USD-denominated rewards paid in USDC and/or VVV

Bug Bounty Program

Help us keep Venice secure. We reward security researchers who responsibly disclose vulnerabilities in our products.

Process

How the Program Works

Our bug bounty program provides a structured way for security researchers to report vulnerabilities and earn rewards.

Step 1

Discover

Find a security vulnerability in a Venice product within scope.

Step 2

Document

Create a detailed report with proof of concept and reproduction steps.

Step 3

Report

Submit your findings through our secure reporting form.

Step 4

Reward

Eligible bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV at Venice's discretion.

Rewards

Rewards

Eligible bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV at Venice's discretion. Rewards are based on demonstrated impact, exploitability, novelty, reproducibility, and report quality.

LowStarts at $200

Minor but real security issues with clear reproduction, such as limited information disclosure or low-risk configuration gaps with demonstrated impact.

MediumStarts at $750

Contained vulnerabilities with demonstrated impact, such as limited stored XSS, narrow authorization gaps, or abuse paths affecting a small set of users.

HighStarts at $2,500

Significant vulnerabilities affecting account security, authorization boundaries, billing integrity, or user data.

CriticalCase-by-case, scaled to impact

Severe, novel vulnerabilities with broad user impact, such as authentication bypass, remote code execution, sensitive data exposure at scale, or VVV smart contract compromise.

Coverage

Program Scope

Please review what is and is not covered by this program before submitting.

In Scope

  • Venice web application (venice.ai)
  • Venice API (api.venice.ai)
  • Venice Android app, iOS app, and official APK
  • Authentication and session management
  • Payment and billing flows
  • User data handling and privacy controls
  • Chat and conversation encryption

Out of Scope

  • Social engineering or phishing attacks
  • Denial-of-service (DoS/DDoS) attacks
  • Third-party or vendor-managed issues unless caused by Venice's integration or configuration
  • Issues requiring physical access
  • Automated scanning without validation
  • Spam, abuse, or reputation reports without a security vulnerability
  • Security header, DNS, SPF, DMARC, CAA, or version disclosure reports without demonstrated exploitability or user impact
  • Theoretical rate limiting or brute-force reports without demonstrated impact
Guidelines

Report Requirements

All submissions must include a clear proof of concept, exact reproduction steps, and a description of the security impact.

Proof of Concept

Demonstrate actual exploitation with video, screenshots, or exact reproduction steps. Exceptions apply for self-evident issues like certificate problems.

Specific to Our Environment

Show the vulnerability exists in our actual application, not theoretical scenarios. Generic scanner output without validation is not eligible for rewards.

Based on Your Testing

AI-assisted reports are acceptable only if they are personally validated and reproducible. Unverified AI-generated reports will be rejected.

FAQ

Frequently Asked Questions

Ready to Report?

Help Keep Venice Secure

Found a vulnerability? Submit your report and help us protect our users. Eligible bounty rewards are denominated in USD and paid in USDC and/or equivalent VVV at Venice's discretion.

Back to Venice