonstrated impact.
Contained vulnerabilities with demonstrated impact, such as limited stored XSS, narrow authorization gaps, or abuse paths affecting a small set of users.
Significant vulnerabilities affecting account security, authorization boundaries, billing integrity, or user data.
Severe, novel vulnerabilities with broad user impact, such as authentication bypass, remote code execution, sensitive data exposure at scale, or VVV smart contract compromise.
Coverage
Program Scope
Please review what is and is not covered by this program before submitting.
In Scope
- Venice web application (venice.ai)
- Venice API (api.venice.ai)
- Venice Android app, iOS app, and official APK
- Authentication and session management
- Payment and billing flows
- User data handling and privacy controls
- Chat and conversation encryption
- VVV and DIEM smart contracts
Out of Scope
- Non-CSAM related content generation
- Exfiltration of system prompts
- Social engineering or phishing attacks
- Denial-of-service (DoS/DDoS) attacks
- Unsubstantiated or non-deterministic IDOR, CORS, or BOLA issues
- Third-party or vendor-managed issues unless caused by Venice's integration or configuration
- Tokens or IDs that are public-facing by design, required to integrate with third-party services, such as Datadog RUM IDs, PostHog keys, Google API IDs, or Mapbox IDs
- Other pieces of metadata that are public-facing by design, such as model catalogs, pricing, AI character templates, or blockchain data
- Build artifacts, including but not limited to: deployment IDs, Vercel IDs, or Github hashes
- Issues requiring physical access, such as using the mobile app on a jailbroken iPhone
- Automated scanning without validation
- Spam, abuse, or reputation reports without a security vulnerability
- Security header, DNS, SPF, DMARC, CAA, or version disclosure reports without demonstrated exploitability or user impact
- Theoretical rate limiting or brute-force reports without demonstrated impact
Guidelines
Report Requirements
All submissions must include a clear proof of concept, exact reproduction steps, and a description of the security impact.
Proof of Concept
Demonstrate actual exploitation with video, screenshots, or exact reproduction steps. Exceptions apply for self-evident issues like certificate problems.
Specific to Our Environment
Show the vulnerability exists in our actual application, not theoretical scenarios. Generic scanner output without validation is not eligible for rewards.
Based on Your Testing
AI-assisted reports are acceptable only if they are personally validated and reproducible. Unverified AI-generated reports will be rejected.
FAQ
Frequently Asked Questions
Anyone can participate in the Venice Bug Bounty Program. You must be at least 18 years old or have parental consent. Participants must comply with all applicable laws and these program rules.
Rewards are determined by Venice based on severity, impact, exploitability, novelty, reproducibility, and report quality. Eligible bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV at Venice's discretion. Small valid reports typically start at $200, with larger rewards considered for higher-impact vulnerabilities.
A good report includes a clear title, exact reproduction steps, proof of concept, the affected Venice product or endpoint, expected versus actual behavior, security impact, and any relevant screenshots, videos, commands, or request/response details. The more complete and reproducible your report is, the faster we can validate it.
We review submissions as quickly as practical. Complex reports, duplicates, third-party issues, and reports requiring additional validation may take longer.
We do not make any commitments, guarantees, or set any SLAs around when or how we respond to bug bounty reports. Do not email us or submit additional bounty reports inquiring as to the status of yours - They will be deleted.
No. Do not publicly disclose, discuss, or publish a vulnerability report without written approval from Venice. If public disclosure is appropriate, we will coordinate timing and credit with you after the issue has been resolved.
If another researcher has already reported the same vulnerability, the reward goes to the first valid report. Reports may also be closed without reward if they are already known issues, accepted risks, theoretical findings without demonstrated impact, third-party issues outside Venice's control, automated scanner output without validation, or AI-generated reports that have not been personally verified.
Bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV on Base, at Venice's discretion. If your report is eligible for a bounty, we will ask you for a wallet address that can receive Base network assets. Please do not include wallet addresses, private keys, seed phrases, or sensitive payment information in your initial report. Helpful reports that do not qualify for a bounty may receive Venice Credits or a Venice Pro subscription at Venice's discretion.
Ready to Report?
Help Keep Venice Secure
Found a vulnerability? Submit your report and help us protect our users. Eligible bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV at Venice's discretion.