Report Security Issue
Last Updated: August 2026
Avitka operates with rigorous enterprise security safeguards in place to protect our infrastructure, customer payment workflows, and personal data integrity across avitka.com.
If you have identified a security vulnerability on avitka.com, we encourage you to contact us immediately. We review all legitimate reports and aim to resolve issues quickly. Before reporting, please review this document — including our fundamentals, bounty program, reward guidelines, and non-reportable issues.
Fundamentals
If you follow the principles below when reporting a security issue to avitka.com, we will not initiate legal action or enforcement investigations against you in response to your report.
We ask that:
- You give us reasonable time to review and fix the issue before disclosing it publicly or sharing it with others.
- You do not interact with or access private accounts without the account owner's express consent.
- You make a good-faith effort to avoid privacy violations, service disruptions, or data destruction.
- You do not exploit the issue for any reason, including to demonstrate further risks or access sensitive customer data.
- You comply with all applicable local, state, and federal laws and regulations.
Bounty Program
We recognize and reward security researchers who help protect our platform by reporting vulnerabilities. Bounties are awarded at avitka.com's discretion, based on risk, impact, and report quality.
To potentially qualify for a bounty, you must:
- Follow the fundamentals listed above.
- Report a valid security bug that poses a genuine risk to platform privacy or infrastructure security.
- Submit your report by emailing contact@avitka.com with the subject line: Security Vulnerability Report. Please do not contact team members individually.
- Disclose any accidental privacy violations or disruptions in your initial report.
- Understand that while we investigate all valid reports, priority is determined based on risk severity.
- Agree that all reports remain strictly confidential until the issue has been fully patched and resolved.
Scope
In Scope
- avitka.com website and storefront
- Customer account and authentication systems
- Checkout and payment redirection workflows
- Order management and personal data handling
Out of Scope
- Third-party plugins, CDNs, or external services outside our direct control
- Denial of Service (DoS/DDoS) attacks
- Social engineering, spamming, or phishing attempts
- Physical facility security and staff social manipulation
Rewards
Rewards are based on the impact and severity of the vulnerability. Please provide detailed and reproducible steps in your report. If the issue cannot be reproduced, it is not eligible for a bounty reward.
- The first valid report of an issue receives the designated bounty.
- Multiple bugs caused by a single underlying root vulnerability are treated as one report.
- We assess rewards based on overall impact, ease of exploitation, and report quality.
Major exploit vulnerabilities:
- Remote Code Execution (RCE)
- Remote Shell or Command Execution
- Vertical Authentication Bypass
- SQL Injection leaking sensitive data
- Full account or database takeover
High-risk vulnerabilities:
- Lateral authentication bypass
- Disclosure of sensitive internal data
- Stored XSS affecting other users
- Local file inclusion (LFI)
- Insecure handling of auth cookies
Moderate system flaws:
- Logic or business process flaws
- Insecure Direct Object References (IDOR)
- State verification vulnerabilities
Minor issues & hardening:
- Open redirects
- Reflected XSS
- Low-sensitivity information leaks
Contact Information
To report a security vulnerability, email us directly with the subject line Security Vulnerability Report.



