Reporting a Vulnerability

We welcome reports from security researchers, customers, and anyone who finds a problem. If you’ve found something, we want to hear about it.

Send reports to [email protected].

What to include

  • A description of the issue and the affected system or endpoint
  • Enough detail for us to reproduce or confirm it
  • The date and approximate time of your testing
  • The account or identifier you tested from, if applicable
  • Your view of the potential impact

Reports may be submitted anonymously. We don’t require you to identify yourself.

What you can expect from us

  • We’ll acknowledge your report within three business days
  • If we can’t reproduce it, we’ll come back to you for more detail rather than closing it
  • We’ll give you an initial assessment, including our severity determination, within ten business days
  • We’ll keep you updated at least every 30 days until it’s resolved
  • We’ll tell you when it’s fixed

Our assessed severity may differ from yours based on what we know about our architecture and real-world exploitability.

Safe harbor

If you research in good faith and follow the rules below, Avid will:

  • Consider your research authorized under applicable computer access and misuse laws, including the U.S. Computer Fraud and Abuse Act
  • Not pursue civil claims against you
  • Not refer your research to law enforcement
  • Not treat your research as a violation of our Terms of Use
  • Work with you to get the issue resolved

If a third party takes legal action against you for research conducted under this policy, we’ll make that authorization known.

Rules of engagement

Test only as far as you need to. Limit your testing to what is reasonably necessary to show a vulnerability exists, and stop as soon as you’ve confirmed it. This is the line between security research and exploitation.

Please don’t:

  • Keep pulling records after you’ve confirmed the issue exists
  • Extract, download, or retain Avid or customer data in bulk
  • Include real private or sensitive data in any published writeup
  • Modify, delete, or take down any data or system
  • Use a vulnerability to reach systems, accounts, or data beyond what’s needed to demonstrate it
  • Degrade or disrupt availability
  • Access or store personal data of any Avid customer, user, or donor beyond what’s incidental
  • Social engineer our people, customers, or vendors
  • Test using accounts that aren’t yours or that you didn’t create for the purpose

If you access something you shouldn’t have

Stop testing and tell us. Securely delete every retained, cached, or local copy within 24 hours of filing your report, and confirm the deletion in writing. Doing this promptly and in good faith keeps your safe harbor protection.

In scope

  • app.avidai.com and the Avid application API
  • avidai.com and our public web properties
  • Publicly routable Avid-operated infrastructure

Out of scope

  • Third-party services we use, including Google Cloud Platform, Stripe, HubSpot, and Zendesk. Report those to the vendor
  • Scanner output without demonstrated impact
  • Denial of service, volumetric, or load testing
  • Social engineering
  • Physical security testing
  • Software version or configuration reports without a demonstrated exploit path
  • Model jailbreaks, system prompt extraction, or prompt injection without demonstrated impact on application data or APIs
  • Model hallucinations, bias, or output quality

Coordinated disclosure

Please give us a reasonable window to fix things before going public. We ask that you hold details for 90 days from your report, or until we confirm remediation, whichever comes first. If you think a different window makes sense, talk to us.